LEGAL & TRUST
Data Retention and Deletion Policy
Retention is defined by record category and purpose. Removing information from an active account is different from expiring backups or preserving restricted records required by law. The corporate defaults below do not create one universal deletion period for every KRAVIA product.
1
Scope and principles
This Policy applies to corporate records and establishes a baseline for product schedules. Each product must identify its categories, retention triggers, ordinary duration, legal exceptions, storage and processor dependencies, and responsible owner. Information is not kept indefinitely merely because storage is inexpensive or it might become useful.
Where a record is needed for an applicable statutory purpose, the legal retention requirement prevails for that record. The retained copy must be purpose-restricted; a legal obligation is not permission to continue using it for product personalization, sales or AI training.
2
Corporate service-layer schedule
These are adopted design decisions for the corporate service, subject to verification before publication. The actual provider and backup schedules must be recorded before a public claim of complete deletion is made. A product's different approved schedule must be visible in its own notice.
| Record or event | Ordinary corporate rule | Important boundary |
|---|---|---|
| Ordinary AI-assistant conversations | 90 days from the conversation record's creation | Saved memory and deliberately created support records are separate; mandatory restricted records may last longer |
| Enquiry that does not become an active customer engagement | 12 months from the last substantive business interaction | Particularly sensitive attachments may need earlier removal; automated campaigns do not restart the clock |
| Free corporate account inactivity | Begin the inactivity process after 12 months without meaningful account activity | Send 30 days' notice and explain how to retain the account |
| Deliberate account-deletion request | Ordinarily complete eligible active-account deletion within 30 days | Follow any earlier mandatory period; verify proportionately and explain retained categories |
| Invoices, tax and accounting records | Applicable statutory and accounting schedule | Not deleted merely because the account closes; no unrelated reuse |
| Security, processing and audit records | Verified legal and security schedule for the relevant category | Some legal retention duties require longer restricted preservation |
| Backup copies | Verified backup rotation and expiry schedule | Protected from ordinary use; reapply deletions after restoration |
3
Account inactivity
Meaningful activity involves a genuine user interaction relevant to maintaining the account, not a tracking pixel, internal batch job or unsolicited marketing event. Before the inactivity deletion process completes, we notify the user using an appropriate registered channel and explain the deadline and reactivation method.
Open disputes, lawful holds and active contracted relationships may require separate handling. Such exceptions are documented rather than silently resetting an account's inactivity indefinitely. Corporate inactivity rules do not automatically delete an organization's student, employee or clinical records.
4
Requested deletion and exports
A verified deletion request starts the applicable workflow. Where appropriate, users can obtain eligible data before irreversible deletion. Recovery can be offered for a limited period where suitable, but it must not prevent an earlier deletion that the law requires or turn a request into an unwanted retention period.
We distinguish account closure, renewal cancellation, content deletion, saved-memory deletion and integration disconnection. Deleting one item does not necessarily perform all other actions. The interface and response explain what the request will do and the remaining options.
5
Restricted retention and legal holds
Some records must remain for tax, accounting, audit, regulatory, security, legal-claim or other lawful preservation purposes. A hold identifies the relevant information, reason, scope, owner and review or expiry event. Unrelated data is not automatically included. Access is limited and the record is not reused for an incompatible purpose.
When the reason ends, normal deletion resumes. Mandatory Indian security or data-processing retention may require preservation beyond the ordinary corporate defaults; the India supplement and internal legal schedule govern the applicable period. This Policy does not describe those duties as optional or assume they are already identical across commencement dates.
6
Backups and restoration
Backup copies are protected and retained according to a defined rotation schedule. They are not a second active database for continued ordinary use after deletion. Where removing an individual record from an immutable backup is not immediately feasible, it expires with the approved backup lifecycle, unless law requires otherwise.
After a restore, deletion instructions and suppression records must be reconciled so eligible previously deleted information is not inadvertently reactivated. Restored data is not put back into ordinary service without the appropriate controls. We do not promise instant erasure from every backup where that is not technically supported.
7
Processors, integrations and derived records
Relevant deletion and retention instructions are transmitted to processors under the applicable agreement. We review provider retention, logs, safety monitoring and backup arrangements; our own deletion of an API request does not prove that a provider erased its copy.
Disconnection stops future authorized access through an integration. It does not automatically erase records a third party independently controls. Derived identifiable information, retrieval indexes and saved memories must be considered in the deletion map, not ignored because they are not the original file. Truly anonymized aggregates that no longer relate to an identifiable person may be retained with safeguards against re-identification.
8
Evidence, questions and corrections
We maintain proportionate evidence of deletion jobs, legal exceptions and outcomes without retaining a new complete copy of the material being deleted. Failed deletion tasks require investigation and retry. A successful user-interface message must not be treated as proof that all storage systems have completed their work.
Contact privacy@kraviaprivatelimited.com about the applicable schedule, a deletion request or a retained record. Where exact periods depend on a legal duty or contract, we explain the relevant criteria and restrictions rather than offering a misleading single number.