One Identity keeps your personal data for as long as it decides is necessary for its business and legal purposes, using a general risk-based approach rather than publishing specific retention periods for each data category.
This analysis describes what OneLogin's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the operational framework governing data lifecycle management, linking retention duration to business necessity and regulatory mandate rather than indefinite storage. The multi-factor assessment approach (amount, nature, sensitivity, risk, legal requirements) creates a structured basis for retention decisions.
One Identity does not publish specific retention timeframes for individual data categories, making it difficult to verify when your personal data will be deleted — you can request deletion at any time, but the company may retain data it deems necessary for legal or business reasons.
How other platforms handle this
We collect and keep personal data only as needed or allowed for the purposes set out in this Statement, based on the reason we collected the personal data in the first instance and what is permitted under the laws that apply to the processing.
Affirm will retain your information in accordance with our Privacy Policy and any applicable state or federal law, rule or regulation.
Mistral AI shall retain the Customer Exportable Data and Assets for a period of thirty (30) days from the earlier between (a) the expiration of the Transitional Period or (b) Customer's notification under Section 2.2.2 (b) of these Additional Terms.
"We retain personal information for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, regulatory, accounting, or reporting requirements. When determining retention periods, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure, and applicable legal requirements.Excerpt from OneLogin's Privacy Policy
REGULATORY FRAMEWORK: GDPR Art.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the operational framework governing data lifecycle management, linking retention duration to business necessity and regulatory mandate rather than indefinite storage. The multi-factor assessment approach (amount, nature, sensitivity, risk, legal requirements) creates a structured basis for retention decisions.
One Identity does not publish specific retention timeframes for individual data categories, making it difficult to verify when your personal data will be deleted — you can request deletion at any time, but the company may retain data it deems necessary for legal or business reasons.
ConductAtlas has identified this type of provision across 275 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OneLogin.