Data Retention Policy

This Data Retention Policy is published by the Company. The Company's full identity, address, and legal contact details appear at the bottom of this page.

This Policy explains how long the Company retains the various categories of data processed in connection with the Service, and what happens to that data once the applicable period has elapsed. It supplements the Privacy Policy and, for the Customer, the Data Processing Agreement: the latter prevails over the contractual terms applicable to the Customer's own data. This Policy applies to any data processed in connection with a Customer's or User's use of the Platform, whether account data, content, or technical logs generated by the operation of the Service.

> In short: we keep your data only for as long as necessary, under automated rules specific to each category, and then delete or anonymize it — except where the law requires us to retain it longer.

Table of Contents

  1. Our general retention principle
  2. Retention periods by data category
  3. Deletion upon contract termination
  4. Legal exceptions to deletion
  5. How to request early deletion
  6. Links to other documents

1. Our general retention principle

> In short: we keep data only for as long as needed for the reason we collected it, or to meet a legal obligation — never indefinitely by default.

The Company applies a principle of time-based minimization: each category of personal data processed in connection with the Service is retained only for the period necessary to the purposes described in the Privacy Policy, or for the period required by applicable legal obligations, including accounting and tax obligations.

This principle is applied in two concrete ways:

  • Retention periods defined by data category. Rather than a single period applied to all of the Service's data, each category — account data, Customer content, technical logs, exports, and so on — follows its own retention rule, proportionate to its purpose and sensitivity.
  • Automated enforcement. Once the applicable period has elapsed, deletion or anonymization of the data concerned is triggered by automated mechanisms built into the Platform, rather than by a one-off manual intervention. This reduces the risk that data is retained beyond its intended period through oversight.

The following sections set out the periods applicable to the main categories of data processed by the Service.

2. Retention periods by data category

> In short: here, category by category, is how long data stays in our systems before being automatically deleted or anonymized.

The table below summarizes the retention periods applicable to the main categories of data processed in connection with the Service. Where an exact period is not made public in this document, the category remains nonetheless subject to a defined retention rule applied automatically — see the "Applicable period" column for detail.

| Data category | Description | Applicable period |
|---|---|---|
| Customer account and content data | Account information, configurations, and content created or uploaded by the Customer in the course of using the Service (including exchanges processed by conversational agents) | For the duration of the contract, then for a reasonable period following termination, unless early deletion is requested — see Section 3 and the Data Processing Agreement |
| Login logs and technical checks | Logs related to authentication, system access, and technical operational checks | Automatic purge after 30 days by default |
| Audit logs | Logs tracing actions performed within the Service for traceability and security purposes | Period defined per log category, applied automatically by a recurring scheduled job |
| Other technical logs (contact channels, third-party integration gateways, system events) | Technical logs generated by integrations, communication channels, and internal Service events | Period defined per log category, applied automatically |
| Personal data exports | Export files generated at the request of a User or Customer | Download link with a limited lifespan, expiring automatically after a defined period |

These periods apply by default to all Customers and Users of the Service. Certain particular contractual terms applicable to a given Customer's data may be specified in the Data Processing Agreement entered into with that Customer.

3. Deletion upon contract termination

> In short: when a contract ends, its data does not disappear instantly — it is kept for a reasonable period, then permanently deleted, unless the Customer requests faster deletion.

When a contract between the Company and a Customer ends, the account and content data associated with that Customer is not necessarily deleted instantly. Instead, it is retained for a reasonable period following termination, in particular to allow for:

  • retrieval of data by the Customer before final closure of its account, where applicable;
  • resolution of any dispute or administrative matter related to the end of the contract;
  • compliance with the applicable legal obligations described in Section 4.

Upon expiry of that period, the data concerned is permanently deleted, in accordance with the automated procedures described in Section 1.

A Customer may request early deletion of its data before that reasonable period expires, subject to the legal exceptions described in Section 4. The precise terms applicable to the retention and deletion of a given Customer's data — including any specific contractual period — are set out in the Data Processing Agreement applicable to that Customer, which prevails over the general guidance in this section in the event of any discrepancy.

4. Legal exceptions to deletion

> In short: some data must occasionally be kept longer than planned, because the law or an ongoing proceeding requires it — we are not the ones deciding to extend retention, it is an external obligation.

The retention periods described in the preceding sections apply subject to legal exceptions that may, in certain cases, require data to be retained beyond the period normally applicable. These exceptions include, in particular:

  • accounting and tax obligations, which may require certain billing or transaction data to be retained for the period set by applicable law;
  • ongoing or reasonably foreseeable disputes, where relevant data may need to be retained for as long as necessary to resolve the dispute or to exercise, defend, or establish legal rights;
  • any other legal or regulatory obligation expressly imposing a minimum retention period on a given data category.

In these situations, only the data strictly necessary to the legal purpose invoked is retained beyond the normally applicable period; the remaining data stays subject to the deletion rules described above.

5. How to request early deletion

> In short: you can request deletion of your data before the normal deadline — the Platform includes a dedicated system for submitting this kind of request and tracking how it is handled.

A User or Customer who wishes to obtain deletion or correction of their personal data before the normally applicable periods expire may do so through the built-in deletion and correction request system offered by the Platform.

This system allows a request to be submitted and its handling tracked under a clear status:

  • pending — the request has been received and has not yet been taken up;
  • in progress — the request is being reviewed and processed;
  • completed — the request has been processed and the data concerned has been deleted or corrected, subject to the applicable legal exceptions;
  • denied — the request could not be processed as submitted, generally due to an applicable legal or contractual exception described in Section 4.

Any request for early deletion remains subject to the legal exceptions described in Section 4 and, for a Customer, to the applicable terms set out in the Data Processing Agreement. Where a request cannot be honored in full for these reasons, the status and scope of the deletion carried out are communicated to the requester through the same system.

6. Links to other documents

> In short: this Policy is part of a set of complementary documents — consult them for a full picture of the security and location of your data.

This Data Retention Policy should be read together with the other documents published by the Company, in particular:

  • the Security Overview, which describes the technical and organizational measures in place to protect data throughout its retention period;
  • the Data Residency & Transfers document, which specifies where data is hosted and under what conditions it may be transferred between jurisdictions;
  • the Privacy Policy, which describes the processing purposes underlying the retention periods referred to in this document;
  • for the Customer, the Data Processing Agreement, which specifies the contractual terms applicable to the retention and deletion of its own data.

In the event of any discrepancy between this Policy and the Data Processing Agreement applicable to a Customer, the latter prevails for that Customer's data.