What is Security & Data Retention?
Security & Data Retention covers two areas of your workspace: the security controls that protect your data, and the retention rules that automatically delete recordings or candidate data after a time period you choose. Together, these features help support compliance requirements like GDPR, CCPA, and HIPAA while keeping your research operations running.Why it matters
Protect participant data at every layer. Great Question maintains SOC 2 Type II attestations, encrypts data in transit and at rest, and applies field-level encryption for sensitive credentials. Support privacy regulations. Built-in tooling helps you honor participant data rights and enforce retention policies in support of GDPR, CCPA, and HIPAA. Control how long data lives in your workspace. Configurable retention rules let Admins set deletion schedules for recordings and candidates. Enforce access at every level. Role-based access controls, team-scoped permissions, and SAML SSO.Infrastructure and encryption
Great Question’s infrastructure is hosted on AWS, using SOC 1 and SOC 2 certified data centers in the US-1 East region. All data in transit is encrypted with TLS, and data at rest uses AES-256 block-level encryption. Security posture is continuously monitored through Vanta, with regular penetration tests and policy reviews.Authentication
Great Question supports multiple authentication methods, configurable at the account level:- Password — Must be 8 to 70 characters and include at least one uppercase letter, one lowercase letter, one digit, and one special character.
- Google OAuth — Sign in with your Google account.
- OpenID Connect — Sign in with a Microsoft or Intuit account, configured per account.
- SAML SSO — Supported identity providers include Okta, Azure AD, OneLogin, JumpCloud, and Google. Each account configures one SAML provider.
- SCIM — Open-standard protocol for automated cloud identity and access management, available on Enterprise plans.
Roles and access controls
Great Question uses a role-based access control system. The standard roles are:See User Roles and Permissions for the full breakdown of what each role can do, including how Admins can adjust the minimum role required for specific actions.
Compliance
SOC 2 Type II. Great Question has completed SOC 2 Type I and Type II audits. GDPR and CCPA. Great Question supports your compliance needs as both a data processor and a partner in protecting participant information:- Right to access and portability — Request data exports via support.
- Right to be forgotten — Deletion across our systems and sub-processors.
- Right to object — Participants can opt out per study or across the account.
- Right to rectification — Users can make updates directly or by contacting support.
Data retention
Admins can create data retention rules that automatically delete recordings or candidate data after a period of time you choose. This supports data minimization and compliance with privacy standards such as GDPR and CCPA.Only Admins can create and manage data retention rules.
Configurable retention periods
When creating a rule, choose from preset durations — 1, 2, 3, or 6 months, or 1 or 2 years — or set a custom duration (the settings UI supports up to 100 days, weeks, months, or years). Each rule applies to a specific resource type and is scoped to your account.Resource types
Data retention rules can target Recordings or Candidates. Recordings — When a recording is deleted, its transcript, AI-generated summaries and chapters, video file and thumbnails, and any highlights and clips created from it are removed with it. Candidates — When a candidate is deleted via a retention rule, screener responses are destroyed, clips are removed from highlight reels (reels are automatically restitched), participations and linked recordings are discarded, and PII (name, email, phone number) is anonymized.What stays intact
Studies, incentive records, data retention audit logs, and the retention rules themselves are not affected by data retention deletions.How deletion works
Data retention runs as a two-stage background process. Each night, the system first identifies records that have exceeded their retention period and marks them for deletion in an audit log; a short time later, marked records are processed and soft-deleted. Records are never deleted before the rule’s activation date (plus a short buffer), so no retroactive deletions occur immediately upon rule creation.Audit trail
Every data retention action is logged in a dedicated audit trail. Logs track when a record was scheduled for deletion, when it was actually deleted, and its outcome (pending, approved, completed, failed, or cancelled). Audit logs are permanently retained even after the associated data is removed.How to set up data retention rules
- Click your name in the bottom-left corner and select Settings.
- Navigate to Governance > Data Retention.
- Click New Rule.
- Select the resource type (Recording or Candidate), set the retention period, and preview which records will be affected.
- Activate the rule. You can pause, resume, or archive rules at any time.
Rule statuses
Troubleshooting
Still need help? Contact us at support@greatquestion.co — median response time is 19 minutes during support hours.