A security-questionnaire question, answered without certification

How can customers get their data deleted, and what are your retention periods?

The honest answer pattern

Commit to a deletion path you actually operate: how a customer asks, how long removal from live systems takes, and when backups age out. Tie the backup retention window to the deletion answer so the two never contradict each other. If deletion is manual today, say it is handled on request rather than implying a self-service button that does not exist.

What a credible answer looks like

A credible answer is specific and current-tense only where it's true: it names your actual provider and systems, states what is in place today, and moves anything that isn't into a clearly labelled roadmap item instead of an aspirational “yes”. Reviewers read dozens of these a quarter — vague assurances are what get a vendor flagged, not missing certifications.

You can see this pattern applied end-to-end in the full sample security pack — a real trust page, three policies, and an answer bank generated by the same pipeline a paying customer uses, shown without any email gate.

The facts your answer needs (from the Trustpack intake):

  • How can customers get their data deleted?
  • How are backups handled?
  • What categories of customer data do you store?

Answer the whole questionnaire, not one row

Trustpack turns your own attested answers into three security policies, a copy-paste answer bank covering the canonical questionnaire topics, and a live public trust page. Every document is vendor-attested and says so plainly — it never claims certification. Flat $49, one time.

← All answer guides