Data Retention Schedule
This schedule states what BeaconRelay deletes automatically today, what remains as verifiable evidence, and which launch periods still require an operational decision.
- Effective
- 2026-09-26
- Contact
- legal@beaconrelay.dev
1. Enforced payload windows
The clock begins when BeaconRelay receives the event. Cleanup runs periodically. When an event is Delivered or Dead Letter and its deadline has passed, BeaconRelay erases the encrypted Salesforce payload and encrypted receiver response bodies. If an event is still Pending, Retrying, or Blocked, content remains temporarily because it is required to complete delivery; it becomes eligible for erasure after reaching a terminal state. An expired Dead Letter cannot be redriven.
2. What remains after payload expiry
BeaconRelay preserves non-content evidence so customers can prove and diagnose transport without retaining the original body: event ID, channel and object/operation labels, replay identity, timestamps and states, SHA-256 fingerprint, signature and signing-key ID, delivery attempts and HTTP status, failure classification, route history, incidents, signed receipts, and payload-expiry timestamp.
Before expiry, payload and captured response content are stored only in encrypted form. At expiry the encrypted content itself is removed; metadata and cryptographic proofs cannot reconstruct it.
3. Category schedule
| Category | Current rule | Trigger |
|---|---|---|
| Salesforce payload and receiver response content | 7, 14, 30, or contracted 90+ days; terminal events only | Plan at event receipt and terminal state |
| OAuth access and refresh tokens | Until access revocation or Salesforce organization deletion | Customer action or authorization failure |
| Organization configuration, topics, destinations, events, attempts, incidents and proofs | While the organization exists; deleted from BeaconRelay’s live database when the organization is deleted | Customer organization deletion |
| Account profile and legal acceptance record | While the account exists and as required to establish the agreement | Account closure request and legal obligations |
| Billing and invoice records | As required for subscription administration, tax, accounting, disputes, and applicable law | Subscription/account termination plus statutory period |
| Transactional email and delivery audit | While needed for security, delivery diagnosis, and account administration | Purpose completion or account closure instruction |
| Backups | Launch period not yet finalized | Backup rotation |
4. Organization deletion
Deleting a Salesforce organization stops its listener, attempts remote topic and OAuth revocation, and deletes its topics, receiver, gateway events, delivery attempts, route changes, replay cursor, monitoring events, and incidents from the live BeaconRelay database. Remote revocation can fail if Salesforce is unavailable; BeaconRelay reports that outcome.
5. Account closure and legal holds
Self-service account deletion is not currently available. An account owner may request closure, export guidance, or deletion at legal@beaconrelay.dev. Provider may retain narrowly scoped records when required by law, to resolve payment disputes, enforce the agreement, or preserve evidence under a legal hold. Restricted records will not be used for unrelated purposes.
6. Launch commitments still required
- Set and technically enforce a maximum backup lifetime.
- Set fixed periods for account records, email audit, billing metadata, and integrity evidence after account closure.
- Implement a documented account deletion workflow and deletion confirmation.
- Name the infrastructure host, storage locations, backup locations, and international-transfer safeguard.
Until those controls exist, BeaconRelay must not advertise a shorter period than this page or represent that all account data is automatically deleted on a fixed schedule.