/ /

Platform log retention and telemetry lifecycles

Updated 32 seconds ago

Overview

This article explains how long Simpplr keeps platform logs, how it deletes them, and how your team can request log records for an investigation.

It covers three areas.

  • How long Simpplr keeps request logs, system health logs, security protection logs, and admin activity logs.

  • How Simpplr deletes logs automatically when they expire.

  • What to include when you request log records for an investigation.

These time limits let Simpplr find and fix platform issues while keeping only the data it needs. They align with SOC 2 Type II, ISO/IEC 27001, and global privacy laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the California Privacy Rights Act (CPRA).

Note: Simpplr automatically and permanently deletes most platform logs after 30 days. It keeps records of actions your organization's admins take for 180 days.

How long Simpplr keeps each log

Simpplr keeps four types of platform logs. Each log entry is counted from the moment it's recorded, so every entry expires on its own schedule.

Log type

What it records

Kept for (calendar days)

What happens next

Request logs

Details of each request sent to or from Simpplr, including request details, whether it succeeded, the web address it went to, its unique request ID, and diagnostic details about how it was handled

30

Deleted automatically and permanently

System health logs

How Simpplr's services are running, including health and performance measurements and diagnostic events

30

Deleted automatically and permanently

Security protection logs

Traffic that Simpplr's security protections blocked, responses to attempts to overwhelm the platform with traffic, and records of connections being set up

30

Deleted automatically and permanently

Admin activity logs

Actions your organization's admins take, such as adding or removing users, changing roles or permissions, and updating single sign-on settings

180

Archived on a set schedule

How automated deletion works

Once a 30-day log is deleted, no one can get it back, including Simpplr engineering and support.

Rolling expiry

Simpplr sets every request log, system health log, and security protection log to expire automatically. When an entry reaches 30 calendar days (720 hours) from the time it was recorded in Coordinated Universal Time (UTC), the system permanently deletes it from Simpplr's monitoring systems.

Permanent deletion

Deleted logs can't be recovered, reconstructed, or restored.

Backups don't keep expired logs

Simpplr uses backups and disaster recovery copies only to keep the platform running and to restore its databases. They don't store expired request or troubleshooting logs, and they don't keep any record of them.

Security and privacy

The 30-day limit exists because request logs can hold personal details, and privacy laws require deleting them once they're no longer needed.

  • Keeping only what's needed. Request logs may contain details such as IP addresses, browser and device information, and session IDs. A strict 30-day limit means Simpplr keeps these details only as long as it needs them to run the platform, in line with GDPR and CCPA.

  • SOC 2 Type II audits. Independent auditors regularly check the systems that store Simpplr's logs to confirm that automatic retention and deletion work continuously and correctly.

  • Encryption. Simpplr encrypts all logs while they're being sent, using TLS 1.2 or later, and while they're stored, using AES-256.

Request log records

Submit your request within 30 calendar days of the event. Simpplr reviews and fulfills standard requests within 2 to 3 business days.

Your security or IT team can request log records for internal investigations, audits, or security reviews of events from the last 30 days.

  1. Open a support ticket within 30 calendar days of the event.

  2. Include the details in the table below so Simpplr can process your request without follow-up questions.

  3. Expect the log records within 2 to 3 business days.

Detail

What to include

Required

Affected user

The user's email address or unique account ID

Yes

Date, time, and time zone

The specific date and time range of the event, preferably in UTC

Yes

What happened

A summary of the activity you're looking into, such as a failed sign-in, a profile update, or a request from a connected app

Yes

Web address or service

The specific web address or Simpplr service involved

Yes

Reference IDs

Any request IDs, transaction IDs, or browser network recordings (HAR files) you saved

If known

Frequently asked questions

Q: Why does Simpplr keep request logs for only 30 days?

Ans: A 30-day window gives enough time to troubleshoot issues and review security events. It also meets international privacy laws that require activity data to be deleted regularly.

Q: Can Simpplr retrieve request logs older than 30 days on special request?

Ans: No. Automatic deletion rules permanently remove these logs after 30 days. Simpplr engineering and support teams can't retrieve them.

Q: Does the 30-day limit apply to admin activity logs?

Ans: No. Simpplr stores admin activity logs separately and keeps them for up to 180 days. These logs cover actions such as role changes, governance setting changes, and security setting changes.

Was this article helpful?
Subscribe to receive updates on this article