Skip to content

TOMOPACT / DATA MANAGEMENT

Data management policy

How data is retained, deleted, recovered, and handled when cases are archived.

Updated: October 4, 2026

Scope

This policy covers Tomopact accounts, workspaces, cases, conditions, discussions, approval and task history, attachments, and notification settings. Other Stratum Flow services follow their respective retention policies.

Deletion and recovery requests (normally within 14 days)

Deleting a workspace, an uploaded individual file, or an account makes it unavailable in the normal app. Workspace deletion stops access and notifications for everyone. Account deletion stops sign-in and notifications to that person. File deletion stops new downloads and viewing. An already issued download link may remain usable until it expires, for up to 60 seconds.

As a rule, submit a recovery request to support within 14 days of requesting deletion. This is the request deadline, not a guarantee that recovery will be completed within 14 days. Recovery is subject to identity and authorization checks and an assessment of whether restoration is possible. Contact support with the affected workspace, file, or account and the approximate deletion time. Recovery requires support review and processing; the app does not provide a recycle bin or automatic restoration.

Recovery is unavailable once 30 days have elapsed from the deletion time. During the next 30 days, within 60 days of deletion, the affected records in the active database and attachment originals and previews are physically deleted in stages. Periods are measured as elapsed time from the deletion timestamp.

Recovery and storage usage

Restoring a workspace does not restart a canceled subscription, old invitation links, or queued notifications. Sign in again after account recovery. External service connections may need to be configured again.

An individually deleted file continues to count toward storage while retained for recovery. Its capacity is released when physical deletion completes. Files used by a revision submitted for approval cannot be deleted individually because they form part of that revision's history. Incomplete or failed uploads are removed after expiration and are not recoverable.

Archiving and notifications

Archiving a case retains its content, approval and task history, and attachments while stopping ordinary edits, approvals, and task updates. Retained attachments count toward storage. Archiving alone does not schedule physical deletion after 30 days.

While a case is archived, notifications for conditions, discussions, notes, approvals, tasks, case updates, and invitation emails are suppressed. Its Web notifications are hidden from the inbox and unread count. Restoring the case does not replay old notifications; new actions follow the notification settings. Emails and external messages already delivered cannot be recalled.

Backup deletion

Daily database backups are retained for up to 30 days, and point-in-time recovery (PITR) data for up to 7 days, for disaster recovery. Physical deletion from active systems is completed within 60 days of deletion. Any remaining backup copies expire within the following 30 days, within 90 days of deletion in total. Backups do not extend the normal user recovery period.

For deletions accepted before this change, any previously recorded deletion deadline is not extended.

Disaster recovery from a backup does not reactivate deleted data for normal use. Restored data is checked in isolation and reconciled with deletion status and access permissions before being used by the service.

Shared history and required records

Account deletion alone does not remove author names, responses, or approval and task history from shared cases used by other participants. Shared history follows its workspace's retention and deletion policy. Leaving a workspace, revoking participation, or disconnecting notifications stops the relevant access or connection; it does not delete the case or shared history.

Payment and billing records required by law are retained for the applicable period. Security access logs are retained for up to 90 days. Records outside normal deletion and recovery are managed for their specific purposes.

Recovery requests and contact

Follow support's instructions for identity verification. Do not include passwords or authentication tokens in your request.

Contact support