Skip to main content

Document retention: how long CyberVadis keeps your files

Find out how long CyberVadis retains your uploaded documents, why certain records are kept after your assessment is complete, and how to request deletion of your files.

Written by Ana Nikolaeva

Documents you upload to the CyberVadis platform are retained for the duration of your subscription agreement plus up to three years, in accordance with the General Data Protection Regulation (GDPR). This retention period applies to all files uploaded during the assessment process.

Why we retain records after your assessment

As a rating agency, CyberVadis is required to maintain a secure and traceable audit trail of all actions related to client accounts. This includes:

  • Documents uploaded to the platform

  • Questionnaire submissions

  • Approvals to share cybersecurity performance results with third parties

Under Article 17.3(e) of the GDPR, the right to erasure does not apply where processing is necessary for the establishment, exercise, or defence of legal claims. Maintaining these traceability records falls within this provision.

For the full information notice on data protection and retention periods, see [cybervadis.com/data-protection-assessment].

When documents are deleted

Documents may be deleted in three ways:

  • Manually by you: you can delete documents from your document library at any time while your questionnaire is in progress. See [How to upload, manage, and delete documents] for instructions.

  • On request to our team: once your assessment review is complete, you can request deletion of your uploaded documents by contacting support@cybervadis.com. We will remove the files from active systems within 3 business days and from offline backups within 120 days.

  • Automatically: documents that have not been attached to an assessment within the applicable retention period will be deleted automatically in accordance with our retention schedule.

Your data rights

Your data belongs to you. At any point during or after your assessment, you can:

  • Request deletion of your uploaded documents by contacting support@cybervadis.com. Deletion from active systems is completed within 3 business days; deletion from offline backups within 120 days.

  • Retrieve your data at any time, free of charge, by contacting support@cybervadis.com.

For questions about how your data is handled, stored, and protected, see [How your data is stored, transported, and accessed: technical detail] or contact infosec@cybervadis.com.

Did this answer your question?