Skip to content
Help  /  Security

Exporting and deleting your data

Your event data is yours. This covers getting a copy out, deleting individual records, deleting everything, and what deletion does and does not reach.

Before you start

1. Export a single module

Most modules have their own Export in the header, which gives you that module's records as a file. Two worth knowing by name: Export Guest CSV in the Table Planner, which carries the dietary column your caterer wants, and Export Table Plan CSV, which is the seating rather than the people. Print Guest List, Print Table Plan and Name Cards are next to them for the paper the room needs.

2. Export the whole account

Settings & Branding → Data & Privacy → Export All Data. Use this before a migration, before a purge, and at the end of every cycle as your own archive. Do not treat our backups as your archive — they are for disaster recovery, they are not customer-restorable, and they expire.

3. Delete individual records

Delete a record from its own module. Do this before, not after, anything that depends on it: deleting a nomination that has been scored takes its scores with it, and deleting a guest who has been seated frees the seat but does not tell the caterer.

4. Anonymise instead of deleting

Anonymise Test Data in Data & Privacy is the option people forget. If you have been trialling with real names, this lets you keep the shape of the data without keeping the people in it — usually a better answer than deleting a workspace and starting again.

5. Delete everything

Purge All Data does exactly what the label says and it is not an undo you can press. Export first, confirm who else is using the workspace, then run it.

For deletion of the account itself, email privacy@accolade.live. After cancellation your data is retained for 90 days so you can still export it, then permanently deleted from primary databases, and we confirm in writing.

6. Set your retention policy once

Data & Privacy also holds the retention settings, and it is worth setting them deliberately rather than leaving the defaults: Nomination Data, Financial Records, User Activity Logs and Deleted Data Purge. As the data controller you decide these; we apply them.

What deletion does not reach

Backups are encrypted and taken daily. They expire automatically on a rolling window set by our database provider, which means a record deleted from the live platform remains inside unexpired backups until the last backup containing it rolls off. Backups are never used to restore deleted customer records to the live platform. We are confirming the exact retention window with the provider and will publish it here once it is confirmed.

The practical consequence: a record deleted from the live platform is gone from the live platform immediately, and disappears from backups when the last backup containing it expires. If you are answering an erasure request, that distinction is the one to put in your reply.

Subject access and erasure requests

You are the data controller for your nominees, judges and guests, so requests come to you first. The Data Subject Requests (DSARs) register in Data & Privacy is where you log one with + New Request, and it tracks the statutory deadline alongside it. Search the person's email in the relevant module, export the result, and record what you sent. The GDPR overview covers the controller/processor split.

Common problems

Not a customer yet?

The Free plan runs a real event on the same codebase and the same database as every paid tier, so you can follow this guide against your own data. First reply on support is 1 business day on Professional, 4 business hours on Enterprise and 1 business hour on Agency; Free is best effort with no written target. The full targets and severity definitions are on /support.