Data retention policy
Index Data and Analytics Data are kept for the duration of the agreement and for sixty (60) days thereafter. Audit logs are kept for one (1) year. (6 years in the HIPAA-Compliant services, as per regulation.)
Data archiving and removal policy
The Coveo platform will notify organizations owners ten (10) days, five (5) days, and one (1) day prior to expiration. A final email notification is sent when the organization expires. Once expired, the organization will be deleted in the following days.
Data storage policy
Coveo Hosted Services leverages US-based data centers in the United States as well as in Ireland and France for Data Residency of Multi-Region Customers. The physical infrastructure is hosted and managed within nondescript, reinforced facilities capable of withstanding adverse weather and other reasonably predictable natural conditions. Physical access is strictly controlled both at the building perimeter and at building ingress points by professional security staff utilizing video surveillance, state-of-the-art intrusion detection systems, and other electronic means. Authorized staff must pass two-factor authentication multiple times to access data center floors. All visitors and contractors are required to present identification and are signed in and continually escorted by an authorized staff. For more information, please view: https://docs.coveo.com/en/1560 App/service has sub-processors
yes
Guidelines for sub-processors