If your subscription lapses — what stops and what is kept

A lapsed subscription puts your account into dormant. Nothing is deleted, resubscribing resumes everything, and each surface stops at the moment it is used.

If a renewal payment fails, your subscription enters a short grace period — everything keeps working while you sort the payment out. If it is not resolved by the end of that period, your account becomes dormant.

Dormant is not deleted, and it is not closed. It is your account, paused.

Nothing is deleted

Your saved documents and their version history, your business profile, your subprocessor register, your published record, your clause library and your data subject request log all stay exactly as they were.

What stops, and when

Nothing is switched off in advance. Each thing stops at the moment it is used:

SurfaceWhat happens
API tokens (mt_live_*)Requests to /api/v1/* stop being served
Auditor share linksStop opening. The auditor sees the same "access ended" page they would see if you had revoked the link — they are never told anything about your account
Signature links sent to counterpartiesStop opening, and a signature cannot be completed. The counterparty sees the same page an expired or cancelled link shows
Public data subject request intakeStops accepting submissions once your subscription has ended. It stays open for as long as a failed payment is still being retried. Anyone who tries after it closes is shown a neutral message asking them to contact you directly
Outbound webhooksStop delivering. The endpoint stays configured and is never auto-disabled; skipped events appear in the delivery log as Not sent
Public subprocessor feedStops serving. The feed URL and its token are unchanged
Subprocessor change emailsStop going to your feed subscribers. Nobody is unsubscribed
Drift notifications (Slack / Discord)Stop firing. Your webhook URL is kept
Reminder emailsRenewal reminders and annual review reminders stop
Data subject request deadline remindersStop

Two things to plan for.

Deadline reminders stop; the deadlines themselves do not. An open request keeps its response date, but you will not be reminded of it and you will not be able to open it — the dashboard is closed and the API refuses. Export is the way to it, and the export includes your full request log.

Requests submitted to your intake form once your account is dormant are not received and not stored. We never tell the person anything about your account, and their rights are unaffected.

What you can still do

A dormant account keeps three things, and none of them is a paid feature:

  1. Resubscribe — from the screen you land on when you sign in, or directly at id.dekimu.com/billing.
  2. Export everything — your profile, every draft, your subprocessors and your full data subject request log.
  3. Delete your account — at id.dekimu.com/privacy-center, which cascades to your miniterms workspace.

Signing in still works. You land on a screen with those three actions instead of the dashboard.

How it resumes

Resubscribing is the whole of it. There is nothing to re-enable, re-configure or re-issue:

  • your API tokens start answering again — the same tokens, not new ones;
  • your auditor share links open again, for whatever time was left on them;
  • your intake form starts accepting submissions again, on the same intake token, so your website needs no change;
  • your webhooks deliver again, at the same URLs, with the same signing secrets;
  • your subprocessor feed serves again at the same URL;
  • reminders resume on their normal schedule.

Events that were not delivered while you were dormant appear in the delivery log marked Not sent, with the original payload kept, and Retry sends one now.

The log is bounded, so this is not a substitute for a queue: it holds the most recent 100 attempts per webhook, and entries are kept for 90 days. Anything past either bound is gone and cannot be replayed.