Data Retention and Deletion
How long Kiko keeps each kind of record, what statutory retention forces our hand, and exactly what happens when you leave.
Last updated 1 September 2026
Kiko is a demonstration product. This document is written as a realistic sample and is not a binding agreement. Do not rely on it as legal advice.
1. The principle
We keep a record for as long as you need it to run your organisation, plus as long as the law requires you to be able to produce it, and then we delete it.
Two things pull in opposite directions here. Data protection law says do not keep personal data longer than necessary. Payroll and tax law says be able to produce a payslip years after the person left. Retention rules are how those two get reconciled, and most of the dial is yours to set.
2. While your subscription is active
We keep what is in your workspace. We do not silently age out employee records, payslips or audit history while you are a customer.
Where a record type has a configurable retention period, your administrator sets it in the workspace and the setting is itself audited. We apply your policy; we do not impose one.
3. Statutory retention in India
Several Indian obligations require payroll and employment records to remain producible well after employment ends. Provident fund, employees state insurance, income tax and shops and establishments records commonly need to be available for several years, and eight years is a widely used planning figure for payroll records.
Kiko will therefore warn you, rather than silently comply, if a deletion request would remove a record you are likely still obliged to hold. The decision remains yours as the filer of record. Confirm the specific periods that bind you with your own advisers.
4. Retention by record type
These are the defaults for a new workspace. Each can be changed by your administrator except where noted.
- Employee master record: retained while employed, then for your configured post exit period, eight years by default.
- Payslips and payroll runs: retained for the statutory period you configure. An approved run is immutable and cannot be edited, only superseded by an arrears entry in a later cycle.
- Attendance and leave records: retained for eight years by default, matching payroll, because they are the evidence behind a pay calculation.
- Candidate records for applicants not hired: 12 months by default, then deleted or anonymised at your choice.
- Performance reviews, goals and feedback: retained while employed, then 3 years by default.
- Documents you upload: retained with the record they are attached to, and deleted with it.
- Audit events: retained for 8 years and never editable, including by us. Their whole value is that nobody can quietly change them.
- Sign in and security logs: 18 months.
- Support correspondence: 3 years from the closure of the ticket.
5. When an employee leaves
An exit removes access, it does not remove the record. The person can no longer sign in, and their record moves to a former employee state where only roles you have authorised can reach it.
The record then follows your post exit retention period. This is the behaviour statutory retention requires, and it is why an exit is not the same as an erasure.
6. Erasure requests from employees
An erasure request from one of your employees comes to you, not to us, because you are the fiduciary. The admin console lets you action it directly.
Where a statutory obligation means a record cannot lawfully be erased yet, the platform supports restricting it instead: the record stops being used for any operational purpose and is reachable only for the statutory purpose that requires it. We think that is a more honest answer than either refusing the request or deleting something you are obliged to keep.
7. When your subscription ends
You get a 90 day export window from the end of the agreement, matching the Terms and Conditions. Everything comes out in machine readable formats, and the export includes the audit trail.
After the window closes we delete your production data within 30 days. Backups containing it age out on their normal rolling cycle, which is 35 days, so all copies are gone within roughly 65 days of the window closing.
We confirm completion in writing on request. If a legal hold or a live dispute means we must keep something, we will tell you exactly what and why.
8. Backups
Backups run continuously and are held on a rolling 35 day cycle, encrypted at rest. Restore procedures are tested rather than assumed.
A deletion inside a live workspace is applied to production immediately and works through backups as they cycle. We do not surgically edit historical backups, because a backup you have modified is no longer a reliable restore point.
9. Requesting early deletion
You can ask us to delete a workspace before the standard window closes. Write to privacy@kiko.co from an administrator account. We will confirm the scope, warn you about anything statutory, and then proceed.
Early deletion is irreversible and there is no recovery afterwards. We will say so again in the confirmation, and we require a second confirmation from a different administrator where one exists.
Still have a question?
Bring it to the demo and we will answer it on the call, or write to legal@kiko.co.
Book a demo