Data lifecycle
Retention Policy
How HireEGG determines how long account, interview, payment, support, and security records are kept.
- Applies to
- Users, candidates, enterprise customers, privacy teams, and reviewers.
- Effective
- July 17, 2026
- Document
- Operational policy · 2026.07
Browse all policies
01
Retention principles
HireEGG keeps personal data only while it is needed for the service, customer instructions, account administration, security, disputes, and legal obligations. The exact period can depend on the product, campaign settings, contract, data sensitivity, account status, and whether the record is part of a legal hold or active investigation.
02
Account and learner data
Profile, entitlement, progress, practice, CV, and generated-document data may be kept while an account is active and for a limited period afterward to support recovery, disputes, fraud prevention, and legal obligations. A valid deletion request starts the deletion or de-identification workflow unless an exception applies.
03
Enterprise candidate data
Candidate invitations, answers, transcripts, reports, consent records, reviewer notes, and integrity events are retained according to the hiring organization's configuration or signed agreement and applicable law. The organization should choose a period proportionate to the campaign purpose.
04
Recordings
The application default for stored interview recordings is 30 days. A customer configuration or signed agreement may set a different period. Recordings should not be kept longer merely because storage is available, and enabled campaigns should tell candidates the applicable period or retention criteria.
05
Payments, support, and security
- Payment, invoice, tax, and refund records are retained as required for accounting, tax, fraud, and dispute obligations.
- Sales and support records are retained while the enquiry is active and afterward when needed for follow-up, service history, or a legal claim.
- Authentication, audit, rate-limit, abuse, and security records are retained for a period proportionate to detection, investigation, incident response, and evidence needs.
06
Deletion, backups, and de-identification
Deletion removes or de-identifies data from active systems according to the applicable workflow. Copies may remain temporarily in protected backups until their normal expiry. HireEGG may retain de-identified or aggregated information that can no longer reasonably identify a person.
07
Exceptions
Data may be preserved for a legal hold, court or regulatory requirement, security incident, fraud investigation, unpaid account, contractual claim, or protection of rights. Access remains restricted and the data is deleted or de-identified when the exception ends.
08
Requests and configuration
Questions or requests may be sent to info@hireegg.com. Please do not send passwords, one-time codes, full payment-card details, or unnecessary identity documents by email.
Questions about this document?
Enterprise customers can also request a signed DPA, security review, or procurement materials.