Data governance

Data retention & deletion

How BuildPilot decides how long personal and commercial information should be kept, reviewed and securely disposed of.

Last updated: 13 August 2026

Our approach

BuildPilot does not keep personal data indefinitely just in case it may become useful. Retention is based on the purpose for which the information is held, customer instructions, contractual needs, security requirements, tax/accounting duties and the need to establish, exercise or defend legal claims.

The periods below are standard policy positions. Data may be removed earlier when it is no longer needed. A legal hold, active dispute, security investigation, fraud concern or statutory requirement can justify keeping specific records for longer.

Retention schedule

CategoryTypical periodWhyEnd of period

Active account and workspace data

Account profile, memberships, business settings and live workspace records

For the life of the account/workspaceNeeded to provide the contracted service and maintain account security.Deleted or anonymised after account closure when no longer required for another lawful purpose.

Customer CRM and commercial records

Leads, quotations, tenders, estimates, rate-library records and related notes

For the life of the workspace, then reviewed on closureCustomers control these records as part of their commercial workspace. Some records may need longer retention for disputes, accounting or legal claims.Deleted, anonymised or returned where appropriate after closure/review.

Billing and transaction records

Subscription status, invoices, payment references and Stripe identifiers

Normally up to 6 years after the relevant accounting period or relationship endsTax, accounting, fraud prevention, contractual evidence and legal-claims requirements.Secure deletion or anonymisation when the retention justification expires.

Security and audit records

Login/security events, hashed IP indicators and administrative audit entries

Normally up to 24 months, longer where linked to an investigation or legal claimSecurity monitoring, fraud prevention, accountability and incident investigation.Secure deletion or irreversible anonymisation.

Privacy-rights and legal requests

Subject access, correction, erasure, restriction, objection and portability requests

Normally up to 6 years after closure of the requestTo demonstrate how legal requests were handled and defend or establish legal claims.Secure deletion after the accountability period ends.

Support and transactional communications

Support emails, service notices and transactional messages

Normally up to 24 months after the matter is resolvedCustomer support, service continuity, complaint handling and dispute evidence.Deleted when no longer needed, subject to legal holds.

Backups

Provider-managed database or infrastructure backups

According to the configured provider backup lifecycleResilience, disaster recovery and restoration of service.Expires through the provider backup lifecycle; restored data remains subject to the live retention policy.

Account closure and erasure

Closing a BuildPilot account and exercising the legal right to erasure are related but not identical. We may need to retain limited billing, tax, security, fraud-prevention, contractual or legal-claims records after service access ends. Where complete deletion is not appropriate, access is restricted and the retained information is kept only for the applicable lawful purpose.

Backups

Deleted information may remain temporarily in provider-managed backups until those backups expire through their normal lifecycle. We do not restore deleted data from backup simply to continue ordinary processing. If a backup is restored for disaster recovery, applicable deletion and restriction decisions must be re-applied.

Reviews

We review this schedule at least annually and whenever the purposes or providers materially change. Customers and individuals can challenge retention through the Privacy & Data centre or by contacting admin@buildpilotai.co.uk.