These periods match the register approved on 14 August 2026. A documented legal hold can pause deletion. Tenant intake stays off.
Retention register
| Category | Default period | Trigger | Automated action |
|---|---|---|---|
| Pending application | 15 minutes | Creation | Delete the unfinished application |
| Email verification code | 24 hours maximum | Expiry | Delete the code |
| Tenant access token | 30 days | Creation or revocation | Delete or revoke the token |
| Unshared document request | 30 days | Request | Expire the request |
| Tenant document | 30 days or request expiry | Upload | Remove the file and its record |
| Active rental application | Until the property closes | Submission | Keep while the listing is active |
| Closed or declined application | 6 months | Stage change | Erase application data |
| Rental Passport | Until erasure or inactivity | Last activity | Notify, then erase |
| First-party analytics | 13 months | Event time | Delete the event |
| Agency account | Contract plus claims period | Contract end | Erase or anonymise account data |
| Billing records | Statutory accounting period | Invoice date | Restrict, then delete |
| Audit event | Security and claims period | Event time | Remove personal identifiers where possible |
| System event | 13 months unless incident evidence | Event time | Delete or archive the incident record |
How deletion works
Expired records and private document files are deleted automatically. If you erase your Passport, we delete data you control immediately unless a documented legal hold applies.
Legal holds
A legal hold must be documented, scoped, and time-limited. Failed cleanups create a system event for an operator.
Not legal advice. Billing and audit exceptions remain reviewable before intake is enabled.