Data Retention Policy

Effective date | Last updated | Contact
17 September 2026 | 17 September 2026 | [email protected] | +91 95581 33552

This Data Retention Policy explains AiToolkit’s default approach to keeping and deleting data. Retention may vary when a business customer selects a different supported setting, a written enterprise agreement applies, an investigation/legal hold is active, or applicable law requires a different period.

12.1 Retention principles

  • Keep data only as long as necessary for a defined business, contractual, security or legal purpose.
  • Allow customer-controlled deletion where appropriate and technically supported.
  • Separate active operational data from restricted archives or backups where feasible.
  • Retain only limited data after account deletion when there is a legitimate legal, accounting, security or dispute reason.
  • Use secure deletion, expiry, anonymization or overwrite processes appropriate to the storage system.

12.2 Default retention schedule

Data category | Default retention approach | Notes
Account/profile data | While account is active; targeted deletion within 30 days after verified account deletion. | Limited records may remain for legal/security reasons.
CRM contacts & custom fields | While the customer account is active, unless deleted earlier by the customer; generally up to 30 days after full account deletion. | Business customers control the lawful basis and may delete records sooner.
WhatsApp message content & media stored by AiToolkit | While needed for the subscribed CRM service or until customer deletion; generally up to 30 days after full account deletion. | Meta/WhatsApp and recipients may retain independent copies outside AiToolkit.
Campaign/automation logs | Generally up to 12 months after creation or as configured for the account. | Longer retention may apply for troubleshooting or audit needs.
Authentication/session logs | Generally up to 180 days. | May be retained longer where needed for a security investigation.
Security/audit logs | Generally up to 12 months. | May be extended for fraud prevention, incident response or legal hold.
Support tickets & related communications | Generally up to 24 months after closure. | Sensitive attachments may be removed sooner when no longer needed.
Billing, invoice & tax records | Up to 8 years or the period required by applicable tax/accounting law. | Payment processors may retain separate records under their own policies.
Consent, opt-out & suppression records | For as long as reasonably necessary to demonstrate compliance and avoid re-contact, typically up to 5 years after last relevant activity. | A minimal suppression record may be retained even after other contact data is deleted.
Backups | Rotating backup copies generally expire within 90 days after production deletion. | Backups are not ordinarily restored to recover individual deleted records unless operationally necessary.
Cookie/analytics identifiers | Session duration for session cookies; optional analytics identifiers typically up to 13 months where configured. | Subject to consent and provider settings.
Refund/chargeback records | Generally up to 8 years with related financial records. | Needed for accounting, fraud prevention and dispute evidence.

12.3 Deletion from backups

When data is removed from active production systems, the same data may remain temporarily in encrypted or access-controlled backups until the normal backup rotation expires. Backups are maintained for disaster recovery and service continuity and are not intended for ordinary use of deleted information. If a backup must be restored, deletion controls should be reapplied where reasonably feasible.

12.4 Legal holds and exceptions

AiToolkit may suspend normal deletion when information is relevant to litigation, a regulatory inquiry, fraud investigation, security incident, unpaid dispute, lawful government request or another legal preservation obligation. A legal hold is limited to relevant information and lifted when the preservation need ends.

12.5 Customer responsibilities

Business customers should configure retention to match their industry, consent model and legal obligations. Customers are responsible for exporting records they are legally required to keep and for deleting data they no longer need. AiToolkit’s default schedule does not replace industry-specific retention rules that apply to a customer.

12.6 Deletion requests

Account deletion and specific data-deletion requests are handled through the Account Deletion and Data Deletion Request pages. Questions about retention may be sent to [email protected].