This article explains how long Simpplr keeps platform logs, how it deletes them, and how your team can request log records for an investigation.
It covers three areas.
How long Simpplr keeps request logs, system health logs, security protection logs, and admin activity logs.
How Simpplr deletes logs automatically when they expire.
What to include when you request log records for an investigation.
These time limits let Simpplr find and fix platform issues while keeping only the data it needs. They align with SOC 2 Type II, ISO/IEC 27001, and global privacy laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the California Privacy Rights Act (CPRA).
Note: Simpplr automatically and permanently deletes most platform logs after 30 days. It keeps records of actions your organization's admins take for 180 days.
Simpplr keeps four types of platform logs. Each log entry is counted from the moment it's recorded, so every entry expires on its own schedule.
Log type | What it records | Kept for (calendar days) | What happens next |
|---|---|---|---|
Request logs | Details of each request sent to or from Simpplr, including request details, whether it succeeded, the web address it went to, its unique request ID, and diagnostic details about how it was handled | 30 | Deleted automatically and permanently |
System health logs | How Simpplr's services are running, including health and performance measurements and diagnostic events | 30 | Deleted automatically and permanently |
Security protection logs | Traffic that Simpplr's security protections blocked, responses to attempts to overwhelm the platform with traffic, and records of connections being set up | 30 | Deleted automatically and permanently |
Admin activity logs | Actions your organization's admins take, such as adding or removing users, changing roles or permissions, and updating single sign-on settings | 180 | Archived on a set schedule |
Once a 30-day log is deleted, no one can get it back, including Simpplr engineering and support.
Simpplr sets every request log, system health log, and security protection log to expire automatically. When an entry reaches 30 calendar days (720 hours) from the time it was recorded in Coordinated Universal Time (UTC), the system permanently deletes it from Simpplr's monitoring systems.
Deleted logs can't be recovered, reconstructed, or restored.
Simpplr uses backups and disaster recovery copies only to keep the platform running and to restore its databases. They don't store expired request or troubleshooting logs, and they don't keep any record of them.
The 30-day limit exists because request logs can hold personal details, and privacy laws require deleting them once they're no longer needed.
Keeping only what's needed. Request logs may contain details such as IP addresses, browser and device information, and session IDs. A strict 30-day limit means Simpplr keeps these details only as long as it needs them to run the platform, in line with GDPR and CCPA.
SOC 2 Type II audits. Independent auditors regularly check the systems that store Simpplr's logs to confirm that automatic retention and deletion work continuously and correctly.
Encryption. Simpplr encrypts all logs while they're being sent, using TLS 1.2 or later, and while they're stored, using AES-256.
Submit your request within 30 calendar days of the event. Simpplr reviews and fulfills standard requests within 2 to 3 business days.
Your security or IT team can request log records for internal investigations, audits, or security reviews of events from the last 30 days.
Open a support ticket within 30 calendar days of the event.
Include the details in the table below so Simpplr can process your request without follow-up questions.
Expect the log records within 2 to 3 business days.
Detail | What to include | Required |
|---|---|---|
Affected user | The user's email address or unique account ID | Yes |
Date, time, and time zone | The specific date and time range of the event, preferably in UTC | Yes |
What happened | A summary of the activity you're looking into, such as a failed sign-in, a profile update, or a request from a connected app | Yes |
Web address or service | The specific web address or Simpplr service involved | Yes |
Reference IDs | Any request IDs, transaction IDs, or browser network recordings (HAR files) you saved | If known |
Q: Why does Simpplr keep request logs for only 30 days?
Ans: A 30-day window gives enough time to troubleshoot issues and review security events. It also meets international privacy laws that require activity data to be deleted regularly.
Q: Can Simpplr retrieve request logs older than 30 days on special request?
Ans: No. Automatic deletion rules permanently remove these logs after 30 days. Simpplr engineering and support teams can't retrieve them.
Q: Does the 30-day limit apply to admin activity logs?
Ans: No. Simpplr stores admin activity logs separately and keeps them for up to 180 days. These logs cover actions such as role changes, governance setting changes, and security setting changes.