Data privacy and retention
Data residency
Choose EU or US hosting when the workspace is created. Content, contacts, and analytics stay in that region. The choice cannot be changed later without a support-assisted migration.
Retention defaults
| Data | Default retention |
|---|---|
| Published content and analytics | Lifetime of the workspace |
| Inbox conversations | 24 months |
| Audit log | 24 months |
| Deleted drafts | 30 days in trash, then purged |
| Backups | 35 days rolling |
Admins can shorten any retention window in Settings → Privacy. Shortening a window purges anything already past it within 24 hours, permanently.
Subject access and erasure
Search a contact by email in Audience → Privacy requests to export everything held about them, or to erase it. Erasure removes the contact, their conversations, and their event history, and adds a hash of their address to the suppression list so a re-import cannot resurrect them.
Sub-processors and DPA
The current sub-processor list and the standard Data Processing Agreement are available in Settings → Legal, and are versioned — you are notified 30 days before any addition.
Last updated 28 July 2026

