Personal Data Retention screen

Company > Profile > Persona Data Retention

Invitations to provide feedback and records may contain personally identifiable information. Some of this data must be retained at least until the respondent completes the feedback or until the signal expires. Other data are useful for tracking and reporting purposes, but may be considered personal.

Use the Personal Data Retention screen to control what and how long to retain personal data in unopened and completed records.

Note: Imported files and events may contain personal data. Such files and events are purged from Medallia Experience Cloud as per the schedules on the Company settings screen.

Ballot deletion

Surveys are created when an Invitation email is sent to contacts. These unopened surveys (called ballots) exist in the Survey engine and contain personally identifiable data about the respondent. To ensure privacy, and for compliance with government regulations, the unopened surveys must be erased after a period of time.

Invitations expire some number of days after being created, as specified on the distribution setting expiration. As such, unopened ballots must remain in the Survey engine until at least after they expire.

Delete ballots after survey program expires
Whether or not to remove data from the Survey Engine.
Days offset
When to erase the data from the Survey engine after the associated invitation expires. The range is 1 to 30 days, where 1 means the data is erased at least 1 day (24 hours) after the invitation expired.
Important: The erase process runs once per day. As such, it is possible for the ballot data to remain in the Survey engine for up to 24 hours past the target time, depending on when the invitation expired.
Last Survey Engine sweep
When survey ballot data was last erased from the Survey engine.

Survey data retention

In addition to the data provided when taking a survey, Medallia Experience Cloud also records identifiable information when the customer starts to take a survey. Specifically, it tracks data in these fields:

  • Survey cookie confirmation needed (a_survey_is_cookie_confirmation_needed) — Whether or not the customer is know to be in a country that requires confirmation of the survey using cookies.
  • The IP address from which the invitation was opened (a_invite_first_opened_ip_address) — IP address of the device that first opened the invitation, when the address is provided by the device.
  • IP address (a_ipaddress) — IP address of the device that took the survey, when the address is provided by the device.
  • HTTP client cookies (a_cookies) - The cookie created by the survey engine while the survey taker takes the survey.
Do not track IP addresses in survey records
Whether or not to track IP addresses and cookie confirmation in the record.
Warning: Selecting this property stops tracking for future records, but does not impact historical records.
Important: Selecting this checkbox does not affect Anti-cheating Engine and its associated health check reports. ACE stills generates the reports with the IP address appearing most frequently among those associated with the record. This is because ACE does not use the IP address field for these reports. Primary IP Address (e_primary_ip_address) field is created from the deployment of the Anti-Cheating Engine app. When Experience Cloud imports the export from ACE, the field Primary IP Address (bp_fp_primary_ip_address_txt) is populated with the value from field Primary IP Address (e_primary_ip_address). For more information, see Program fields.