Effective 2 August 2026 · Version 2026-08-02
Data retention schedule
This schedule explains Arxela’s standard retention periods. A legal duty, dispute, security investigation or documented controller instruction may require a different period.
Our retention principles
We keep personal data only while it is needed for the service, security, legal compliance, disputes or documented controller instructions. We minimise what is retained, restrict access and delete or anonymise data when the applicable period ends.
Where a landlord or organisation is controller, it remains responsible for deciding how long its tenancy and property records must be kept. Arxela applies this schedule unless the controller gives a lawful documented instruction requiring a different period.
Account and customer records
- Active account identity and configuration: for the life of the account.
- Closed account administration and acceptance evidence: normally six years after closure where needed to evidence the contract, policy acceptance, instructions or legal claims.
- Unverified or abandoned signup records: reviewed and deleted or anonymised when no longer needed for security, conflict handling or signup recovery, normally within 12 months.
Property-management service data
Property, contact, tenancy, agreement, compliance, maintenance, message, contractor, invoice and payment records are retained while the account is active and the controller requires them.
After account closure, active-system service data is returned where an available return method is requested and then scheduled for deletion, normally within 90 days. A controller instruction, statutory retention duty, legal hold or unresolved dispute may extend that period. Records retained under a legal hold are isolated from ordinary product use.
Deleted and replaced operational records
- In-product Bin: eligible operational records are normally recoverable for 30 days and then purged.
- Replaced or archived compliance/document versions: retained as history while the relevant account and legal record require them, rather than silently overwritten.
- Private files: deleted with the linked record or account process, subject to legal hold and backup rotation.
Authentication and security data
- Signed login session: up to seven days or until logout.
- Password-reset token: expires after one hour; only its hash is stored.
- Email-verification token: expires after 24 hours; only its hash is stored.
- Portal invitation token: expires after 72 hours; only its hash is stored.
- Rate-limit and security events: normally up to 12 months, or longer where required for an active investigation or legal claim.
- Material audit logs: normally six years where needed for accountability, disputes, legal claims or controller instructions.
Emails, support and waiting lists
- Transactional email records: delivery metadata is kept only as long as needed for delivery, support, abuse prevention and provider retention; relevant audit evidence may be kept with the associated account record.
- Support and complaint correspondence: normally three years after resolution, or up to six years where it concerns a contract or legal claim.
- Full-management waiting list: until consent is withdrawn, the service opens and the communication purpose is complete, or 24 months pass without meaningful engagement. A minimal suppression record may be retained to honour an opt-out.
Cookies and browser storage
The session cookie lasts up to seven days. Setup-wizard drafts remain in the user’s browser until setup completes, the service discards the draft or the user clears browser storage. Google controls the reCAPTCHA cookie duration. See the Cookies Policy for details.
Backups and provider copies
When data is deleted from active systems, residual encrypted or protected copies may remain in provider backups until they rotate out. They are not restored for ordinary use and are normally removed within 90 days, unless a legal hold or provider incident-recovery requirement applies.
Deletion requests and legal holds
A valid deletion request is assessed against controller instructions, tenancy and property-record duties, security needs and legal claims. If complete deletion is not lawful, we will explain the relevant exception and restrict the retained data to the permitted purpose.
To request closure, deletion or a copy of relevant information, email hello@arxela.co.uk. If the data belongs to a landlord-controller, we may route the request to that landlord.
Review
This schedule is reviewed at least annually and whenever a material data flow, provider, legal requirement or product feature changes.