Retention and deletion
Choose how long Agoo keeps visits, photos, ID images and other data, and how deletion, legal hold and exports work.
Agoo is in early access. This page describes the feature as it ships to early-access organisations; screens are illustrative.
Act 843 expects you to keep personal data only as long as you need it. In Agoo, you set how long each kind of data is kept, and deletion then happens automatically, on schedule, with every deletion logged.
Set retention in Console → Settings → Data & privacy.
How long you can keep visitor data
Your plan sets the longest retention period you can choose for visitor data. You can always choose a shorter period.
| Plan | Visitor history |
|---|---|
| Free | 3 months shown |
| Starter | 12 months |
| Growth | 24 months |
| Pro | Up to 5 years |
| Enterprise | Custom, with legal hold |
On Free, the console shows the last 3 months of visit history. Older records aren't deleted: they're kept, hidden, and come back when you move to a paid plan.
After a move to a lower plan
Moving to a lower plan never deletes data by itself. That's true for a move to Free, whether after a trial, a missed payment or cancelling, and for a move to a cheaper paid plan, such as from Pro to Starter.
- What you see follows the new plan. Its visitor history decides what the console, exports and the API's lists show. Older records are kept, hidden, and come back when you move to a plan with a longer history.
- Your retention settings don't change. If one is longer than the new plan's maximum, for example 5 years after a move from Pro to Starter's 12 months, it keeps working as before: it only ever deletes records older than the period you chose. Console → Settings → Data & privacy shows that older records are hidden by your plan.
- New settings stay within the plan. To change a period, choose one up to the new plan's maximum.
- Requests from individuals are complete. Data subject requests and erasure cover hidden records too.
- You can still take everything with you. A full organisation export includes hidden records, on every plan.
Data is deleted only by your own retention settings, by an Owner's request to delete it, or when the organisation is deleted.
The audit trail has its own retention: 7 days on Free, 90 days on Starter, 1 year on Growth, 3 years on Pro and up to 7 years on Enterprise. See Audit trail.
Set retention by kind of data
Different data deserves different periods. A visit record may be useful for a year; a photo of someone's ID rarely is.
| Kind of data | Counted from | What to consider |
|---|---|---|
| Visit records | When the visit ended | Who came, when, and who they saw. Often kept longest, for security and reporting. A visitor goes with their last visit. |
| Visitor photos | When the photo was taken | Useful on the day for the badge. Consider a much shorter period. |
| ID images | When the image was taken | Deleted automatically on your schedule. The default is 24 hours. |
| ID numbers | The visitor's last visit | Stored masked and encrypted. Keep them only if your policy requires it. |
| Answers to your questions | When the visit or booking ended | Each question can have its own, shorter period. See Forms and fields. |
| Bookings | When the meeting ended | Or when it was cancelled, declined or expired. |
| Deliveries | When the package was collected | Or when it arrived, if nobody collected it. |
| Clock-ins and clock-outs | When the punch happened | Usually kept in line with your payroll and employment records. |
| Clock-in selfies | When the selfie was taken | Also set in Settings → Attendance. |
| Clock-in locations | When the punch happened | The coordinates go; whether the punch was inside the site stays. |
| Messages sent | When the message was sent | The address and text of emails, SMS and WhatsApp messages go; the record that a message was sent, and its cost, stays. |
| QR code scans | When the scan happened | 2 years by default. No IP addresses are kept. See Tracked codes. |
| Audit trail | When the entry was made | 1 to 7 years, or until deleted another way. The oldest entries go first, and the chain still verifies. |
Open Console → Settings → Data & privacy
You need to be an Owner or Admin.
Choose Change next to a kind of data
Pick a period. Your plan's maximum is shown for visitor data, and longer periods aren't offered.
Check what it deletes, then save
Before you save a shorter period, Agoo counts the records it would delete at the next run, within the hour. If there are any, tick the box to confirm, then Save and delete.
The new periods apply to all existing data as well as new data. A longer period keeps what's still there; it can't bring back what's already gone.
How deletion works
- Automatic, every hour. Deletion runs on its own; nobody has to remember.
- Logged. Each run is recorded in the audit trail with how many records of each kind went, and listed under Deleted on schedule in Data & privacy, so you can show auditors your rules are working.
- Complete. A visit goes with its timeline, consents and photos; personal details in audit entries about it are blanked, and the chain stays valid. A visitor's own record goes once they have no visits, bookings or watchlist matches left.
- Staff photos follow the person. A profile photo that's replaced or removed is deleted within the hour, and a person's photo is deleted when they're deactivated. Legal holds apply.
- Permanent. Deleted data can't be recovered from Agoo. Copies in encrypted backups expire within a further 30 days and aren't restored in the meantime except to recover from an incident.
Legal hold (Enterprise)
When you're involved in an investigation, dispute or regulatory request, a legal hold stops scheduled deletion and erasure of the records you place it on until you lift it.
In Console → Settings → Data & privacy → Legal holds, choose Place a legal hold, then what it covers: the whole organisation, a site, a person in your directory or a visitor, and a reason. Owners and Admins can see the reason. Placing and lifting a hold are recorded in the audit trail.
When you lift a hold, scheduled deletion covers what it kept from the next run. A hold placed before a move to another plan stays until you lift it.
Export your data
You can export your data at any time, on any plan. That includes after you cancel: your organisation moves to the Free plan with its data kept.
- Reports and lists export from the console to CSV, Excel or PDF. Exports follow role-based masking, so personal data someone isn't allowed to see stays masked, and cover the visitor history your plan shows.
- A full organisation export contains every record Agoo keeps for your organisation, including records hidden by your plan's history. Owners and Admins request it on any plan, Free included, with Export everything in Console → Settings → Data & privacy. It's always available: before you ask for your organisation to be deleted, after you cancel, and for 30 days after the agreement ends.
- It's a ZIP file: one CSV file per kind of record (spreadsheets open them), the photos, signatures and documents still kept, and a guide to what's inside.
- It leaves out passwords, keys and other secrets, face templates, and full ID numbers, which never leave Agoo; their last four characters are included. Clock-in badges, PINs, NFC cards and API keys are listed (whose, what kind, when they were issued, used and revoked), never the code or key itself.
- Agoo emails you when it's ready. The download is in the console, so you sign in to take it, and it's there for 7 days. One export is prepared at a time.
- Every export is recorded in the audit trail.
- For one person, use a data subject request to gather everything held about them.
Shortening a period deletes data
If you shorten a retention period, older data is deleted at the next scheduled run and can't be recovered. Export anything you need to keep first.
Deleting your organisation
Cancelling your subscription doesn't delete your data. To delete the whole organisation, the Owner asks for it at the bottom of Console → Settings → Billing or in writing, for example by email to agoo@ardentafrica.com. We confirm the request with the Owner first.
- We complete the deletion within 30 days of the request.
- We keep only what the law requires us to keep, such as invoices and tax records, and a record that the deletion took place.
- Copies in encrypted backups expire within a further 30 days.
Request a full organisation export before you ask: it includes records hidden by your plan. Deletion can't be undone.