Elaine provides configurable retention and deletion controls for recipient data, memberships, message history, response data, transactional data, imports, exports, and operational records. This flexibility enables organizations to implement a deletion concept that reflects their purposes, system landscape, and legal obligations. It does not replace that concept: the organization must define the required periods and verify whether Elaine’s configured defaults are appropriate.
Retention is part of the processing design
A retention period should be derived from the purpose for which a data category is processed. Different purposes can require different periods, even when the data relates to the same person. For example, an active subscription, a campaign-specific attribute, a delivery event, and evidence of an opt-in have different lifecycles.
Before configuring Elaine, document at least:
the data category and processing purpose;
the trigger that starts the retention period;
the required period and the action at its end;
whether deletion, anonymization, aggregation, or continued restricted retention is required;
the authoritative system and every copy in connected systems, exports, archives, and backups;
the owner responsible for configuration, monitoring, and periodic review.
Warning
Elaine’s defaults are technical starting points, not legal recommendations. The controller must determine suitable retention periods, provide any required instructions to its processor, and validate the configuration for the applicable purposes, contracts, and jurisdictions. This documentation is not legal advice.
How deletion works in Elaine
Elaine supports several deletion paths. The appropriate path depends on whether a single use context, a complete recipient profile, or another object must be removed.
Remove a membership or use context. A recipient can be removed from a campaign, recipient group, automation, bounce list, or other membership without necessarily deleting the complete profile.
Move an unused profile to the recycle bin. When a recipient no longer has an active membership, Elaine can place the profile in the recipient recycle bin. The recycle-bin period provides time for synchronization and reconciliation with connected systems.
Delete after the configured period. Cleanup processes evaluate configured periods regularly and remove records whose period has expired.
Delete immediately when required. Authorized users can permanently delete recipients from the recycle bin or empty it. File-based interfaces can also be configured to delete identified recipients directly without first using the recycle bin.
Apply additional rules. Marketing Automation and Data Business Rules can implement purpose-specific cleanup logic beyond fixed retention settings.
Note
Permanent deletion cannot be undone in the production system. Test identifiers, scope, permissions, connected-system propagation, and evidence requirements before using immediate or bulk deletion.
Membership deletion and profile deletion are different
A recipient profile can support several legitimate contexts at the same time - for example, a customer relationship, a press distribution list, and a separate newsletter subscription. Ending one context should therefore not automatically erase data that is still required for another documented purpose.
Elaine can manage retention at the level of memberships and purpose-specific data before the complete profile is deleted. When the last relevant membership is removed, the recipient recycle bin can act as the final stage before profile deletion. Organizations must define which memberships represent an active purpose and ensure that obsolete memberships do not retain a profile indefinitely.
Configurable retention controls
Data or lifecycle area | Elaine control | Configuration consideration |
|---|---|---|
Recipient recycle bin | Recipients without another active membership can be retained temporarily and then deleted. The Elaine default is 30 days and can be changed in the tenant configuration. | Allow enough time for the organization’s deletion, suppression, and CRM synchronization processes, but no longer than the documented purpose requires. |
Message and response history | The retention period can be set for an individual message. The tenant configuration can provide the default for newly created messages; the documented Elaine default is 30 days. | Shortening the period can affect reaction-based segmentation, follow-up campaigns, and personalized online message views. |
Temporary transactional-message data | The tenant-level period is configurable; the documented Elaine default is 7 days. | Consider dependencies such as personalized online views and delivery to downstream systems. |
Campaign-specific recipient data | Retention can be defined for the campaign or membership and supplemented with automation or business-rule logic. | Define what happens when a campaign ends, a recipient leaves it, or the period expires. |
Bounce, unsubscribe, pending-subscription, and automation-goal memberships | Cleanup periods can be configured by membership type. | Preserve suppression and deliverability behavior while synchronizing the resulting status with connected systems. |
Response raw data and export queues | Raw events can be aggregated for statistics or profiles and then discarded. Temporary export availability depends on the configured delivery variant. | Aggregated information may remain after raw data is removed. Include both raw and derived data in the deletion concept. |
Import files, import logs, and export archives | File-retention periods can be configured for supported file-based interfaces. | Transfer files needed by another system before the Elaine period expires and govern copies outside Elaine separately. |
Content, aggregate statistics, metadata, and operational records | Some records are deleted with their parent object; others follow service-level, security, accounting, or infrastructure schedules. | Confirm the applicable service specification and project configuration instead of applying a recipient-data period to every record type. |
The availability, allowed range, and operational effect of a setting depend on the Elaine version, enabled features, service class, and project configuration. Some settings require administrator or service-provider support. Record the effective production values rather than relying only on the general defaults shown here.
Raw, aggregated, and evidence data have separate lifecycles
Deleting a raw event does not necessarily delete information derived from it. Elaine can aggregate delivery and response events into statistics or, where the required PAC permission exists, profile values. The organization must decide how long the raw event, aggregate KPI, recipient-level profile value, and any exported copy may remain.
Evidence and suppression data can also require a lifecycle different from the active recipient profile. For example, an opt-in history can preserve a hashed identifier and relevant events after the operational profile is deleted. Define whether and for how long this information is required, who may access it, and how it is removed at the end of its own period.
Coordinate Elaine with connected systems
Changing a period in Elaine does not delete copies in a CRM, data warehouse, analytics platform, file transfer location, or other connected application. Before changing retention settings, determine the maximum synchronization cycle across the system landscape - the time required for a deletion, unsubscribe, or suppression status to reach and be reconciled by every relevant system.
For each deletion event, define:
which system initiates the event and which identifier it uses;
whether connected systems receive a deletion, anonymization, unsubscribe, or suppression instruction;
how retries, failures, and late-arriving imports are handled;
how a deleted or suppressed person is prevented from being unintentionally recreated;
how completion is monitored and documented across all systems.
Backups and recovery
Deletion normally affects the production data set; existing backups are not rewritten record by record. Backup and archive periods follow the applicable operational and contractual schedules. Recovery procedures must prevent deleted or suppressed recipients from becoming active again - for example, by reapplying current deletion and suppression information after a restore.
Implementation checklist
Inventory personal data, derived data, content, files, logs, archives, and backups in Elaine and connected systems.
Assign a purpose, lifecycle trigger, period, end action, and owner to every category.
Compare the required periods with the effective Elaine tenant, message, campaign, membership, and interface settings.
Define the distinction between ending one membership and deleting the complete recipient profile.
Align deletion with consent withdrawal, suppression, PAC permissions, and connected-system synchronization.
Test automatic expiry, recycle-bin cleanup, immediate deletion, bulk deletion, restore behavior, retries, and reporting with non-production data.
Monitor cleanup results and periodically review defaults, exceptions, and new data flows.
Default retention periods at a glance
The following values are the documented Elaine defaults for the main configurable retention categories. They describe the starting configuration of a standard setup, not mandatory or legally recommended periods. Existing environments can use different values because of their Elaine version, service class, enabled features, project configuration, or previously agreed requirements.
Category | Documented default | What happens when the period expires |
|---|---|---|
Recipient recycle-bin membership | 30 days | The recipient profile is permanently deleted if no other membership or retention context keeps it active. |
Unsubscribe membership | 30 days | The expired membership is removed by the cleanup process. The profile lifecycle then depends on any remaining memberships. |
Bounce-list membership | 30 days | The expired membership is removed. If the recipient has no other membership, the profile proceeds through the recycle-bin lifecycle. |
Pending subscription | 30 days | An uncompleted subscription is removed from the pending-subscription queue. |
Automation-goal membership | 30 days | The goal membership expires and is cleaned up according to the automation lifecycle. |
Temporary transactional-message data | 7 days | Temporary personalization and transaction data is removed. This can affect personalized online message views. |
Message dispatch and response history | 30 days | Recipient-level history outside the configured period is cleaned up or archived according to the applicable setup. The period can be changed for an individual message, and the tenant default can be changed for newly created messages. |
Raw response-data archive | 30 days | Archived raw-data entries are deleted after aggregation or delivery. Derived statistics or permitted profile values can follow a separate lifecycle. |
Historical snapshots of tenant data outside the instance | 180 days | Historical states of the tenant data that are stored outside the active Elaine instance are retained for 180 days and deleted when this period expires. |
Other categories - including campaign-specific recipient data, import and export files, opt-in evidence, content, aggregate statistics, security logs, billing records, and backups - do not have one universal tenant default that is suitable for every Elaine environment. Their periods follow the applicable object configuration, interface configuration, service specification, contract, or legal requirement.
Note
Verify the effective values in the production configuration and record approved deviations in the organization’s deletion concept. Changing a period can affect synchronization, suppression, personalized online views, reaction-based segmentation, reporting, and evidence processes.