Skip to content
Legiscope
Menu
Data lifecycle and exit

Portability and deletion

The current register of export methods and formats, switching assistance, account restorability and deletion timing for the Legiscope application.

01

Contractual roles and controlling documents

The DPA controls the return, retention and deletion of Customer Personal Data processed by Legiscope as processor or subprocessor. The Terms govern Data Act switching and the portability of other exportable data and digital assets. If this operational page differs from an accepted Agreement or DPA, the accepted contractual document controls.

Legiscope’s separate application-controller records follow the purposes and retention criteria in the independent-controller register in the Terms. Controller operations concerning visitors to the public website are described separately in the Privacy Notice.

02

Available export and transfer methods

A Customer may use an available in-service export while its account is active. During switching or after ordinary application access ends, Legiscope may provide the same records through a secure final package or, where an enabled interface is available for the purchased workflow, through that documented interface.

A Customer may ask Legiscope to demonstrate the available export path for its purchased workflows and to coordinate delivery to the Customer, its authorised destination provider or its on-premises infrastructure. Switching operations and associated data egress are provided without charge; separately requested work that is not necessary for switching is chargeable only if agreed in an Order Form.

  • Structured records: available CSV or JSON exports, or an equivalent documented machine-readable package.
  • Human-readable records and reports: supported PDF or DOCX format where applicable.
  • Uploaded source files and attachments: original format or a commonly readable format where the original cannot safely be supplied.
  • Delivery: in-service download, access-restricted transfer of a secure final package or an enabled documented interface appropriate to the volume and destination.
03

Data structures and formats

A structured export preserves the customer-visible identifiers, relationships, statuses, decisions, approvals, timestamps, history and other metadata available for the exported workflow. A secure final package includes a manifest or data dictionary sufficient to identify the supplied files and structured fields.

CSV is supplied as UTF-8 tabular data and JSON as documented objects and arrays. PDF and DOCX are human-readable document formats rather than substitutes for structured data where structured data exists. There is currently no representation that every workflow has a continuous public API or that a single universal industry schema applies to privacy-governance records. Any workflow-specific API, schema, open standard or direct destination-provider interface is identified during exit planning or in the Order Form before it is relied upon.

04

Exportable categories

To the extent present in the Customer account, exportable data and digital assets include Customer organisation and programme configuration; Authorised User, role and permission records; applications; processor relationships; processing activities and RoPA records; rights-request records; incident and breach records; audits and evidence records; roadmap tasks; uploaded source files and attachments; Customer-specific reports, assessments and AI-assisted Output; the current AI Funds balance and customer-visible task-level EUR usage history; and their customer-visible relationships and metadata.

The export excludes other customers’ data; credentials and cryptographic secrets; Legiscope source code and executables; system prompts and reusable prompt templates; model weights; proprietary algorithms and routing rules; security-detection logic and internal risk signals; raw provider-wide telemetry whose disclosure would create a security risk or reveal a trade secret; irreversibly anonymised provider analytics; and third-party material the Customer is not entitled to receive. An exclusion is not used to impede switching, and customer-visible metadata remains exportable.

05

Switching sequence and limitations

The Customer starts a switch, on-premises port or erasure process through the notice channel in the Terms. The maximum notice period is two months. The standard transition is no more than 30 calendar days after that notice period, followed by at least 30 calendar days for retrieval. If the standard transition is technically unfeasible, Legiscope follows the notice and extended-transition procedure stated in the Terms.

Export and transfer performance depends on the purchased workflows, data volume, attachment sizes, destination readiness and the Customer’s timely provision of destination and security information. A large package may be divided into access-restricted parts. Ordinary application access need not remain active after termination where the records are provided through a secure final package or interface.

06

Return, restorability and active-system deletion

When an Agreement ends, the Customer may elect return, erasure or retention for restorability as stated in the DPA. Without an election, retention for restorability is the standing instruction: the account and Customer Personal Data remain access-disabled and restorable for up to 12 months without an additional charge. The Customer may request return or instruct erasure at any time during that period.

Restorability is a courtesy safeguard, not a guaranteed archive. After the applicable retrieval period, Legiscope may delete the dormant account earlier and will delete it no later than 12 months after the Agreement ends. A later agreement with the same Customer may reactivate the account and its recorded unused AI Funds if the account has not been deleted. The right to carry unused AI Funds into a new Agreement remains governed by the Terms even if the earlier account data has already been deleted.

Following an erasure instruction, Legiscope deletes the applicable Customer data from active systems without undue delay and records the instruction. Legiscope confirms the active-system deletion and final backup expiry on request as provided by the DPA.

07

Immutable disaster-recovery backups

Encrypted, access-restricted and unmodifiable disaster-recovery backups expire automatically 90 days after active-system deletion. The protected backup cycle cannot be selectively shortened, and residual copies are not available for ordinary operation, analytics, model training or product development.

If a protected backup is restored during its retention cycle, Legiscope re-applies recorded deletion instructions before deleted data can return to ordinary use. The DPA continues to protect Customer Personal Data for as long as a backup copy is retained.

Exit planning

Review the exit path for your service scope.

Tell us which workflows, records and destination are in scope. We can identify the current exports, package structure and transfer method before switching begins.

Contact Privacy