Data Retention and Disposal Policy
Last updated: August 8, 2026
This policy defines how long Assenture retains data, why, and how it is securely disposed of at the end of its life. It applies to all data processed by Assenture, including personal data of our customers' employees and consumer financial data received through our bank data aggregation partner. It is designed to comply with the UK GDPR, EU GDPR, the California Consumer Privacy Act as amended, Singapore's PDPA and the Gramm-Leach-Bliley Act safeguards expectations that apply to consumer financial information. Read it with our Privacy Policy, Data Processing Addendum, Security Policy and Logging and Monitoring Policy.
1. Principles
- Purpose limitation. Data is retained only for the purpose it was collected for, or a compatible one.
- Storage limitation. Data is kept for the shortest period that satisfies that purpose and any legal obligation.
- Defined schedules. Every category of data has an owner and a maximum retention period, enforced by automation rather than memory.
- Irreversible disposal. When the period ends, data is destroyed in a way that makes recovery infeasible.
- Customer control. Customers can delete their data at any time, subject only to retention we are legally required to apply.
2. Roles
For data our customers put into Assenture, the customer is the controller and Assenture is the processor; we retain and delete on their documented instructions and in line with the schedules below. For our own account, billing and website data we are the controller. Our Data Protection Officer owns this policy.
3. Retention schedule
| Category | Retention | Basis |
|---|---|---|
| Account and profile data (name, work email, role) | Life of the account, then 30 days | Contract performance |
| Workspace business records (assets, tasks, employees, documents, messages, meetings) | Life of the account, then 30 days; customer may delete at any time | Controller instruction |
| Consumer financial data from our aggregation partner (account metadata, balances, transactions) | While the connection is active; deleted within 30 days of disconnection, account closure or consumer withdrawal of consent, whichever is first | Consent and contract |
| Aggregator access tokens and item identifiers | Revoked with the provider and deleted immediately on disconnection | Security |
| Meeting recordings, transcripts and AI notes | Customer-configurable, default 90 days; deleted immediately where a participant opted out of recording | Consent and controller instruction |
| AI prompts, file extractions and generated outputs | Held with the conversation and deleted with it; not used to train third-party models | Controller instruction |
| Security and privilege audit records | 12 months hot, 24 months archived | Legal obligation, legitimate interest in security |
| Application and infrastructure logs | 90 days hot, 12 months archived | Legitimate interest in security |
| Billing, invoices and tax records | 7 years from the end of the relevant financial year | Legal obligation |
| Support correspondence | 24 months from closure | Legitimate interest |
| Marketing contacts | Until unsubscribe, then suppression-list record only | Consent |
| Encrypted backups | Rolling 35 days, then automatic expiry | Resilience |
4. Deletion on request and on termination
- A workspace administrator can delete individual records at any time and can request deletion of the entire workspace from account settings.
- On account termination, live data is deleted within 30 days. The window exists so an accidental cancellation can be reversed; a customer may request immediate deletion instead.
- Deletion is propagated to subprocessors under contractual instruction, and confirmation is obtained.
- A consumer whose financial account was connected may withdraw consent at any time; disconnection revokes the aggregator token immediately and deletes the derived data within 30 days.
- Written confirmation of deletion is provided on request.
5. Backups
Deleted records may persist in encrypted backups until those backups expire on the rolling 35-day cycle. Backups are never restored selectively to resurrect deleted data. If a backup must be restored for disaster recovery, deletion requests processed since the snapshot are re-applied immediately after restoration.
6. Disposal methods
- Database records. Hard delete, with cascading removal of dependent rows. Soft deletion is used only where the product requires historical continuity and is itself subject to the schedule above.
- Object storage. Objects and all versions deleted; lifecycle rules prevent orphaned copies.
- Cryptographic erasure. Where data is encrypted with a per-tenant or per-object key, destruction of the key is used to render the data unrecoverable.
- Logs. Expired by automated retention jobs running under a privileged service identity; no manual deletion of audit records is permitted.
- Devices and media. Corporate devices are fully-disk encrypted; decommissioning uses cryptographic erase and, for physical media, destruction by a certified vendor with a certificate of destruction.
- Paper. Cross-cut shredding. We do not hold customer data in paper form in the ordinary course.
7. Anonymisation
We may retain aggregated or irreversibly anonymised statistics beyond these periods for capacity planning and product analytics. Such data contains no identifiers and cannot be re-associated with an individual, workspace or financial account.
8. Legal holds
Where data is subject to litigation, regulatory investigation or a lawful preservation request, the applicable retention period is suspended for the specific records in scope. Holds are documented, scoped as narrowly as possible, owned by the DPO, and released promptly when the matter closes, after which the normal schedule resumes.
9. Enforcement and evidence
- Retention periods are implemented as scheduled jobs and storage lifecycle rules, not manual processes.
- Job outcomes are logged and monitored; a failed retention job raises an alert.
- Deletion events are recorded in the audit trail with actor, scope and time.
10. Review
This policy and the schedule are reviewed at least annually by the DPO with engineering and finance, and additionally whenever a new data category, subprocessor, jurisdiction or product capability is introduced. Changes are versioned and dated on this page.
11. Contact
Retention or deletion questions: privacy@assenture.app. To exercise access, correction or deletion rights, see our Data Subject Requests process.