There are two different things people mean by closing an account, and they behave differently. Deleting your own user account removes you as a person. An organization account is the shared workspace your team uses, and it survives you leaving it, unless you were the last one in it. This article covers both, and how long data is kept afterwards.
Deleting your own user account
You can delete your own account from your profile. If you have a password set you will be asked to confirm it first. Accounts that only sign in with Google can delete without one.
Your personal details are anonymized straight away rather than being held for any retention period. Your name and email address are replaced, your sessions and tokens are destroyed, and you are removed from every organization you belonged to.
Your user record itself is kept in that anonymized form. This is deliberate, and it is what allows the rest of the deletion to work: invoices, audit logs, and compliance records refer to the person who performed an action, so those references have to stay resolvable. Keeping an anonymized record means those business records remain intact and complete without you remaining identifiable in them.
If you own an organization that other people are still members of, ownership passes to one of them so the organization is never left without an owner. An existing administrator is preferred. If you would rather choose who takes over, transfer ownership yourself before you delete your account. See Managing Users and Roles for how.
What happens to an organization with no members left
When the owner of an organization deletes their account and nobody else is a member, the organization is deactivated rather than deleted immediately.
- The subscription is cancelled.
- The organization becomes inaccessible. Nobody can sign in to it or reach its data.
- Any invitation that had been sent but not yet accepted is withdrawn, so nobody can join a workspace that has been taken out of service.
It is deactivated rather than erased because the organization’s records are not only about the person who left. Invoices, audit logs, compliance evidence and attestations may need to be kept, and some of that data describes other people, including your own customers. Deactivating stops all access to it without destroying records that may still be required.
If a deactivated organization needs to be brought back, for example because a colleague should have taken it over, contact support before the retention period ends. It can be reactivated and a new owner appointed.
Once the retention period has passed there is no longer a basis to keep it, and the organization is removed along with its data.
How long data is kept
The baseline retention period for business records is seven years. That figure comes from the longest statutory requirement ISO Mate is subject to: section 286 of the Corporations Act 2001 (Cth) requires an Australian company to keep financial records for at least seven years.
Seven years is a ceiling for records that have to be kept, not a target applied to everything. Data protection law requires personal data to be held no longer than is necessary for the purpose it was collected for, so categories with a shorter justifiable life are kept for less time.
Kept for the full seven years
- Invoices and payment records, along with their accounting system records. These are statutory financial records.
- Subscription and billing history, which supports the financial record and any query about what was charged.
- Security and authentication audit logs, covering sign in events, identity confirmations, permission changes and role assignments. Incidents sometimes only come to light long after the event, and these logs are also how access control is evidenced to auditors.
- Records of attempted access across organizations, which are kept even when the organization they refer to has been removed. They are security records and lose their value if they disappear with their subject.
- Compliance evidence and policy attestations, or longer where your own framework requires it, since you may rely on this to demonstrate historical compliance.
Kept for less
- Workflow audit entries: one year. These are operational diagnostics with no evidential value beyond the current configuration.
- Workflow version history: the most recent 50 versions of each workflow. Older versions describe configurations that can no longer be meaningfully restored.
- Your personal details on account deletion: anonymized immediately, as described above.
How data is disposed of
Disposal removes the record from the live systems: the databases, and the file storage holding uploads such as logos, compliance evidence and attachments.
Data that has already been captured in a backup snapshot is not picked out of that snapshot individually. Doing so would compromise the integrity of the backup and its usefulness for recovery. It is instead disposed of when the snapshot reaches the end of its rotation. So the honest outer limit for complete disposal is the retention period plus the backup rotation, and we do not claim erasure is instantaneous everywhere.
Exporting your data first
Deletion cannot be undone, so export anything you want to keep before you start. Most list pages in ISO Mate offer CSV and PDF export from their Export menu, and a copy of your personal data can be requested from your profile.
Legal holds and requests
A retention period can be extended where there is a legal reason, such as litigation or a regulatory investigation. Any extension is recorded with its reason and its expected end, and lifted once it no longer applies.
The full schedule is set out in our Data Retention and Disposal Policy, which is reviewed at least annually. If you need it for a security review or a vendor assessment, or you have a data subject request, contact support.