Trust and legal

Data Retention Policy

This policy describes how FormEsque keeps active records, temporary recovery data, deleted drafts, signed legal records and operational metadata.

Effective July 13, 2026Last updated July 13, 2026Version 1.0

1. Retention principles

FormEsque retains information only while it is reasonably needed to provide the service, follow customer instructions, preserve transaction integrity, maintain security, meet legal obligations or resolve disputes. Retention can vary by record type, workspace configuration, contract and applicable law.

2. Active workspace records

Active proposals, templates, invoices, customer records, settings and related history normally remain available for the life of the customer account unless an authorized user deletes or archives them through a supported control. Organization permissions continue to govern access during that period.

3. Drafts, trash and temporary cache

Where the recently-deleted workflow is enabled, eligible unsigned records can remain recoverable for up to 30 days before permanent deletion is offered or an authorized user removes them. Temporary offline recovery copies may remain in the browser until synchronization, replacement, expiration or manual browser clearing.

4. Signed and legal records

Signed documents, signature records, sent invoices, confirmed payment history and supporting audit events are treated as retained legal records. Normal user deletion archives these records instead of erasing them. FormEsque does not currently apply automatic deletion to completed signed records; removal requires a reviewed legal, contractual or privacy basis and must preserve required evidence.

5. Operational and delivery metadata

Security, audit, email-delivery, webhook, error and operational records are retained for troubleshooting, abuse prevention, reliability and compliance. FormEsque limits stored webhook data to necessary metadata where supported and does not intentionally store raw message bodies in the webhook processing ledger.

6. Account closure and legal holds

After account closure, information may remain for a reasonable transition period and longer where required to preserve signed transactions, satisfy law, prevent fraud, collect amounts or resolve disputes. A legal hold, investigation or backup lifecycle may delay deletion. Customers should export needed records before access ends.

7. Backups and deletion requests

Deletion from active systems does not immediately remove disaster-recovery copies. Backup copies are isolated from normal application access and age out through provider schedules. Requests should identify the organization, workspace and records involved and must be verified before action. FormEsque may direct a document recipient to the organization that controls the record.