This document states how long UDISOFTBOX CONSULTORIA E TECNOLOGIA LTDA ("INGESTIA") keeps each record it creates while operating the ingestia.io platform, why it keeps it and on which legal basis — and what happens when the deadline passes. It forms part of the Privacy Policy.
The table in section 2 is not descriptive: it is the same list the purge program reads in order to delete. The deadline published here and the deadline executed by the system are, by construction, the same value.
1. The two sides of the line
INGESTIA handles two very different sets of data, and retention works in opposite ways for each:
| Who sets the deadline | Where it is described | |
|---|---|---|
| The Customer's business data (what they load, transform and analyse) | The Customer. INGESTIA is the processor; the deadline is the controller's instruction | The Data Processing Agreement (DPA) and the environment's own settings |
| The Platform's operational records (audit, runs, deliveries, alerts, website telemetry) | INGESTIA, through the table below | This document |
INGESTIA does not delete on its own initiative the business data inside an active customer's environment. Doing so would mean deciding, in the controller's place, the end of a processing activity that is not ours.
2. Deadlines for operational records
| Record | Deadline | What for | Legal basis |
|---|---|---|---|
| Audit trail (who did what, with the SQL and the cost of the run) | 730 days | Incident investigation and accountability | Legal obligation/record of operations (art. 7, II and art. 37) and legitimate interest (art. 7, IX) |
| Report run that was delivered (the number that reached the page) | 365 days | Proof of what was delivered to the Customer | Legitimate interest and regular exercise of rights (art. 7, IX and art. 10) |
| Dashboard run (materialised snapshot and cost) | 90 days | Operational cache and refresh history | Legitimate interest (art. 7, IX) |
| Delivery receipt (e-mail, WhatsApp, webhook) | 180 days | Proof and tracing of the delivery | Legitimate interest (art. 7, IX) |
| Alert firing | 180 days | History of what fired, when and to whom | Legitimate interest (art. 7, IX) |
| Commercial enquiry that did not convert | 730 days | Prospecting; once the deadline passes without a contract, it leaves on minimisation grounds | Consent and/or legitimate interest (art. 7, I and IX), with minimisation (art. 6, III) |
| Website visitor funnel event | 365 days | Measuring what works in our outreach across an annual cycle | Legitimate interest (art. 7, IX), with minimisation (art. 6, III) |
| Visitor per-page engagement (active time, scrolling, clicks) | 180 days | Diagnosing the journey and fixing the page | Legitimate interest (art. 7, IX), with minimisation (art. 6, III) |
The last two concern people who merely visited the website and never became customers. They are here with a deadline because collecting visitor behaviour with no discard deadline is the opposite of minimisation. What is collected is described in the Website Privacy Notice.
3. How the deadline is enforced
- The purge runs automatically, once a day.
- It counts the deadline from a date defined per record — creation, queueing, firing or last update, according to the nature of each one — and deletes whatever lies beyond it.
- It deletes in batches, with a ceiling per run. An accumulated backlog leaves over successive runs instead of a single operation that would lock the database.
- A failure is an incident, not silence. If the purge of any record fails, the run is marked as failed and flagged to operations. A purge that does not purge is a broken promise to the data subject, and it cannot end by reporting success.
Until October 5, 2026 the first six deadlines in this table were declared internally and were not executed by any routine. The publication of this document accompanies the entry into operation of the automatic purge. We record the date because transparency about a deadline includes transparency about when it began to be met.
4. What has no deadline, and why
- Ingestia Academy certification credentials. They are a public record, verifiable by third parties, and live until any revocation. On account deletion the credential is not deleted: it is anonymised — the holder's name leaves, the verification keeps answering. The opposite would leave an orphan credential bearing the name of someone who asked to be erased.
- Account and contracting records (registration data, billing, contracts). They follow the applicable statutory and limitation periods, not a deadline of our choosing.
- Academy exam and quiz attempts and Academy telemetry have a declared deadline (730, 730 and 365 days) and are not yet purged automatically: they belong to another area of the product, whose purge depends on review by the people who built it. That is declared in the code, with the reason written out, rather than omitted.
5. Backups
A backup is not a working copy. When a record is deleted from the active database, it may remain for a time in a backup until that backup's cycle ends. During that period the copy is isolated, does not return to ordinary use and does not feed any feature. This is the treatment set out in the DPA.
6. End of contract and deletion requested by the data subject
- End of contract: the Customer may export their data during the term and for 30 days after termination; after that, active data is deleted within 30 days, as set out in the DPA.
- Deletion requested from inside the Platform: a data subject holding the owner role may request deletion of the environment and the account from the settings screen itself, and it is processed immediately, with no waiting period. That is a request by the data subject, not the commercial termination described above — which is why there is no 30-day window.
- Request to the Data Protection Officer: any data subject may exercise the rights in art. 18 of the LGPD through the privacy channel, including erasure, confirmation of processing and portability.
7. Changing a deadline
Changing a deadline in this table is a change to the system, not just to the text: it is the same list. A material change is published here with a new update date, and is recorded in the Version History.
8. Contact
Data Protection Officer: Encarregado de Dados (DPO) — encarregado@ingestia.io · Channel: privacidade@ingestia.io