Skip to content

Data retention and right to erasure

This page documents how long SkillFoundry keeps candidate and account data, and how it honors data-subject rights under GDPR / UK GDPR and CCPA / CPRA — the right to access, rectify, erase, port, restrict, and object.

Roles and who handles a request

For employer-run assessments, the hiring organization is the controller and SkillFoundry is the processor (a service provider under CPRA). That means:

  • A candidate's request is normally directed to the controller (your organization). SkillFoundry, as processor, assists you and acts on your instructions.
  • For self-serve candidates with no employer, SkillFoundry is the controller and handles the request directly.

The DPA sets out the obligation for SkillFoundry to forward any request it receives directly from your candidate, and to help you respond within the statutory deadline.

Retention schedule

Retention is policy-driven, with a defined period, description, and legal basis per data category:

Data category Default retention Legal basis
User account & profile data 7 years (2555 days) Contract performance and legitimate interest
Security & audit logs 7 years (2555 days) Legal obligation and legitimate interest
Task submissions & evaluations 3 years (1095 days) Contract performance
AI/chat conversations 1 year (365 days) Legitimate interest
Marketing preferences & communications 2 years (730 days) Consent

Additional operational retention applies to lower-level data: raw request/security telemetry is kept on a rolling basis measured in days (see Access and audit logging), and encrypted database backups are kept for up to 90 days and then roll off; there are no longer-lived weekly or monthly copies.

Behavioral evidence (evidence-based assessment)

Behavioral evidence and its protected artifacts are held in the behavioral evidence service with their own retention, enforced by a scheduled job:

Data Default retention Configurable per organization Measured from
Behavioral evidence (events and derived scoring data) 24 months 90 days to 36 months Newest evidence received for the attempt
Protected artifacts (diffs, test reports, AI transcripts) 12 months 30 days to 24 months, never longer than evidence Artifact upload
Pseudonymized research copies (practice attempts with research consent only) 36 months Not configurable Last evidence of the attempt

On request (for example account deletion), behavioral assessment evidence and its protected artifacts are deleted from live systems within 48 hours, and each erasure is recorded with a deletion receipt that contains no identifiers. Other account data is deleted or anonymized on the schedule described in this page. Legal holds block both expiry and erasure until released. Research use of practice attempts requires explicit, unbundled opt-in consent that can be withdrawn in Settings; withdrawal deletes research copies and any research data derived from them, while the attempt's own evidence keeps its standard retention.

Retention is configurable for enterprise

The periods above are platform defaults. Because the appropriate retention depends on your legal basis and jurisdiction, enterprise customers can agree shorter (or, where a legal-hold applies, longer) periods for their organization's data as part of the DPA. Do not retain assessment data longer than you can justify — over-retention is itself a compliance risk.

How retention is enforced

Retention runs are automated and each run is written to the audit trail (gdpr.retention_enforcement). Enforcement is category-aware rather than a blunt delete:

  • User data beyond the window: inactive-account purge.
  • Audit logs beyond the window: deleted after the legal-retention period.
  • Submissions beyond the window: anonymized, not deleted — the candidate identifier is hashed and code/feedback are redacted — so aggregate analytics and adverse-impact history survive without retaining identifiable candidate data.
  • Conversations beyond the window: deleted.

Data-subject rights

SkillFoundry implements the full set of GDPR data-subject rights, each producing an audit record:

Right (GDPR) CCPA/CPRA analog How it works
Access (Art. 15) Right to know Full export package assembled per user (see below)
Rectification (Art. 16) Right to correct Field-level corrections applied to the profile, audited
Erasure (Art. 17) Right to delete Soft-delete + related-data anonymization (see below)
Portability (Art. 20) — Export is machine-readable (structured JSON)
Restriction (Art. 18) — Request tracked as a data-subject request with status
Objection (Art. 21) Right to opt out Tracked; combine with consent withdrawal for monitoring

What an access/portability export contains

A data export assembles, in a single structured document with export metadata (subject id, date, version, data controller):

  • Personal / profile data
  • Consent records (type, status, timestamps, policy version)
  • The subject's audit-log history
  • Task data (created and, where applicable, assigned)
  • Submissions (including code, language, score, feedback, execution results)
  • Conversation history (messages with roles and timestamps)
  • Organization membership (role, join date)

Because it is JSON with stable keys, the same export satisfies both the access and the portability right.

How erasure actually works

The "right to be forgotten" is processed as a tracked request (gdpr.deletion_request → gdpr.deletion_completed) that:

  1. Marks the data-subject request in-progress.
  2. Soft-deletes the user record (the account is deactivated and delisted rather than hard-dropped, so referential integrity and in-flight obligations are preserved).
  3. Anonymizes or removes related artifacts — submissions are anonymized on the retention path (identifier hashed, content redacted); audit entries tied to the subject are anonymized rather than destroyed where they serve a legal-evidence purpose.
  4. Marks the request complete with a timestamp.

Honest note on erasure completeness

The deletion pipeline soft-deletes the account immediately and anonymizes submissions/audit records through the retention path. Full, synchronous cascade deletion of every related artifact (tasks authored, conversations, cached derivatives) across all stores is an area of active hardening on the roadmap. The 48-hour deadline is enforced and monitored for behavioral evidence and artifacts. For a contractual hard-deletion guarantee covering every other store, raise it in the DPA and your account team will confirm the current end-to-end scope in writing. We would rather commit to what we can verify than claim a clean wipe we cannot evidence.

Deletion, backups and restores

  • Live systems. On request, behavioral assessment evidence and its protected artifacts are deleted from live systems within 48 hours, unless a legal hold applies; this deadline is tracked and monitored per request. The account itself is deactivated immediately, and other account data is deleted or anonymized through the retention path described above (not within a 48-hour guarantee).
  • Backups: up to 90 days. Backups are not rewritten. They are generally kept for up to 90 days and roll off on their normal schedule, so deleted data leaves the backups within that time.
  • Restores re-apply deletions. Data in backups is not restored into live systems except for disaster recovery. Records of deletion requests are kept, and after a restore, before the restored systems are used, pending deletions are applied again.

Anonymization vs. pseudonymization

SkillFoundry supports both, and uses each deliberately:

  • Anonymization removes direct identifiers (email, name, picture, profile metadata) and hashes the id, tagging the record so it is provably de-identified — used when data should survive for analytics but the individual should not be re-identifiable.
  • Pseudonymization consistently hashes identifiers with a secret salt so records can still be correlated internally under controlled conditions — used where continuity matters but exposure should be reduced.

Consent is recorded per purpose (marketing, analytics, functional, performance, cookies, data processing, third-party sharing) with grant/withdraw status, timestamp, IP/user-agent, and the privacy-policy version in force at the time — so you can prove what a person agreed to and when. Withdrawal is a first-class action and is audited. Consent validity can be checked before a purpose-limited processing activity runs. See the behavioral monitoring privacy model for how consent interacts with monitoring.

Breach notification

If a personal-data breach is detected, SkillFoundry runs a severity assessment (affected-user count, data sensitivity, breach type, containment) that classifies severity, determines whether regulatory notification is required, and computes the 72-hour GDPR notification deadline. Detection and assessment are audited. Under the DPA, SkillFoundry notifies affected controllers without undue delay so you can meet your own notification obligations.

Privacy dashboard data

For any user, SkillFoundry can assemble a privacy-dashboard payload: current consent status across all purposes, the retention policy applicable to each data category, recent data-subject requests with status, and the categories of data held. This is the backend for a candidate-facing privacy view (see Candidate rights and appeals).

Current status and roadmap

  • In place: retention policy engine and automated enforcement; DSAR export/rectification/erasure logic; consent recording with policy versioning; breach severity assessment; PIA/DPIA tooling.
  • Roadmap / hardening: persisting consent and data-subject-request records to durable storage (today parts of this run in the service layer and should not be treated as the system of record until confirmed), exposing DSAR operations through a self-service candidate endpoint and admin console, and end-to-end verified cascade deletion. Confirm current status with your account team before relying on any single item for a regulated deadline.