Effective Date: August 18, 2026
This page describes exactly what Klyverity does about document retention, and which retention decisions remain yours. It is written to be precise rather than reassuring, because a retention control that is misunderstood is worse than one that is absent.
Your organization sets a single retention period. Klyverity applies that period to every document in the organization, measured from the date the document is uploaded.
Concretely: a document uploaded on 1 March under a 25 year period is assigned a retention date of 1 March, 25 years later. The same period is applied to every document, of every type, in that organization.
Klyverity does not model record types, and it does not model trigger events. The retention clock starts at upload and at no other moment. In particular, the platform does not know, and does not calculate from:
The retention options offered in your compliance settings are named after the regulations whose durations they match. Those names describe the length of the period only. They do not mean the platform starts counting from the event named in the underlying regulation.
Determining which retention obligations apply to your records, and when each obligation begins, is your responsibility under your own procedures. Klyverityprovides the storage, the integrity controls and the audit trail. It does not perform your retention assessment and does not act as your records manager.
Because a single organization-wide period is applied from upload, we recommend setting that period to the longest period that could apply to any record you place in the platform, and documenting that choice in your own retention SOP along with the reasoning. Over retention is generally recoverable. Early destruction generally is not.
If different record types in your organization carry materially different obligations, and you need those tracked separately, use separate organizations or keep the governing schedule in your own quality system.
Nothing is deleted automatically. The retention date is enforced as a block on deletion, not as a trigger for it. While a document is within its retention period, completed and signed documents cannot be deleted. When the period elapses, that block simply no longer applies. No scheduled process removes documents at expiry, and deletion remains an action a person has to take.
The organization retention period is set in Settings, under Compliance. Changing it affects documents uploaded after the change. Contact us if you need to discuss historical records.
Questions about how this applies to your records? Contact compliance@klyverity.com. Related: Data Processing Agreement and Compliance overview.