Aude Data Retention Policy
Purpose: This policy outlines Aude's procedures for retaining and disposing of customer data to ensure proper data management throughout the customer lifecycle.
Scope: This policy applies to all data collected through Aude's performance management platform, including but not limited to:
Engineering Activity Data
GitHub/GitLab data: Pull requests, code reviews, commit messages
Jira data: Ticket activity, assignments, comments
Confluence data: Document contributions and edits
Slack data: Messages and interactions in work-related channels
Performance Management Data
Goals and objectives
Performance evaluations
1:1 meeting notes
Feedback records
Organizational Data
Team structure and reporting relationships
Role/title information
Employee identifiers
Data Retention Periods
Active Customers
All customer data is retained for the duration of the active business relationship
Data is maintained and accessible throughout the service period
Design Partners
Data is retained for the duration of the design partner program
Upon program completion, data is retained for 30 days unless converted to a paid customer
Trial/Evaluation Users
Data is retained for the duration of the trial period plus 30 days
If not converted to a paid customer, data is purged after the 30-day grace period
Data Deletion Process: Upon service termination or end of relationship:
Customer receives notification of impending data deletion
30-day grace period begins
Option to export data is provided
After grace period, automatic purge process begins
Data Purge Process
All customer data is deleted from production systems
Backup data is removed according to backup rotation schedule
No customer data is retained beyond 90 days post-termination
Customer Rights and Responsibilities
Customers may request data export during active service period
Early data deletion requests will be honored upon written or email confirmation
Customers are responsible for extracting any desired data before the end of the grace period
Compliance and Verification
Audit Logs
Audit logs record all data deletion events including:
Date and time of deletion request
Customer identifier
Data categories deleted
Verification of successful deletion
Personnel who executed the deletion
Method of deletion
Audit logs are retained for 2 years after deletion
Logs are encrypted and accessible only to authorized personnel
Compliance with Data Protection Regulations
GDPR Compliance
Right to erasure ("right to be forgotten") honored upon request
Data minimization principles followed
Processing records maintained as required
Data transfer mechanisms compliant with EU requirements
CCPA Compliance
Consumer deletion requests honored within 45 days
Verification process for deletion requests
Records of deletion requests maintained
General Data Protection:
Regular security assessments conducted
Data processing agreements with subprocessors maintained
Privacy impact assessments performed for new features
Employee training on data protection requirements
Incident response procedures in place
Verification Process
Customer can request written verification of deletion
Deletion certificate provided including:
Confirmation of data categories deleted
Date of deletion
Verification of completion
Signed by authorized Aude representative
Last updated