Data retention policies define how long document data is stored in Docupath before automatic deletion. The retention period is set in days and applies globally to your tenant. Once a retention period is shortened, the change is irreversible and all data beyond the new retention window will be permanently deleted within the enforcement period.
Retention policies must align with legal and regulatory requirements (GDPR, CCPA, industry-specific standards) and should be carefully planned to balance compliance needs with operational requirements.
How It Works
Accessing the Data Retention Settings
Select System Settings from the Main Menu
Locate the Data retention section
View the current retention period in days
Setting the Initial Retention Period
In the Data retention section, enter the desired retention period in days:
Minimum: 30 days (allows for document review and correction)
Recommended: 365 days (1 year, covers most fiscal and compliance cycles)
Maximum: 2555 days (7 years, typical for legal/audit requirements)
Click Save to apply the retention policy
A confirmation message displays the effective date and scope
All new documents are subject to the new retention period immediately
Understanding Irreversibility
Critical Important:
Once you update the data retention period, all data older than the new retention window will be permanently deleted
This action is permanent and cannot be reversed by support
Example Scenario:
Current retention: 365 days
You change retention to 90 days
All documents older than 90 days are queued for deletion
Deletion occurs within 24-48 hours
After deletion, no recovery is possible
Retention Period and Document Lifecycle
Retention Period | Use Case | Considerations |
30-90 days | High-volume, short-term processing | Minimal audit trail; limited dispute resolution |
180-365 days | Standard business operations | Covers typical fiscal year and invoice matching cycles |
1-3 years | Legal/compliance requirements | Aligns with most tax authorities and audit requirements |
3-7 years | Heavy regulatory environment | Required for SOX, GDPR right to be forgotten, industry audits |
Production vs. Sandbox Considerations
Production Environment Recommendations:
Retention periods should be conservative
Shorter retention risks losing data needed for disputes or audits
Changes should be planned months in advance
Notify legal, compliance, and operations teams before reducing retention
Sandbox Environment Recommendations:
Can use short retention periods (30-90 days) for testing
Useful for testing auto-deletion workflows
Does not affect production data
Should not be used for ongoing test data that needs preservation
Monitoring and Enforcement
Automatic Enforcement:
Docupath runs daily cleanup jobs to delete documents past the retention window
Cleanup jobs respect the defined retention period precisely
No manual intervention required
Audit Log Records:
All retention policy changes are logged with timestamp and user
Deleted documents are recorded in compliance audit logs
Deletion logs can be exported for regulatory reporting
Alerts and Notifications:
Document approaching deletion: may trigger notification (if configured)
Retention period changes: email confirmation to administrators
Large bulk deletions: warning if thousands of documents are deleted
Supported Configurations and Options
Configuration | Description | Range | Unit | Required |
Retention Period | Maximum days to store documents | 30-2555 | Days | Yes |
Effective Date | When new retention period applies | Immediate | - | Auto |
Historic Data Handling | How existing data is treated on change | Retroactive | - | Auto |
Enforcement Schedule | When deletion occurs | Daily | Scheduled job | System |
Notification on Deletion | Alerts before data is deleted | Optional | - | No |
Compliance Reference | Document policy reason (optional) | Free text | - | No |
Other Technical Specifications
Aspect | Details |
Retention Scope | Global; applies to all documents in tenant |
Minimum Period | 30 days (ensures reasonable document review/correction window) |
Maximum Period | 2555 days (7 years; covers longest regulatory requirements) |
Enforcement Mechanism | Automated daily deletion job; runs at system-defined time (typically midnight UTC) |
Deletion Granularity | Per document (based on creation or last modified date) |
Irreversibility | Changes that reduce retention are permanent; no rollback |
Audit Trail | Retention changes logged with timestamp, user, old value, new value |
Data Recovery | No recovery possible after deletion; database backups not customer-accessible |
Time Zone | Retention period calculated in tenant's configured time zone |
Notification Period | May include grace period before deletion (24-48 hours) depending on configuration |
Notes
No Selective Retention: Retention period applies uniformly to all document types and statuses; per-document-type retention is not supported
Irreversible Reduction: Lowering retention period is permanent; you cannot restore the longer period later
Bulk Deletion Risk: Significantly reducing retention period may delete thousands of documents at once; plan carefully
No Grace Period Override: Documents at the retention window edge are deleted on schedule; no manual grace period extension
Soft-Deleted Documents: Soft-deleted trading parties and organizations do not affect document retention; document retention depends on document creation date only
Timezone Sensitivity: Retention period edge cases (documents created at day boundary) may be affected by timezone differences between client and server
No Retention Bypass: All documents, regardless of status (pending, approved, rejected), are subject to the same retention policy
Multi-Tenant Isolation: Each tenant has independent retention policies; cannot share or inherit retention settings from other tenants
Backup Data Not Affected: Database backups may retain data beyond the retention policy; backup retention must be configured separately
