FairMind legal
Data retention policy
Maximum retention by website data category, with deletion, backup, and exception rules stated plainly.
1. Policy rule
FairMind keeps public-website information for the shortest period reasonably needed for the stated purpose, subject to the maximums below. A maximum is not a promise to keep information for the entire period. Data may be deleted or aggregated sooner.
2. Retention schedule
| Category | Maximum active retention | Start point | Reason |
|---|---|---|---|
| Anonymous web and product analytics events | 12 months | Event timestamp | Journey and content analysis across meaningful periods |
| Session replays | 30 days | Recorded session end | Short-lived interaction and usability diagnosis |
| Web performance, heatmap, dead-click, rage-click, media, and client-error events | 12 months | Event timestamp | Regression comparison and incident diagnosis |
| Contact and access-request submissions | 24 months | Last substantive interaction | Reply, qualification, and relationship context |
| Hosting, delivery, and abuse-prevention logs under FairMind's control | 90 days | Request or security event | Availability, investigation, and abuse prevention |
| Deletion-request and consent-response audit records received by FairMind | 3 years | Request closure or superseded choice | Demonstrate that the request was handled |
3. Consent-manager records
The external consent manager owns the durable preference record and its configured retention. FairMind's website bridge receives only the current analytics decision, source, and policy version in memory. When the manager is selected and configured, its published retention must not exceed the period reasonably required to demonstrate consent and withdrawal.
4. Deletion and withdrawal
Analytics withdrawal stops future capture and session replay; it does not rewrite events that were lawfully collected before withdrawal. A verified deletion request is removed from active systems within 30 days unless an exception applies. Where a provider exposes separate deletion queues, FairMind initiates the corresponding provider deletion as part of the same request.
5. Backups
Deleted information may remain in encrypted, access-restricted backups until the backup expires, for no more than 90 additional days. Backups are not restored to avoid a completed deletion. If restoration is required for disaster recovery, deletion records are reapplied before ordinary use.
6. Aggregation and de-identification
FairMind may retain statistical or aggregated information longer when it no longer identifies or can reasonably be linked to an individual or device. Removing a direct field while keeping a linkable identifier is not treated as de-identification.
7. Exceptions
FairMind may retain limited information beyond a scheduled period when required by law, a legal hold, fraud or security investigation, dispute, contractual record duty, or a request from the person to preserve it. Access is restricted to the exception purpose, and deletion resumes when the exception ends.
8. Configuration accountability
Service settings, exports, and deletion jobs must match this schedule before a data category is enabled. A policy page is not a retention control by itself. FairMind reviews the schedule when a provider, purpose, or legal requirement changes and updates the version and date shown above.
The short version
Most anonymous analytics lasts at most 12 months. Replay lasts 30 days. Website forms last at most 24 months after the conversation ends. Routine logs under FairMind's control last 90 days.
Why the dates differ
A replay is useful for a short debugging window. A business conversation needs enough context for a follow-up. A deletion record may need to outlive both so FairMind can prove the deletion happened. Giving every table row “forever” would be simpler and indefensible.
What deletion means
Active copies are removed within 30 days after verification, provider queues are included, and encrypted backups age out within 90 additional days. Legal holds and security investigations are narrow exceptions, not a second retention policy hiding in a trench coat.
Retention lifecycle
| Stage | Control | Deadline | Evidence |
|---|---|---|---|
| Collect | Purpose and consent gate | Before data enters a provider | Configured category and policy version |
| Use | Access restricted to the stated purpose | During active retention | Provider and access configuration |
| Expire | Provider retention or deletion job | Category maximum | Deletion setting, job, or provider record |
| Delete on request | Verify, remove active copies, queue providers | Within 30 days unless an exception applies | Request closure record |
| Age out backups | Restricted backup lifecycle | Within 90 additional days | Backup schedule |
For questions or a verified deletion request, use the contact page and identify the relevant submission without sending credentials or production AI data.