Skip to content

Data retention

What we retain, and why

Raw source payloads. Every sync stores the raw payload it read from connected source, tenant-scoped, alongside the reconciled device records built from it. Raw source payloads are kept so that matching can be re-run against the original data. There is no automatic deletion schedule for them today.

Reconciled device and exception records. Kept for as long as the connection or customer is active, so the device matrix, exceptions, and billing reconciliation views always reflect full history rather than only the most recent sync.

Warranty records. The warranty expiry rows a customer uploads for a client's devices — serial, purchase date, expiry date, who uploaded them and when — are removed along with the customer's data.

Deletion

  • On customer offboarding: raw payloads and reconciled records are kept until deletion is carried out. No deletion deadline is stated here; the deletion commitment on the Trust page has not been confirmed yet, and no value is asserted until it is.
  • On request: a customer can ask the Ledger team, through their account contact, for deletion at any time, independent of offboarding.
  • Credentials specifically: deleting a departing customer's stored credentials is a manual action by the Ledger team on request, with no automatic schedule and no promised deadline. This is the same position stated in Security.

Export anytime

Nothing here is a lock-in mechanism. The table views in the app — the device matrix, exceptions, billing reconciliation — export to CSV or XLSX on demand (see exports), so a customer can take a copy of the data shown in each table view, up to 50,000 rows per export, at any point before, during, or instead of requesting deletion.

Encryption of what we retain

Every stored connection credential is encrypted per customer with a fresh data key generated at encryption time and bound to that customer, so a mismatched customer id makes decryption fail outright. The data key is wrapped by a managed key store, and only the wrapped key is stored beside the credential; the plaintext data key is never cached, logged, or stored. See the questionnaire for the full encryption and access control picture.