Skip to main content

Data Retention

OASIS supports tenant-specific lifecycle rules for each customer record class.

Reviewed September 15, 2026

Control details

Customer schedules

  • Administrators define versioned retention policies by record class and source, with a records-schedule reference and a calculated effective period.

Source restrictions

  • Licensed-source minimums and maximums constrain the effective retention window so a customer schedule cannot override provider or dataset rights.

Disposition

  • Disposition requires an explicit review decision.
  • Long-term archival and non-retainable records require documented policy context.

Export

  • Public-records and e-discovery packages preserve record-level custody hashes and a package checksum.
  • Approved report editions preserve the exact data and definitions used at issuance.

Deletion

  • Deletion is audited.
  • Legal holds, contract terms, source-license rules, backup cycles, and security obligations may affect deletion timing or scope.

Default examples

  • The baseline control model includes seven-year audit retention, social content for the contract term plus one year, and configurable 30-day AI prompt/output retention.
  • Contracted tenant policy is authoritative.

Important: Published durations are baseline control defaults. The signed customer agreement and configured records schedule govern each organization.