Compliance
Retention policy
Dynafloxis retention is enforced in code where possible and tracked here for policy review.
| Data type | Retention target | Notes |
|---|---|---|
| Soft-deleted users | 30 days | Purged by retention cleanup |
| Notifications | 90 days | Removed after the retention window |
| Closed support tickets | 365 days | Archived then purged |
| Audit logs | 365 days | Keep longer only under legal hold |
| Accepted runtime evidence | Organization setting (default 90 days) | MFA-protected owner/admin policy with audit reason |
| Quarantined runtime evidence | Organization setting (default 30 days) | Separate shorter window for rejected telemetry |
| Organization legal holds | Until explicitly released | Pauses accepted and quarantined evidence deletion; activation and release are audited |
| Compliance requests | Case-dependent | Retain enough to prove response |
| Run artifacts | Policy-dependent | Should match customer and plan retention |
| Mining outputs | Policy-dependent | Prefer derived data over raw source retention |