Retention

Keep evidence only while it has a purpose.

Evidence Pack availability and de-identification use separate clocks under DoorID’s Data Processing Agreement.

Secure applicant linkGuided verificationControlled evidencePass / Refer / Fail
Retention model

Keep data only as long as it is needed.

Retention is set by workflow, buyer contract, legal need and region.

Applicant evidence

An Evidence Pack is available for 7 days after a Verification concludes. On written instruction, DoorID may extend availability for a named account to a maximum of 30 days.

Account records

Clients should download their Evidence Packs as their own record. Account, billing and other controller records are retained under the Privacy Policy and applicable law.

Security logs

From the account’s Retention Start Date, DoorID removes identifying Applicant data within 7 days after each Verification concludes, or at the end of an instructed extended availability period.

Licence-first identity capture

Where a driving licence or identity document is captured first so a later Verification can rely on it, DoorID keeps the identity-document images and extracted details for 60 days from capture. Each Verification that relies on them restarts that 60-day period, up to 180 days from capture in total. They are removed within 7 days after the Verification they were kept for concludes, or at the end of the period, whichever is sooner.

Practical controls

Retention uses technical controls.

A policy is not enough unless the platform can apply it.

Retention settings

Before the Retention Start Date, Applicant data is held securely and is deleted on the Client’s instruction. DoorID shows the date in the portal and notifies the Client when it is set.

Deletion jobs

A Client may request erasure of a specific Applicant’s data at any time. DoorID acts within 7 days, confirms deletion, and records what was removed and when for access through the portal and API.

Legal hold

Before de-identification, a Client may hold a specific Verification for a dispute, complaint, or legal or regulatory need. A portal hold lasts 90 days; written instruction may extend it to 12 months. DoorID records the hold, pauses de-identification, and reminds the Client before expiry. De-identified data cannot be restored.

Data retained after de-identification

DoorID retains only the de-identified technical and audit categories listed in DPA clause 8.4, including integrity hashes, delivery records, the Evidence Pack fingerprint, reported outcomes, and one-way keyed telephone and identity-document fingerprints. The full declared address is kept for 90 days, then reduced to outward postcode and property identifier.

Account closure

On termination, DoorID de-identifies or deletes remaining Applicant data within 30 days and confirms completion in writing, except where a legal hold applies or law requires retention.

Proof

DoorID records what was removed and when for every Verification and makes that record available to the Client through the portal and API.

Next step

See DoorID on a real workflow.

Talk to us and we will map DoorID to your application process, risk team and approval workflow.