Retention & erasure
このコンテンツはまだ日本語訳がありません。
There are two ways to remove a document, and the difference matters.
Ordinary delete — reversible
Section titled “Ordinary delete — reversible”Delete (at the bottom of a document’s drawer) is a soft delete. The document leaves the folder and moves to Pending deletions on the Retention page (the Files group in the sidebar). From there you can:
- Restore it back to where it was, or
- leave it — its bytes and history are retained, just out of the way.
Nothing is destroyed. This is the everyday “get this out of the active tree” action, and it’s always undoable. A deleted document keeps its record and can still be found in the queue.
Legal erasure — permanent
Section titled “Legal erasure — permanent”Erase permanently is different in kind. It exists for a legal erasure request — PDPA / GDPR / APPI “right to be forgotten” — where you must be able to attest that the material is gone, not merely hidden. It:
- Destroys every version’s bytes in storage.
- Removes all derived knowledge — anything the platform extracted from the document (the same purge as removing an inbox item).
- Deletes the document’s rows, including any share links (the links go dead).
- Leaves one trace: an entry in the erasure ledger recording what was erased, when, by whom, and the reason you gave.
Because it’s irreversible, the action asks for two things: a reason (the legal basis — required, and it’s the one thing the ledger keeps) and the document’s name retyped to confirm. It’s available to workspace admins on the filing surface.
The erasure ledger
Section titled “The erasure ledger”The Erasure ledger (on the same Retention page) is the permanent, append-only record of every erasure on the project: the document name, the reason, who did it and when. It’s what you show to demonstrate that an obligation was met — the ledger persists precisely because the document doesn’t.
What about partner uploads?
Section titled “What about partner uploads?”A delivery partner’s uploads belong to the project record. Revoking a partner’s access ends their portal, but doesn’t erase what they filed — that stays part of the project’s history and is subject to the same two mechanisms above.