Data Retention & Deletion Policy
Chaos Circle is committed to responsible data management. This policy outlines how long we retain different types of data, our deletion procedures, and your rights regarding data retention. We comply with GDPR, CCPA, and other applicable data protection regulations. Our data retention practices are designed to balance operational needs with privacy requirements, ensuring we keep data only as long as necessary for the purposes for which it was collected.
Data Retention Periods
| Data Category | Retention Period | Justification |
|---|---|---|
| Account Information | Duration of account + 30 days | Required for service delivery and account recovery |
| Chaos Circle Assessments | Duration of account + 90 days | Historical analysis and trend tracking |
| Team Member Data | Duration of account + 30 days | Organizational management features |
| AI Conversation History | 90 days | Service improvement and context continuity |
| Audit Logs | 2 years | Security compliance and incident investigation |
| Billing & Transaction Records | 7 years | Legal and tax compliance requirements |
| Contact Form Submissions | 2 years | Customer support and dispute resolution |
| Data Subject Requests | 3 years | Regulatory compliance documentation |
| Security Incident Logs | 5 years | Security analysis and regulatory requirements |
| Session & Authentication Data | 30 days after session end | Security monitoring and fraud prevention |
Deletion Procedures
Data is automatically deleted according to the retention schedules above. Our automated systems run daily to identify and securely delete data that has exceeded its retention period.
You can request deletion of your data at any time through: Self-Service using the "Delete Account" feature in your Privacy Settings, or by submitting a Data Subject Request through our Contact page under "Privacy & Data Rights".
Deletion process: (1) Identity verification to prevent unauthorized deletion. (2) 7-day grace period to cancel accidental deletion requests. (3) Soft delete: data is marked for deletion and removed from active systems. (4) Hard delete: within 30 days, data is permanently removed from all systems including backups. (5) Confirmation sent once deletion is complete.
Certain data must be retained for legal compliance even after account deletion: financial transaction records (7 years for tax compliance), security incident logs related to your account, anonymized aggregate analytics data, and data required for ongoing legal proceedings.
Backup & Archive Practices
Backup schedule: Real-time replication of critical data to secondary systems. Daily full system backups every 24 hours. Weekly snapshots retained for disaster recovery. Daily backups retained for 30 days; weekly backups retained for 90 days; monthly backups retained for 1 year. When you delete your data it is removed from active systems immediately; backup copies are overwritten through the natural backup rotation cycle within 30-90 days.
Special Circumstances
Legal holds: If data is subject to a legal hold or ongoing investigation, retention periods may be extended until the legal matter is resolved. Enterprise customers may have customized retention periods as specified in their Data Processing Agreement. Some industries (healthcare, finance) may require extended retention periods.
Your Rights
Under GDPR and similar regulations you have the right to: access your data (request a copy of all personal data we hold), data portability (export your data in a machine-readable format), request correction of inaccurate information, request deletion of your personal data, restrict processing, and object to certain types of data processing. Submit requests via our Data Subject Request form or contact support@chaoscircle.ai.