Lesson 6/9 · 67%
← Course Home
Compliance Essentials for Visitor Intelligence
1 Privacy Law Basics for B2B 2 Company vs Personal Data 3 What Kopimore Collects (and Doesn't) 4 Your Privacy Policy 5Consent Banner Configuration 6Data Retention Policies 7DSARs and Opt-Outs 8Privacy Impact Assessments 9Training Your Team
Lesson 6 of 9

Data Retention Policies

How long you retain visitor intelligence data is a compliance decision that affects your risk profile, your storage costs, and your ability to demonstrate regulatory compliance. This lesson covers how to set a defensible policy.

The Retention Principle

GDPR requires that personal data be "kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed" (Article 5(1)(e) — the storage limitation principle). Even where visitor intelligence data is primarily company-level, applying this principle to all visitor data is best practice.

Setting Your Retention Period

For most B2B companies, a 12-month retention period for raw visit session data is defensible and practical. The business case: a company that visited 12 months ago and hasn't been contacted is unlikely to be a current opportunity; the data's commercial value has expired. Longer than 24 months is difficult to justify under storage limitation principles.

For company-level records (firmographic data, not raw session logs), longer retention (3–5 years) can be justified for CRM-integrated records under the legitimate interest of maintaining business relationships.

Configuring Retention in Kopimore

In Kopimore account settings, you can set an automatic data retention period. Visit data older than this threshold is automatically deleted from Kopimore's servers. Configure this to match your documented retention policy — the two documents should be consistent.

CRM Data vs Kopimore Data

Once Kopimore data has been synced to your CRM, the retention period of the CRM record is governed by your CRM data retention policy — not Kopimore's. Ensure your CRM policies are also documented and consistently applied.

Key Takeaways
  • 12 months is the defensible default retention period for raw visit session data
  • Company-level CRM records can be justified for 3-5 year retention under legitimate interests
  • Configure Kopimore's automatic deletion to match your documented retention period exactly
  • CRM data retention is separate from Kopimore retention — ensure both policies are documented
← Consent Banner Configuration DSARs and Opt-Outs →