Overview
This policy explains how retention, deletion and audit evidence are established for OpsRabbit deployments. Because customers commonly control the hosting environment, the final schedule must be recorded for each deployment rather than assumed from a universal default.
The policy covers data categories, retention decisions, deletion, backups, legal holds and security logging.
Data minimization
OpsRabbit is designed to use the operational signals and contextual evidence required for an authorized task. Customers control connected data sources, user permissions and the model endpoint in the documented customer-hosted deployment.
Audit events
- User and administrative activity
- Agent execution and tool calls
- Model request metadata and output references, subject to configured safeguards
- Approvals, denials and policy decisions
- Integration, error and security-relevant events
Retention and deletion
Retention for customer-hosted logs, databases, backups and model-provider records is configured by the customer and relevant service provider. OpsRabbit provider retains only data needed for agreed delivery, support, security or legal obligations and deletes or returns it under the DPA and agreement. Specific periods must be documented per deployment.
Access and export
Audit data should be protected from unauthorized alteration, limited to authorized roles and made available for customer monitoring or SIEM integration where supported by the deployed architecture.
Retention schedule requirements
Each deployment must document the system of record, data category, purpose, owner, configured retention, deletion mechanism, backup behavior and applicable legal hold. OpsRabbit provider does not prescribe a universal retention period for customer-hosted data because customers control the infrastructure and may have different regulatory needs. Retention must be no longer than necessary for the documented purpose.
Deletion process
Deletion requests are authenticated and scoped before execution. Customer-hosted primary data is deleted by the customer using platform and database controls. OpsRabbit provider deletes customer data in OpsRabbit provider-controlled support or delivery systems when no longer required, subject to legal obligations and backup lifecycle. Where immediate deletion from immutable backup is impracticable, the data remains protected and is not restored except for recovery.
Logging standard
Logs should record timestamp, actor or service identity, action, target, result, policy decision and correlation identifier. Sensitive payloads are minimized; credentials and secrets must not be intentionally logged. Time synchronization, access restriction, integrity protection and monitoring are configured by the controlling party. Security-relevant events should be retained long enough for investigation and customer obligations.
Review and legal hold
Retention settings and log coverage are reviewed during deployment and after material data-flow changes. A documented legal or security hold may suspend normal deletion for the limited data and period required. Holds are authorized, access-restricted, reviewed and released when the basis ends.