Speech data · Retention and deletion

Every recording has a retention window. Deletion is a contract term, with a certificate at the end.

Retention windows, deletion triggers, what happens to raw data, derived datasets and audit artifacts, and the handover at the end of the engagement, written into the DPA annex before the first recording.

Retention schedules and deletion triggers are set during scoping and documented in the DPA annex.

The lifecycle of one corpus
  1. Scoping

    Retention window, deletion triggers and the end-of-engagement choice written into the DPA annex.

  2. Engagement

    Collection, processing and delivery. Lifecycle tracked and auditable throughout.

  3. Engagement end

    Delete, return or retain, as chosen before the project started.

    • End of engagement
    • Client request
    • Expiry of the window
  4. Retention window

    Contractual, per data type. Audit artifacts may carry a separate window.

  5. Deletion

    Across production systems, backups and other storage, per the written procedure.

  6. Certificate

    Deletion certificate or attestation where contractually required.

Retention per engagement · regulatory

Retention is aligned to the engagement, to your policy and to the regulation that applies.

Retention policies for enterprise speech data vary by engagement based on client requirements, regulatory obligations, and the nature of the data processing activities.

Retention per engagement
Each project carries its own retention period, aligned to the specific needs of that engagement.
Scoping
Retention requirements are established during scoping with your legal, compliance and procurement teams, and documented in the contract.
Regulatory alignment
Retention schedules take into account GDPR, sector-specific regulations and internal retention policies.

Retention periods are defined contractually and included in the DPA Annex for internal review.

Deletion triggers · procedure · types · verification

Deletion follows a written procedure, from the trigger to the certificate.

Deletion obligations are documented in the DPA and enforced according to contractually defined procedures.

What the DPA distinguishes

Data typeOn a deletion triggerRetention note
Raw data Deleted per the written procedure, across production systems, backups and other storage The retention window set at scoping
Derived datasets Deleted with the raw data, or on their own window where the DPA says so Obligations may differ by type
Processed outputs Delivered outputs are yours; copies at YPAI follow the DPA Return or deletion at the end of the engagement
Audit artifacts Provenance and audit records may persist where contractually required A separate window, stated in the DPA

Specific deletion timelines and procedures are provided for internal review during scoping.

Client control definition · instruction · change

You define the lifecycle at scoping. Changes go through the amendment procedure.

Clients define retention and deletion requirements during scoping. These requirements are documented contractually and govern data lifecycle handling throughout the engagement.

Requirement definition
You specify retention periods, deletion triggers and end-of-engagement handling during scoping.
Instruction
Instructions on retention and deletion are given through the contractual documentation.
Change
Where requirements change during the engagement, the change goes through the amendment procedure in the engagement agreement.

Client control over retention and deletion is a negotiated component of the DPA and engagement agreement.

Audit and provenance separate window · documented

Audit records can outlive the raw data. The DPA says which, and for how long.

Audit trails and provenance records support compliance obligations and long-term traceability of dataset origins.

Separate retention
Provenance and audit records may be retained separately from raw data to support compliance, internal audit and external audit requirements.
Balance with deletion
The DPA states which audit artifacts are retained and for how long, so deletion obligations and audit retention hold at the same time.

Audit and provenance handling is defined contractually during scoping so it aligns with compliance obligations.

End of engagement delete · return · retain

At completion the data is deleted, returned or kept. Which one is decided before the project starts.

Data handling at project completion is defined contractually and varies by engagement type and client requirements.

  1. Delete

    Deletion occurs according to the timeline in the DPA and covers all data types and storage locations as specified.

  2. Return

    Handover procedures are defined contractually, including format, delivery mechanism and verification.

  3. Retain

    Data may be kept beyond completion for warranty, support or another defined purpose, documented contractually with its own window.

End-of-engagement actions are finalized during scoping and documented in the engagement agreement.

Retention and deletion

Windows, triggers and verification

How long is speech data retained?

Retention periods vary by engagement and are defined contractually during scoping. Retention is aligned to client requirements, regulatory obligations, and the nature of the engagement. Specific retention windows are documented in the DPA.

Can we enforce our own retention policy?

Yes. Client retention requirements are defined during scoping and documented contractually. We align our retention practices to your internal retention policies and regulatory obligations. Retention schedules are a negotiated component of the engagement agreement.

How do deletion requests work?

Deletion procedures are defined in the DPA and vary by engagement type. Deletion requests are handled according to contractually defined processes. We support deletion at the end of engagement, upon client request, or according to agreed retention triggers. Deletion handling is documented and auditable.

What happens to data after project completion?

End-of-engagement data handling is defined contractually. Options typically include return of data, secure deletion, or continued retention for a defined period. The chosen approach is documented in the DPA and agreed upon during scoping.

Are backups covered by deletion obligations?

Backup handling and deletion timelines are addressed in the DPA. Deletion obligations typically extend to backups, though backup deletion may follow a defined schedule due to technical constraints. Backup retention and deletion procedures are documented contractually.

How does audit retention affect deletion?

Audit trail and provenance records may be retained separately from raw data to support compliance obligations. The balance between deletion and audit requirements is defined contractually. We document which artifacts are retained for audit purposes and for how long.

Can deletion be verified?

Deletion procedures include verification steps defined in the DPA. We can provide deletion certificates or attestations where contractually required. Verification mechanisms are defined during scoping.

What if regulatory requirements change?

Changes to retention or deletion requirements due to regulatory updates are handled through contract amendment procedures. We work with your legal and compliance teams to document changes appropriately and keep the engagement compliant.

How are retention requirements documented?

Retention schedules are documented in the DPA Annex and referenced in the engagement agreement. Documentation includes retention periods, triggers for deletion, and responsibilities for data lifecycle management.

Can we extend retention beyond initial agreement?

Retention period extensions are handled through formal change procedures defined in the engagement agreement. Extensions require mutual agreement and are documented contractually.

What happens if we need early deletion?

Early deletion requests are handled according to the procedures defined in the DPA. We support early deletion where contractually feasible. The process and timeline for early deletion are defined during scoping.

How is deletion different from anonymization?

Deletion refers to removal of data from systems. Anonymization refers to transformation of data such that it cannot be linked to individuals. The DPA specifies which approach is used under which circumstances, and whether anonymized data may be retained.

Bring your retention policy. The lifecycle annex comes back with the scoping brief.

Retention windows, deletion triggers and the end-of-engagement choice are enough to start. The DPA annex follows from that.