Retention policy

Keep hiring records only under a named owner and lifecycle.

The effective period is the longest of the Babu safe default, the employer’s configured policy, an applicable jurisdictional minimum, and any active legal hold.

Version babu-beta-retention-v2

Policy precedence

  • An active legal hold prevents deletion or anonymization until an authorized release is recorded.
  • An applicable jurisdictional minimum can extend the period but cannot silently shorten the Babu beta baseline.
  • An employer policy can extend retention and names an accountable owner, basis, version, and effective period.
  • The Babu beta default is the fallback where no longer policy applies.

Hiring application

Owner: employer hiring record. Default minimum: 365 days. Disposition: anonymize. Application snapshot, lifecycle, selected evidence snapshot, assessments, interview record, decision, offer, and application communications.

Hiring communication

Owner: application conversation. Default minimum: 365 days. Disposition: anonymize. Candidate-employer messages and delivery metadata for one application.

Consent notice

Owner: candidate notice and consent ledger. Default minimum: 365 days. Disposition: delete. Versioned notice digest, decision, channel, and subject identity.

Candidate rights

Owner: candidate rights workflow. Default minimum: 1095 days. Disposition: anonymize. Identity verification, scope, decisions, exceptions, delivery receipt, and status history.

Accommodation restricted

Owner: restricted accommodation workflow. Default minimum: 365 days. Disposition: anonymize. Candidate request details, restricted coordinator handling, and interviewer-visible logistics.

Ai invocation

Owner: controlled AI invocation ledger. Default minimum: 365 days. Disposition: delete. Provider/model/prompt provenance, bounded output, failure/fallback, cost basis, and human action.

Audit admin

Owner: platform and organization audit ledger. Default minimum: 1095 days. Disposition: anonymize. Material administrative, authorization, rights, retention, and override events.

Abuse trust

Owner: trust and suppression ledger. Default minimum: 365 days. Disposition: anonymize. Reports, blocks, suppression decisions, and rate-limit evidence.

Execution and recovery

  • Every run has a stable operation key, preview or execute mode, policy version, per-record action, attempt count, outcome, and operator report.
  • Application execution is disabled unless an authorized retention worker explicitly enables it.
  • Partial failures remain retryable under the same action identity; a new key is not used to replay an uncertain effect.
  • Candidate-owned Portfolio objects are preserved when employer-record anonymization cannot lawfully or correctly own their deletion.