This document describes the technical retention implementation. It does not constitute legal advice. Consult qualified legal counsel for your specific obligations under GDPR or other applicable data-protection regulations.
Retention setting
Every org has aretention_days value for its Customer Voice submissions: an integer from 1 to 3,650, or null. The default is null — retain indefinitely — until an org owner or admin sets a value.
Configuring retention
The org-scoped settings endpoint authenticates with a bearer token and is available to the owner/admin (write) or owner/admin/auditor (read) roles. Check the current retention setting for an org:On-request deletion
Because automatic expiry is not yet enforced, deletion today is always explicit — issued by an org owner or admin. Both endpoints erase the matching rows synchronously (the erasure is complete by the time the response returns) and return200 OK.
Delete all Customer Voice submissions for an org:
404 either way — the response never discloses which.
Audit trail
Every export, deletion, and settings change is recorded internally in Mnemom’s governance audit log against the acting user and the org. This is a separate log from the general request-levelGET /v1/orgs/{org_id}/audit-log endpoint (which covers HTTP-request metadata, not this feedback-specific governance trail) — there is currently no dedicated customer-facing endpoint to query these particular records directly.
Related
- Customer Voice Privacy & Data Use — What is collected, consent, and data subject rights
- GDPR Right to Erasure — Right to erasure and full deletion cascade architecture
- EU AI Act Compliance — Article 50 audit-trail obligations