Data Retention Policy

Effective Date: May 17, 2026

This policy outlines how MonitorExam retains and deletes data to comply with applicable regulations while providing institutions with control over their examination records.

Purpose

This policy balances the need to retain data for examination integrity, audit compliance, and legal requirements while respecting privacy principles and providing institutions with control over data retention.

Standard Retention Categories

Data TypeTypical Retention
Exam recordingsConfigurable
AI alertsConfigurable
Audit logsUp to 12 months
Support ticketsUp to 24 months
Billing recordsAs required by law
BackupsBased on infrastructure policy

Note: Retention periods are subject to institutional configuration, applicable law, and contractual requirements.

Institutional Control

Institutions may configure retention periods for examination data subject to:

  • Legal and regulatory obligations
  • Contractual requirements
  • Technical limitations
  • Backup and disaster recovery requirements

Institutions can set retention policies through their MonitorExam administrator dashboard or by contacting our support team.

Deletion Procedures

When data reaches its retention expiration date, MonitorExam deletes it according to the following process:

1. Flagging for Deletion

Data reaching retention expiration is flagged for deletion in our systems.

2. Backup Processing

Data may temporarily remain in backup systems according to our infrastructure retention policy (typically 30-90 days).

3. Permanent Deletion

After backup cycles complete, data is cryptographically deleted or overwritten to prevent recovery.

4. Verification

Deletion is logged and verified to ensure compliance.

Data Export Before Deletion

Institutions may request export of data before scheduled deletion. Please contact our support team to arrange data export.

Related Resources