Skip to main content

Configuring Data Retention Policies

How to set the maximum document retention period for your tenant

Data retention policies define how long document data is stored in Docupath before automatic deletion. The retention period is set in days and applies globally to your tenant. Once a retention period is shortened, the change is irreversible and all data beyond the new retention window will be permanently deleted within the enforcement period.

Retention policies must align with legal and regulatory requirements (GDPR, CCPA, industry-specific standards) and should be carefully planned to balance compliance needs with operational requirements.

How It Works

Accessing the Data Retention Settings

  1. Select System Settings from the Main Menu

  2. Locate the Data retention section

  3. View the current retention period in days

Setting the Initial Retention Period

  1. In the Data retention section, enter the desired retention period in days:

    • Minimum: 30 days (allows for document review and correction)

    • Recommended: 365 days (1 year, covers most fiscal and compliance cycles)

    • Maximum: 2555 days (7 years, typical for legal/audit requirements)

  2. Click Save to apply the retention policy

  3. A confirmation message displays the effective date and scope

  4. All new documents are subject to the new retention period immediately

Understanding Irreversibility

Critical Important:

  • Once you update the data retention period, all data older than the new retention window will be permanently deleted

  • This action is permanent and cannot be reversed by support

Example Scenario:

  • Current retention: 365 days

  • You change retention to 90 days

  • All documents older than 90 days are queued for deletion

  • Deletion occurs within 24-48 hours

  • After deletion, no recovery is possible

Retention Period and Document Lifecycle

Retention Period

Use Case

Considerations

30-90 days

High-volume, short-term processing

Minimal audit trail; limited dispute resolution

180-365 days

Standard business operations

Covers typical fiscal year and invoice matching cycles

1-3 years

Legal/compliance requirements

Aligns with most tax authorities and audit requirements

3-7 years

Heavy regulatory environment

Required for SOX, GDPR right to be forgotten, industry audits

Production vs. Sandbox Considerations

Production Environment Recommendations:

  • Retention periods should be conservative

  • Shorter retention risks losing data needed for disputes or audits

  • Changes should be planned months in advance

  • Notify legal, compliance, and operations teams before reducing retention

Sandbox Environment Recommendations:

  • Can use short retention periods (30-90 days) for testing

  • Useful for testing auto-deletion workflows

  • Does not affect production data

  • Should not be used for ongoing test data that needs preservation

Monitoring and Enforcement

  1. Automatic Enforcement:

    • Docupath runs daily cleanup jobs to delete documents past the retention window

    • Cleanup jobs respect the defined retention period precisely

    • No manual intervention required

  2. Audit Log Records:

    • All retention policy changes are logged with timestamp and user

    • Deleted documents are recorded in compliance audit logs

    • Deletion logs can be exported for regulatory reporting

  3. Alerts and Notifications:

    • Document approaching deletion: may trigger notification (if configured)

    • Retention period changes: email confirmation to administrators

    • Large bulk deletions: warning if thousands of documents are deleted

Supported Configurations and Options

Configuration

Description

Range

Unit

Required

Retention Period

Maximum days to store documents

30-2555

Days

Yes

Effective Date

When new retention period applies

Immediate

-

Auto

Historic Data Handling

How existing data is treated on change

Retroactive

-

Auto

Enforcement Schedule

When deletion occurs

Daily

Scheduled job

System

Notification on Deletion

Alerts before data is deleted

Optional

-

No

Compliance Reference

Document policy reason (optional)

Free text

-

No

Other Technical Specifications

Aspect

Details

Retention Scope

Global; applies to all documents in tenant

Minimum Period

30 days (ensures reasonable document review/correction window)

Maximum Period

2555 days (7 years; covers longest regulatory requirements)

Enforcement Mechanism

Automated daily deletion job; runs at system-defined time (typically midnight UTC)

Deletion Granularity

Per document (based on creation or last modified date)

Irreversibility

Changes that reduce retention are permanent; no rollback

Audit Trail

Retention changes logged with timestamp, user, old value, new value

Data Recovery

No recovery possible after deletion; database backups not customer-accessible

Time Zone

Retention period calculated in tenant's configured time zone

Notification Period

May include grace period before deletion (24-48 hours) depending on configuration

Notes

  • No Selective Retention: Retention period applies uniformly to all document types and statuses; per-document-type retention is not supported

  • Irreversible Reduction: Lowering retention period is permanent; you cannot restore the longer period later

  • Bulk Deletion Risk: Significantly reducing retention period may delete thousands of documents at once; plan carefully

  • No Grace Period Override: Documents at the retention window edge are deleted on schedule; no manual grace period extension

  • Soft-Deleted Documents: Soft-deleted trading parties and organizations do not affect document retention; document retention depends on document creation date only

  • Timezone Sensitivity: Retention period edge cases (documents created at day boundary) may be affected by timezone differences between client and server

  • No Retention Bypass: All documents, regardless of status (pending, approved, rejected), are subject to the same retention policy

  • Multi-Tenant Isolation: Each tenant has independent retention policies; cannot share or inherit retention settings from other tenants

  • Backup Data Not Affected: Database backups may retain data beyond the retention policy; backup retention must be configured separately

Did this answer your question?