Getting Your Data Out: Exit Terms, Export and Who Stays Liable
The two questions nobody asks during a software purchase are what happens to your data if you leave, and what happens to it if you stay too long. Both have answers, both belong in writing before you sign, and one of them is a legal obligation rather than a preference.
Software selection conversations are optimistic by construction. Everyone in the room is discussing what will work, which means two questions get postponed indefinitely: how do we get our data out if this ends, and what happens to data we no longer need while it continues. The first is a commercial risk you can negotiate away in an afternoon. The second is a statutory duty under the Data Protection Act that no amount of negotiation removes.
They are the same subject because they are both about data you are holding for longer than the reason you collected it. And they fail in the same way: silently, until the moment somebody needs the answer.
Retention: the obligation that runs in two directions
Most businesses think about record-keeping in one direction only — keep things long enough. Tax records for years, employment records for years, donor documentation for the period the agreement specifies. All correct, and all only half the requirement.
The Data Protection Act pushes the other way: personal data should not be kept longer than the purpose requires. So retention is not a single number but a set of decisions per category, each of which has a floor set by record-keeping obligations and a ceiling set by data minimisation. The CVs of candidates you did not hire have a low ceiling. The payroll register has a high floor. Treating both the same way fails in one direction or the other.
| Category | Pressure to keep | Pressure to delete | Where the decision comes from |
|---|---|---|---|
| Transaction records and ledgers | Statutory record-keeping, audit reconstruction | Low — largely not personal data | Your tax and audit obligations |
| Payroll and employment records | Statutory, and disputes arise years later | Real — highly sensitive personal data | Employment law plus your own policy |
| Audit and access logs | Reconstructing any period you can be asked about | They contain identities and IP addresses | Your longest reconstruction obligation |
| Customer contact records | Commercial value, warranty, repeat sales | Strong once the relationship has ended | Your stated purpose at collection |
| Unsuccessful job applications | Almost none | Strong — you have no ongoing purpose | A policy decision you should write down |
| Sessions, devices, notifications | Operational only, short-lived value | Strong — pure minimisation | Straightforward; short is correct |
The row that catches most organisations is the third. Set audit log retention short for minimisation reasons and you have arranged for your evidence to expire before the obligation it evidences — the trap described in what an audit trail has to reconstruct. Set it to forever and you are holding identities and IP addresses indefinitely with no stated purpose. The answer is a deliberate number with the reasoning written down, which is a ten-minute task nobody does.
A retention policy that nothing executes is a document, not a control. The question is not what your policy says — it is whether anything ran last night.
The difference between a policy and a deletion
This is the point where most retention arrangements are revealed to be aspirational. A policy states a period. Enforcement means something runs on a schedule, finds what is past its period, and removes it — and that you can tell it happened.
Ask a vendor which of those two they provide, and be specific, because the difference determines whether you are compliant or merely documented. A settings screen where you type a number of days is a policy. A scheduled job that acts on that number is a control.
There is a second distinction that matters even more, and it is the one most likely to be assumed wrongly: retention automation in this product — and in most operational systems — applies to logs and operational data plus the purge window on trashed records, not to live business records. Audit logs, sessions, notifications, email logs, scan events, report runs and exports all have a period that a scheduled job enforces. Your customer list does not. Nothing quietly ages out a customer who last bought in 2021. That decision, and its execution, are yours. The mechanics are set out in full in Kenya's Data Protection Act, retention and deletion, which is the companion to this article and the better place to start if retention rather than exit is your question.
Where the disposal boundary actually falls
Logs and operational data
Roughly forty categories with a period in days, an action and an active flag, enforced by a scheduled job with a dry-run mode. Audit logs and document vault access logs default long; sessions, scan sessions and failed jobs default short.
The purge window on records you delete
Deletions route through a recoverable trash with lifecycle events, purge reporting, and legal holds that can block a permanent delete while a dispute or investigation is live. A deletion is a state with a history rather than an absence.
Erasing an individual account holder on request
Anonymises identity — name, email, phone, photo, authentication secrets — clears sessions, tokens and role assignments, deactivates the account, and rewrites the identity in the audit log while leaving the audited actions intact.
Live business records — customers, employees, invoices, tickets
These are kept until you decide otherwise. There is no timer. If your retention policy says inactive customer contact details go after five years, executing that is a job somebody does, not a setting somebody enables.
Deciding every period
Each category has a floor set by your record-keeping obligations and a ceiling set by data minimisation. Choosing the number, and recording why with a date, is a decision no default can make for you.
Everything held outside the system
The exported spreadsheet on a laptop, the payroll report in somebody's email. Outside every permission, every log and every retention policy you configured — and usually the largest real exposure.
Read the fourth row twice, because it is the assumption that most often turns out to be wrong. Many organisations believe a retention setting somewhere is quietly ageing out old personal data. It is ageing out logs.
Exit: the question that reveals what kind of vendor you have
Ask a provider how you leave. The answer, and more tellingly how comfortable they are giving it, tells you more about the next three years than any feature comparison. The ten questions for choosing a provider in Nairobi puts this at number six for a reason: it is the question most likely to produce an evasive answer, and evasion here is itself the finding.
Four exit questions, and how to read the answers
How do we export everything, in what format, and can I see it now?
What you will hear
A demonstration, producing standard formats you can open.
How to read it
A description rather than a demonstration usually means an export exists for some things. Ask specifically about attachments and documents, which is where exports are most often incomplete.
Does exporting cost anything, at any point, including at termination?
What you will hear
No, and it says so in the contract.
How to read it
An export fee is a hostage arrangement with an invoice attached. It is also usually negotiable before signature and never afterwards.
After we terminate, how long do you keep our data and when is it destroyed?
What you will hear
A specific period, a specific mechanism, and confirmation in writing.
How to read it
Vagueness means indefinite retention. As the controller you remain responsible for personal data a processor is holding, so an indefinite answer is your problem rather than theirs.
If we delete our account by mistake, what can be recovered and for how long?
What you will hear
A grace period, stated in days, before anything is irreversible.
How to read it
Immediate irreversible deletion is a support incident waiting to happen. No stated period at all usually means nobody has designed this path.
How this works here
What AWRA OpsHub does today
- Per-category retention policies with scheduled enforcement across roughly forty categories of log and operational data, with a dry-run mode so you can see what a change would remove before it removes it.
- A recoverable trash with lifecycle events, purge reporting and legal holds that can block a permanent delete while a dispute is live, so a deletion is a state with a history rather than an absence.
- Per-person data export, queued and delivered by secure link, covering the personal data held about one individual across the system.
- Per-person erasure that anonymises identity while preserving the audited actions, and which is itself audited.
- Account deletion with a thirty-day grace period — the account is marked pending deletion, notified, and can be cancelled before anything is purged.
- A deletion impact preview, so you can see what a deletion would affect before it happens rather than afterwards.
- Deletion actions audited separately, so scheduling, cancelling and completing a deletion each leave a record.
- Published terms — a data processing addendum and a compliance matrix you can send to a lawyer rather than assurances you have to remember.
What it does not do
- No single "export my entire organisation" button. Data comes out through module exports and reports, and the per-person export is scoped to one individual rather than the whole tenant. A full migration-grade extract is work we do with you, not a self-service action, and you should hold that against us in the same way this article suggests you hold it against anyone.
- No automated export of file attachments and documents alongside the data. Ask about this specifically with any vendor including us, because it is where exports are most often quietly incomplete.
- No automatic ageing-out of live business records. Customers, employees, invoices and tickets are kept until you act. Retention automation covers logs, operational data and the purge window on trashed records — assuming otherwise is the most common mistake on this subject.
- No per-record retention override. Periods are per category, so an individual document cannot be given its own longer life.
- No proof-of-destruction certificate issued automatically after purge. The actions are audited; a formal attestation is a request rather than a document that appears.
- No consent records and no record of processing activities, so those artefacts of your retention reasoning live outside the product.
The first item is the honest weak point and it is deliberate to state it here rather than bury it. An export good enough to migrate away on is a real requirement, and if it matters to your risk position, put it in the contract as a defined deliverable with a timeframe — with us or with anyone else. A promise of cooperation is weaker than a specified obligation.
What to settle before you sign, not after
-
Get the export demonstrated, including attachments
Not described. Ask to see the file, open it, and check whether documents and images came with it. This takes ten minutes during evaluation and is impossible to arrange during a dispute.
-
Put no-cost export at termination in the contract
One sentence. It is nearly always agreed before signature and nearly never agreed afterwards, which tells you what kind of clause it is.
-
Agree the post-termination retention and destruction period
A number of days, a mechanism, in writing. You stay responsible as controller for personal data your processor holds, so an unstated period is an open-ended liability of yours.
-
Set your retention periods in the first month of use
Not in year three when someone asks. Go through the categories, decide each against your actual purposes and obligations, and record the reasoning with a date. Then verify the enforcement job is running.
-
Confirm the grace period on account deletion
Know how long you have to reverse a mistake, and make sure more than one person knows. Thirty days here; ask anyone else and get the number.
-
Review retention annually with a named owner
Obligations change, purposes change, and the categories you added last year came with defaults nobody chose. An annual pass with the reasoning updated and dated is the whole discipline.
The test that settles both questions at once
Ask for two things in writing before signature: a no-cost export at termination, and a stated period after which your data is destroyed. A provider comfortable with both has thought about the end of the relationship, which is the strongest available evidence that they expect to earn the middle of it. A provider uncomfortable with either has told you something more useful than any reference call would.
The wider context for both questions sits in data protection duties — where retention and erasure are statutory rather than commercial — and in ERP pricing in Kenya, because an export fee at termination is a cost that belongs in the three-year total even though it never appears in a quote.
Our take
Settle exit before signature, because every term in that conversation is available then and none of it is available later. Then treat retention as forty small decisions rather than one policy: each category has a floor set by what you must be able to reconstruct and a ceiling set by data minimisation, and the defaults you never reviewed are decisions somebody else made for you. Verify that something actually deletes on a schedule — a policy nothing executes is a document. And ask any vendor, including us, to demonstrate an export with attachments rather than describe one.
See retention, trash and deletion controls
Per-category retention with scheduled enforcement and a dry-run mode, recoverable trash with lifecycle events, per-person export and erasure, and account deletion with a thirty-day grace period.
Explore governance controlsFrequently asked questions
How long should we keep data in our system?
There is no single answer, because retention is a set of decisions per category rather than one number. Each category has a floor set by your record-keeping obligations — tax, employment, donor agreement terms — and a ceiling set by the Data Protection Act principle that personal data should not be kept longer than the purpose requires. Unsuccessful job applications have a low ceiling and almost no floor; the payroll register is the opposite. Go through the categories once, deliberately, and write down the reasoning with a date on it.
Is a retention setting the same as data actually being deleted?
No, and this is the specific question to press any vendor on. A settings screen where you type a number of days is a policy; a scheduled job that acts on that number is a control. Here the enforcement is a scheduled job with a dry-run mode, so you can see what a period change would remove before committing to it — but the general point stands: ask whether anything ran last night, not what the policy says.
What happens to our data if we stop paying or decide to leave?
Account deletion runs through a thirty-day grace period — the account is marked pending deletion and notified, and it can be cancelled before anything is purged — with an impact preview available beforehand and the scheduling, cancellation and completion each audited. What we do not have is a single self-service button that exports your entire organisation; a migration-grade extract is work we do with you. That is a real weakness and we would rather you hold it against us openly than discover it at the end.
Should we expect to pay to get our data out?
No, and an export fee at termination is worth treating as disqualifying rather than negotiable. It is a hostage arrangement with an invoice attached, and it is nearly always removable before signature and nearly never removable afterwards. Put no-cost export at termination in the contract as one sentence, and note that the fee also belongs in your three-year cost comparison even though it never appears in a quote.
Who is responsible for data our software provider is still holding after we leave?
You are, as the controller — which is why an unstated post-termination retention period is your open-ended liability rather than your provider's. Agree a specific number of days and a destruction mechanism in writing before you sign, and note that a formal proof-of-destruction attestation is something you request rather than something that arrives automatically.