Docs
Privacy and data

Retention and deletion

Choose how long Agoo keeps visits, photos, ID images and other data, and how deletion, legal hold and exports work.

Early access· P3For owners, admins and data protection leads

Agoo is in early access. This page describes the feature as it ships to early-access organisations; screens are illustrative.

Act 843 expects you to keep personal data only as long as you need it. In Agoo, you set how long each kind of data is kept, and deletion then happens automatically, on schedule, with every deletion logged.

Set retention in Console → Settings → Data & privacy.

How long you can keep visitor data

Your plan sets the longest retention period you can choose for visitor data. You can always choose a shorter period.

PlanVisitor history
Free3 months shown
Starter12 months
Growth24 months
ProUp to 5 years
EnterpriseCustom, with legal hold

On Free, the console shows the last 3 months of visit history. Older records aren't deleted: they're kept, hidden, and come back when you move to a paid plan.

After a move to a lower plan

Moving to a lower plan never deletes data by itself. That's true for a move to Free, whether after a trial, a missed payment or cancelling, and for a move to a cheaper paid plan, such as from Pro to Starter.

  • What you see follows the new plan. Its visitor history decides what the console, exports and the API's lists show. Older records are kept, hidden, and come back when you move to a plan with a longer history.
  • Your retention settings don't change. If one is longer than the new plan's maximum, for example 5 years after a move from Pro to Starter's 12 months, it keeps working as before: it only ever deletes records older than the period you chose. Console → Settings → Data & privacy shows that older records are hidden by your plan.
  • New settings stay within the plan. To change a period, choose one up to the new plan's maximum.
  • Requests from individuals are complete. Data subject requests and erasure cover hidden records too.
  • You can still take everything with you. A full organisation export includes hidden records, on every plan.

Data is deleted only by your own retention settings, by an Owner's request to delete it, or when the organisation is deleted.

The audit trail has its own retention: 7 days on Free, 90 days on Starter, 1 year on Growth, 3 years on Pro and up to 7 years on Enterprise. See Audit trail.

Set retention by kind of data

Different data deserves different periods. A visit record may be useful for a year; a photo of someone's ID rarely is.

Kind of dataCounted fromWhat to consider
Visit recordsWhen the visit endedWho came, when, and who they saw. Often kept longest, for security and reporting. A visitor goes with their last visit.
Visitor photosWhen the photo was takenUseful on the day for the badge. Consider a much shorter period.
ID imagesWhen the image was takenDeleted automatically on your schedule. The default is 24 hours.
ID numbersThe visitor's last visitStored masked and encrypted. Keep them only if your policy requires it.
Answers to your questionsWhen the visit or booking endedEach question can have its own, shorter period. See Forms and fields.
BookingsWhen the meeting endedOr when it was cancelled, declined or expired.
DeliveriesWhen the package was collectedOr when it arrived, if nobody collected it.
Clock-ins and clock-outsWhen the punch happenedUsually kept in line with your payroll and employment records.
Clock-in selfiesWhen the selfie was takenAlso set in Settings → Attendance.
Clock-in locationsWhen the punch happenedThe coordinates go; whether the punch was inside the site stays.
Messages sentWhen the message was sentThe address and text of emails, SMS and WhatsApp messages go; the record that a message was sent, and its cost, stays.
QR code scansWhen the scan happened2 years by default. No IP addresses are kept. See Tracked codes.
Audit trailWhen the entry was made1 to 7 years, or until deleted another way. The oldest entries go first, and the chain still verifies.

Open Console → Settings → Data & privacy

You need to be an Owner or Admin.

Choose Change next to a kind of data

Pick a period. Your plan's maximum is shown for visitor data, and longer periods aren't offered.

Check what it deletes, then save

Before you save a shorter period, Agoo counts the records it would delete at the next run, within the hour. If there are any, tick the box to confirm, then Save and delete.

The new periods apply to all existing data as well as new data. A longer period keeps what's still there; it can't bring back what's already gone.

How deletion works

  • Automatic, every hour. Deletion runs on its own; nobody has to remember.
  • Logged. Each run is recorded in the audit trail with how many records of each kind went, and listed under Deleted on schedule in Data & privacy, so you can show auditors your rules are working.
  • Complete. A visit goes with its timeline, consents and photos; personal details in audit entries about it are blanked, and the chain stays valid. A visitor's own record goes once they have no visits, bookings or watchlist matches left.
  • Staff photos follow the person. A profile photo that's replaced or removed is deleted within the hour, and a person's photo is deleted when they're deactivated. Legal holds apply.
  • Permanent. Deleted data can't be recovered from Agoo. Copies in encrypted backups expire within a further 30 days and aren't restored in the meantime except to recover from an incident.

When you're involved in an investigation, dispute or regulatory request, a legal hold stops scheduled deletion and erasure of the records you place it on until you lift it.

In Console → Settings → Data & privacy → Legal holds, choose Place a legal hold, then what it covers: the whole organisation, a site, a person in your directory or a visitor, and a reason. Owners and Admins can see the reason. Placing and lifting a hold are recorded in the audit trail.

When you lift a hold, scheduled deletion covers what it kept from the next run. A hold placed before a move to another plan stays until you lift it.

Export your data

You can export your data at any time, on any plan. That includes after you cancel: your organisation moves to the Free plan with its data kept.

  • Reports and lists export from the console to CSV, Excel or PDF. Exports follow role-based masking, so personal data someone isn't allowed to see stays masked, and cover the visitor history your plan shows.
  • A full organisation export contains every record Agoo keeps for your organisation, including records hidden by your plan's history. Owners and Admins request it on any plan, Free included, with Export everything in Console → Settings → Data & privacy. It's always available: before you ask for your organisation to be deleted, after you cancel, and for 30 days after the agreement ends.
    • It's a ZIP file: one CSV file per kind of record (spreadsheets open them), the photos, signatures and documents still kept, and a guide to what's inside.
    • It leaves out passwords, keys and other secrets, face templates, and full ID numbers, which never leave Agoo; their last four characters are included. Clock-in badges, PINs, NFC cards and API keys are listed (whose, what kind, when they were issued, used and revoked), never the code or key itself.
    • Agoo emails you when it's ready. The download is in the console, so you sign in to take it, and it's there for 7 days. One export is prepared at a time.
  • Every export is recorded in the audit trail.
  • For one person, use a data subject request to gather everything held about them.

Shortening a period deletes data

If you shorten a retention period, older data is deleted at the next scheduled run and can't be recovered. Export anything you need to keep first.

Deleting your organisation

Cancelling your subscription doesn't delete your data. To delete the whole organisation, the Owner asks for it at the bottom of Console → Settings → Billing or in writing, for example by email to agoo@ardentafrica.com. We confirm the request with the Owner first.

  • We complete the deletion within 30 days of the request.
  • We keep only what the law requires us to keep, such as invoices and tax records, and a record that the deletion took place.
  • Copies in encrypted backups expire within a further 30 days.

Request a full organisation export before you ask: it includes records hidden by your plan. Deletion can't be undone.

On this page