Set retention policies

ComplianceUpdated 2026-07-26

Set a retention period for each data class in Settings → Data & retention, and the instance enforces deletion or anonymisation automatically on a rolling schedule. Storage limitation is a GDPR obligation rather than a housekeeping preference, so each period needs a stated reason, not just a number.

Why per-class periods matter

Treating "all messaging data" as one bucket with one retention period is the most common mistake in this settings area. A conversation transcript, a voice recording attached to that conversation, and a contact record that has gone inactive all carry different risk and different justification for how long they should be kept. Arino One lets you set these independently so the period for each matches the actual reason you're holding it.

Step by step

  1. Go to Settings → Data & retention.
  2. Set a period for each class: conversations, media attachments, voice recordings, inactive contacts.
  3. Choose hard deletion or anonymisation at expiry for each class.
  4. Record the justification for each period — the legal basis or business reason.
  5. Put a recurring review of these settings on your compliance calendar.

Choosing a period for each class

Data classTypical driverNote
Conversation transcriptsSupport/sales record-keeping needOften the longest-justified period
Media attachments (images, documents)Same conversation, but higher sensitivityFrequently shorter than the transcript period
Voice recordingsCall-quality or dispute-handling needJustify separately; often the shortest period
Inactive contact recordsNo recent engagementConsider deletion or anonymisation after a defined inactivity window

Start from the legal or contractual reason you hold each class of data, not from a round number. If you cannot state the reason in one sentence, the period is probably longer than it should be. Where a class has no ongoing purpose — a voice recording used only for a quality check that concluded weeks ago — anonymise or delete it sooner than the conversation record it's attached to.

Deletion versus anonymisation

Hard deletion removes the record outright and is the more defensible option where there is no continuing analytical need. Anonymisation is useful where you want to keep aggregate patterns — volumes, response times, channel mix — without being able to tie any record back to an individual; once identifiers are stripped, the anonymised data falls outside GDPR's scope for that purpose.

How this differs by connection status

The retention engine and settings screen are identical regardless of setup. Every client holds their own Infobip account and data; what differs is whether the optional $50/month Arino Core connection gives you Arino support in configuring and operating retention.

Connection statusWho configures retentionWho holds the account the data sits inAccountability
Connected ($50/month Arino Core)Client, with Arino support and management availableClientClient is Controller and sets policy; Arino assists as Processor while connected
UnconnectedClient, entirelyClientClient is Controller and Processor in practice — solely responsible for configuring and evidencing retention

In both cases, the client decides and owns the retention policy as Data Controller, since the underlying Infobip account and data are always the client's own. On a connected instance, Arino can assist with configuring and operating the enforcement mechanism as Data Processor. On an unconnected instance, there is no Arino operational involvement at all — the client configures, monitors and evidences retention without support from Arino.

What to include in your Article 30 record

For each data class, note the period, the deletion behaviour, and a one-line justification. This is the exact information a data-protection authority or an enterprise customer's procurement team asks for, and having it ready alongside the settings screen turns a retention review into a five-minute conversation.

Steps at a glance

  1. Open Data & retention settingsGo to Settings → Data & retention in your instance console to see the current period configured for each data class.
  2. Set a period per data classConfigure separate retention periods for conversation transcripts, media attachments, voice recordings, and inactive contact records — they rarely warrant the same period.
  3. Choose the deletion behaviourDecide whether each class is hard-deleted at expiry or anonymised (identifiers stripped, content retained for analytics).
  4. Record the justificationWrite down the business or legal reason for each period; this note is what you attach to your Article 30 record of processing.
  5. Schedule a periodic reviewRevisit the periods at least annually, or whenever a new channel or use case is added, since retention needs drift as the business changes.

Frequently asked

What is a reasonable retention period for conversation history?

There is no fixed legal number — GDPR requires a period no longer than necessary for the purpose. Support and sales teams commonly justify 12–24 months for conversation transcripts; anything longer needs a specific business or legal reason recorded against it.

Should media attachments be kept as long as the conversation text?

Usually not. Images, voice notes and documents often carry more sensitive content than the surrounding text and are harder to justify keeping long-term, so many instances set a shorter period for media than for the transcript itself.

What does anonymisation do differently from deletion?

Hard deletion removes the record entirely. Anonymisation strips identifying fields (phone number, name, contact ID) but can retain the content for aggregate reporting or analytics, provided it can no longer be linked back to an individual.

Does changing a retention period apply retroactively?

A shortened period triggers deletion of records that now fall outside it on the next scheduled run; a lengthened period does not restore records already deleted. Set periods deliberately before, not after, you need the data gone.

Who decides what retention periods are lawful for our business?

The client, as Data Controller, decides and is accountable for the periods; Arino One's platform enforces whatever period is configured but does not set policy on the client's behalf.

Next step

Apply this to your own deployment

This guide describes decisions we make on live instances. Tell us your channels, systems and region and we will map it to an architecture outline, a provisioning plan and an indicative commercial model — usually within one business day.