Data Retention and Disposal Policy

Last updated: August 8, 2026

This policy defines how long Assenture retains data, why, and how it is securely disposed of at the end of its life. It applies to all data processed by Assenture, including personal data of our customers' employees and consumer financial data received through our bank data aggregation partner. It is designed to comply with the UK GDPR, EU GDPR, the California Consumer Privacy Act as amended, Singapore's PDPA and the Gramm-Leach-Bliley Act safeguards expectations that apply to consumer financial information. Read it with our Privacy Policy, Data Processing Addendum, Security Policy and Logging and Monitoring Policy.

1. Principles

  • Purpose limitation. Data is retained only for the purpose it was collected for, or a compatible one.
  • Storage limitation. Data is kept for the shortest period that satisfies that purpose and any legal obligation.
  • Defined schedules. Every category of data has an owner and a maximum retention period, enforced by automation rather than memory.
  • Irreversible disposal. When the period ends, data is destroyed in a way that makes recovery infeasible.
  • Customer control. Customers can delete their data at any time, subject only to retention we are legally required to apply.

2. Roles

For data our customers put into Assenture, the customer is the controller and Assenture is the processor; we retain and delete on their documented instructions and in line with the schedules below. For our own account, billing and website data we are the controller. Our Data Protection Officer owns this policy.

3. Retention schedule

CategoryRetentionBasis
Account and profile data (name, work email, role)Life of the account, then 30 daysContract performance
Workspace business records (assets, tasks, employees, documents, messages, meetings)Life of the account, then 30 days; customer may delete at any timeController instruction
Consumer financial data from our aggregation partner (account metadata, balances, transactions)While the connection is active; deleted within 30 days of disconnection, account closure or consumer withdrawal of consent, whichever is firstConsent and contract
Aggregator access tokens and item identifiersRevoked with the provider and deleted immediately on disconnectionSecurity
Meeting recordings, transcripts and AI notesCustomer-configurable, default 90 days; deleted immediately where a participant opted out of recordingConsent and controller instruction
AI prompts, file extractions and generated outputsHeld with the conversation and deleted with it; not used to train third-party modelsController instruction
Security and privilege audit records12 months hot, 24 months archivedLegal obligation, legitimate interest in security
Application and infrastructure logs90 days hot, 12 months archivedLegitimate interest in security
Billing, invoices and tax records7 years from the end of the relevant financial yearLegal obligation
Support correspondence24 months from closureLegitimate interest
Marketing contactsUntil unsubscribe, then suppression-list record onlyConsent
Encrypted backupsRolling 35 days, then automatic expiryResilience

4. Deletion on request and on termination

  • A workspace administrator can delete individual records at any time and can request deletion of the entire workspace from account settings.
  • On account termination, live data is deleted within 30 days. The window exists so an accidental cancellation can be reversed; a customer may request immediate deletion instead.
  • Deletion is propagated to subprocessors under contractual instruction, and confirmation is obtained.
  • A consumer whose financial account was connected may withdraw consent at any time; disconnection revokes the aggregator token immediately and deletes the derived data within 30 days.
  • Written confirmation of deletion is provided on request.

5. Backups

Deleted records may persist in encrypted backups until those backups expire on the rolling 35-day cycle. Backups are never restored selectively to resurrect deleted data. If a backup must be restored for disaster recovery, deletion requests processed since the snapshot are re-applied immediately after restoration.

6. Disposal methods

  • Database records. Hard delete, with cascading removal of dependent rows. Soft deletion is used only where the product requires historical continuity and is itself subject to the schedule above.
  • Object storage. Objects and all versions deleted; lifecycle rules prevent orphaned copies.
  • Cryptographic erasure. Where data is encrypted with a per-tenant or per-object key, destruction of the key is used to render the data unrecoverable.
  • Logs. Expired by automated retention jobs running under a privileged service identity; no manual deletion of audit records is permitted.
  • Devices and media. Corporate devices are fully-disk encrypted; decommissioning uses cryptographic erase and, for physical media, destruction by a certified vendor with a certificate of destruction.
  • Paper. Cross-cut shredding. We do not hold customer data in paper form in the ordinary course.

7. Anonymisation

We may retain aggregated or irreversibly anonymised statistics beyond these periods for capacity planning and product analytics. Such data contains no identifiers and cannot be re-associated with an individual, workspace or financial account.

8. Legal holds

Where data is subject to litigation, regulatory investigation or a lawful preservation request, the applicable retention period is suspended for the specific records in scope. Holds are documented, scoped as narrowly as possible, owned by the DPO, and released promptly when the matter closes, after which the normal schedule resumes.

9. Enforcement and evidence

  • Retention periods are implemented as scheduled jobs and storage lifecycle rules, not manual processes.
  • Job outcomes are logged and monitored; a failed retention job raises an alert.
  • Deletion events are recorded in the audit trail with actor, scope and time.

10. Review

This policy and the schedule are reviewed at least annually by the DPO with engineering and finance, and additionally whenever a new data category, subprocessor, jurisdiction or product capability is introduced. Changes are versioned and dated on this page.

11. Contact

Retention or deletion questions: privacy@assenture.app. To exercise access, correction or deletion rights, see our Data Subject Requests process.