Skip to main content

Data Retention Configuration

Zipline can be configured to delete candidate, employee or requirement level data based on triggers and retention rules.

Written by Louis Docherty

To set up data retention rules for your business, review the notes in this article. At the bottom of this article, click the button to download the data retention workbook. Once completed, send this to [email protected]

Candidate Records (Never Hired)

Scope

If enabled, applies only where a person:

  • Never converted to an employee, and

  • Has all applications archived

Trigger

Application archiving - the retention period starts from the most recent archived application date.

Data Destruction

The entire candidate record, including all their details (name, phone, etc), all applications for that candidate and all compliance records and documents.


Employee Records (Terminated / Archived)

Scope

If enabled, applies to people:

  • Who were employed and later terminated or archived.

  • Have all applications archived (if any).

  • Are past the defined retention period for candidate records (if they have applications)

Trigger

Employee archived or lifecycle changed to terminated - The retention period starts from the employee archived date or termination date (whichever is earlier).

Data Destruction

The destruction scope is always the entire employee record, including all their details (name, phone, etc), all applications attached to that employee and all compliance records and documents.


Requirement-Level Data

Scope

Applies to individual compliance records for candidates and employees.

Trigger

The retention period starts when a requirement reaches a finalised status (ie. Approved, Exempted, Rejected)

Configuration

Select whether deletion applies to:

  • the entire requirement, or

  • documents only

Note: If the entire requirement is destroyed, and it is currently required for compliance, the employee will become non-compliant.

Data Destruction

Entire requirement - All compliance records for this requirement are removed. All entries in the activity log are removed. All documents are deleted.

Documents only - Documents are deleted, including any AI data. Field data for the requirement is retained.

To allow for processing checks and accounting for any admin errors, we strongly recommend keeping data for at least 2 weeks.

Additional Notes

  • Zipline may opt to keep the minimum de-identified data needed for billing and reporting.

  • Should a specific aspect of data being destroyed be required for a certain use, please extract a report before it is deleted.

  • All data destruction occurs at the person or requirement level. If you want to consider document types, consider the types of documents requested for specific requirements and the purpose of these documents in meeting the requirements.

Did this answer your question?