The values in brackets need an owner-approved data map and a tested offboarding workflow. Camplax must not describe provider snapshots as point-in-time recovery, or a placeholder file as a usable database export.
1. Retention principles
Camplax keeps information only for as long as needed to provide the service, meet documented security and operational needs, resolve disputes, and comply with law. The final policy must name the record owner, retention period, deletion trigger, and backup handling for each category below.
| Information | Draft retention rule to complete |
|---|---|
| Account, team, and project metadata | While the account is active, then [[approved period]] for security, audit, and legal records. |
| Customer code, files, database data, and deployment configuration | Until project deletion is completed, then deleted from active systems within [[approved period]]. |
| Security, access, and audit events | [[Approved period]], with access limited to authorised operations and security staff. |
| Billing and tax records | [[Approved period required by the applicable jurisdiction]]. |
| Support communications | [[Approved period]], unless longer retention is needed for an open issue, abuse investigation, or legal obligation. |
2. Project deletion
A project deletion request must be confirmed by an authorised owner through a step-up or capability-based check. Camplax then performs tracked offboarding: disable and remove compute, revoke credentials and sessions, remove project data from database and storage, detach or remove domains, and delete or isolate the related platform records. Failures must be retried durably, not silently abandoned.
The customer should receive a completion receipt that distinguishes completed steps from queued retries. Deletion does not mean an operator may continue to use old credentials, and it does not guarantee an instant erasure from every legally required record or immutable provider backup.
3. Backups, restore, and exports
Database-provider snapshots can be useful for disaster recovery, but they are not point-in-time recovery. Changes after the most recent snapshot may be lost. Camplax does not advertise a customer database export, restore, or point-in-time recovery capability until the exact workflow has been implemented, access-controlled, and tested in a documented recovery drill.
4. Requests and questions
Account owners can request project deletion through the verified account path. For privacy requests, use [[privacy contact email]]. Camplax must verify authority before deleting or disclosing project data and must keep a minimal audit record of the request and outcome.