Our approach
BuildPilot does not keep personal data indefinitely just in case it may become useful. Retention is based on the purpose for which the information is held, customer instructions, contractual needs, security requirements, tax/accounting duties and the need to establish, exercise or defend legal claims.
The periods below are standard policy positions. Data may be removed earlier when it is no longer needed. A legal hold, active dispute, security investigation, fraud concern or statutory requirement can justify keeping specific records for longer.
Retention schedule
| Category | Typical period | Why | End of period |
|---|---|---|---|
Active account and workspace data Account profile, memberships, business settings and live workspace records | For the life of the account/workspace | Needed to provide the contracted service and maintain account security. | Deleted or anonymised after account closure when no longer required for another lawful purpose. |
Customer CRM and commercial records Leads, quotations, tenders, estimates, rate-library records and related notes | For the life of the workspace, then reviewed on closure | Customers control these records as part of their commercial workspace. Some records may need longer retention for disputes, accounting or legal claims. | Deleted, anonymised or returned where appropriate after closure/review. |
Billing and transaction records Subscription status, invoices, payment references and Stripe identifiers | Normally up to 6 years after the relevant accounting period or relationship ends | Tax, accounting, fraud prevention, contractual evidence and legal-claims requirements. | Secure deletion or anonymisation when the retention justification expires. |
Security and audit records Login/security events, hashed IP indicators and administrative audit entries | Normally up to 24 months, longer where linked to an investigation or legal claim | Security monitoring, fraud prevention, accountability and incident investigation. | Secure deletion or irreversible anonymisation. |
Privacy-rights and legal requests Subject access, correction, erasure, restriction, objection and portability requests | Normally up to 6 years after closure of the request | To demonstrate how legal requests were handled and defend or establish legal claims. | Secure deletion after the accountability period ends. |
Support and transactional communications Support emails, service notices and transactional messages | Normally up to 24 months after the matter is resolved | Customer support, service continuity, complaint handling and dispute evidence. | Deleted when no longer needed, subject to legal holds. |
Backups Provider-managed database or infrastructure backups | According to the configured provider backup lifecycle | Resilience, disaster recovery and restoration of service. | Expires through the provider backup lifecycle; restored data remains subject to the live retention policy. |
Account closure and erasure
Closing a BuildPilot account and exercising the legal right to erasure are related but not identical. We may need to retain limited billing, tax, security, fraud-prevention, contractual or legal-claims records after service access ends. Where complete deletion is not appropriate, access is restricted and the retained information is kept only for the applicable lawful purpose.
Backups
Deleted information may remain temporarily in provider-managed backups until those backups expire through their normal lifecycle. We do not restore deleted data from backup simply to continue ordinary processing. If a backup is restored for disaster recovery, applicable deletion and restriction decisions must be re-applied.
Reviews
We review this schedule at least annually and whenever the purposes or providers materially change. Customers and individuals can challenge retention through the Privacy & Data centre or by contacting admin@buildpilotai.co.uk.