Skip to content
All documentation

Data Retention & Records of Processing

The retention schedule for personal data, the inactivity review window, and the record of processing (GDPR Art 5(1)(e) and Art 30).

Retention schedule (Art 5(1)(e))

Personal data is kept only as long as it serves its stated purpose, in line with the storage-limitation principle. The schedule below is a definition, not a silent cron that deletes production data on its own: every deletion step is surfaced to the controller, who decides when to act.

  • Account and consent records: retained while the account is active. On deletion, the account row and its consent ledger are removed in one transaction.
  • Survey responses: retained while the account (or the organization's survey) is active. They cascade-delete with the account.
  • Learning progress, submissions, and assignments: retained while the account is active, then deleted on account deletion.
  • Auth events: retained for security and support while an account exists; on deletion, user-correlated events are removed and orphan email-only events are anonymized.
  • Roster entries, course shares, and blog subscriptions carrying an email: removed on account deletion.

Inactivity review window

An organization is prompted to review its data after 24 months of inactivity. Inactivity is surfaced (for example, via the last-login dates in the member list and the admin audit view); nothing is deleted automatically. The controller is responsible for triggering the delete-account or export-before-delete path when the review confirms a record is no longer needed.

Delete account and export before delete

A member deletes their own account via DELETE /api/auth/me (self-service erasure). Before doing so they can export their data via GET /api/me/export, so nothing is lost when the account is removed. An admin can export a member's data first via GET /api/admin/members/export?userId=<id>. A sole organization owner must transfer ownership before deleting, which is enforced by the route.

Record of processing (Art 30)

Data categories: contact and account data (name, email, hashed password), learning activity (progress, submissions, assignments), survey responses and identifiers, consent records, auth-event logs, and optional organization contact details.

Purposes: authentication and account security, delivering learning content and grading, survey analytics for the organization, and security/audit logging.

Retention: per the schedule above; no category is retained beyond the active account or the defined review window.

Processor (hosting): the application and database are hosted on Vercel and Neon.

Processor (AI): exercise submissions may be processed by an LLM provider (OpenRouter by default, or the organization's own configured endpoint) solely to grade and give feedback.

DPA note: a customer-facing Data Processing Agreement is a separate legal artifact maintained by the operator (Jay), not part of this codebase. This document identifies the processing activities; the DPA is supplied on request.

This record of processing is deliberately plain and factual. It does not assert the existence of any DPA or certification that has not actually been issued.

Setup

No configuration is required; the retention schedule and review window are policy definitions enforced by existing endpoints (delete account, export, and the admin surface), not by automatic background deletion.