Retention policy
Keep hiring records only under a named owner and lifecycle.
The effective period is the longest of the Babu safe default, the employer’s configured policy, an applicable jurisdictional minimum, and any active legal hold.
Version babu-beta-retention-v2
Policy precedence
- An active legal hold prevents deletion or anonymization until an authorized release is recorded.
- An applicable jurisdictional minimum can extend the period but cannot silently shorten the Babu beta baseline.
- An employer policy can extend retention and names an accountable owner, basis, version, and effective period.
- The Babu beta default is the fallback where no longer policy applies.
Hiring application
Owner: employer hiring record. Default minimum: 365 days. Disposition: anonymize. Application snapshot, lifecycle, selected evidence snapshot, assessments, interview record, decision, offer, and application communications.
Hiring communication
Owner: application conversation. Default minimum: 365 days. Disposition: anonymize. Candidate-employer messages and delivery metadata for one application.
Consent notice
Owner: candidate notice and consent ledger. Default minimum: 365 days. Disposition: delete. Versioned notice digest, decision, channel, and subject identity.
Candidate rights
Owner: candidate rights workflow. Default minimum: 1095 days. Disposition: anonymize. Identity verification, scope, decisions, exceptions, delivery receipt, and status history.
Accommodation restricted
Owner: restricted accommodation workflow. Default minimum: 365 days. Disposition: anonymize. Candidate request details, restricted coordinator handling, and interviewer-visible logistics.
Ai invocation
Owner: controlled AI invocation ledger. Default minimum: 365 days. Disposition: delete. Provider/model/prompt provenance, bounded output, failure/fallback, cost basis, and human action.
Audit admin
Owner: platform and organization audit ledger. Default minimum: 1095 days. Disposition: anonymize. Material administrative, authorization, rights, retention, and override events.
Abuse trust
Owner: trust and suppression ledger. Default minimum: 365 days. Disposition: anonymize. Reports, blocks, suppression decisions, and rate-limit evidence.
Execution and recovery
- Every run has a stable operation key, preview or execute mode, policy version, per-record action, attempt count, outcome, and operator report.
- Application execution is disabled unless an authorized retention worker explicitly enables it.
- Partial failures remain retryable under the same action identity; a new key is not used to replay an uncertain effect.
- Candidate-owned Portfolio objects are preserved when employer-record anonymization cannot lawfully or correctly own their deletion.