Skip to content
FirstSIDocs

Data, GDPR and audit log

How long data is kept, how to turn purging on, and where to find who did what in the console.

Data retention

The setting is in GDPR (#/gdpr) or in the Data & GDPR tab of Settings.

SettingDefault
Automatic deletion after expiryoff
Retention period90 days (1 to 365)
Archive data before deletionno

The purge runs every 6 hours over the detailed data of every module (events, flows, measurements, logs…). Some data is kept longer because it serves security or trend analysis:

DataKept for
Hourly aggregates, SLA reports, compliance historyat least 365 days
Windows authentication failuresat least 1 year
Active Directory changesat least 3 years
Console audit logat least 365 days, up to 10 years
SIEM incidentsdeleted only once resolved or closed
NetDiag network captures30 days

A legal hold (retention required by legal proceedings) stops all purging until it is lifted.

Personal data

Most modules handle personal data: account names, IP addresses, a computer's network activity, file access. The most intrusive options are off by default and flagged in orange, such as open files and window titles in NetDiag. Lookups in Microsoft 365, Google Workspace, the directory and telecom lines are logged together with the name of the person looked up.

Remember to record each enabled module and its purpose (support, security, operations) in your register of processing activities. Connectors have Purpose (GDPR register) and Data concerned fields for this.

Audit log

The Audit Log (#/audit, administrators only) keeps a record of actions taken in the console: successful and failed sign-ins, two-factor authentication (including resets by an administrator), user creation and changes, role changes, settings changes, questions asked to the AI Assistant, sensitive lookups.

You can filter by action, entity, status and dates. The CSV export returns at most 10,000 rows.

Source: · FirstSI Docs · updated 2026-10-10