Data Retention & Deletion Policy

Chaos Circle is committed to responsible data management. This policy outlines how long we retain different types of data, our deletion procedures, and your rights regarding data retention. We comply with GDPR, CCPA, and other applicable data protection regulations. Our data retention practices are designed to balance operational needs with privacy requirements, ensuring we keep data only as long as necessary for the purposes for which it was collected.

Data Retention Periods

Data CategoryRetention PeriodJustification
Account InformationDuration of account + 30 daysRequired for service delivery and account recovery
Chaos Circle AssessmentsDuration of account + 90 daysHistorical analysis and trend tracking
Team Member DataDuration of account + 30 daysOrganizational management features
AI Conversation History90 daysService improvement and context continuity
Audit Logs2 yearsSecurity compliance and incident investigation
Billing & Transaction Records7 yearsLegal and tax compliance requirements
Contact Form Submissions2 yearsCustomer support and dispute resolution
Data Subject Requests3 yearsRegulatory compliance documentation
Security Incident Logs5 yearsSecurity analysis and regulatory requirements
Session & Authentication Data30 days after session endSecurity monitoring and fraud prevention

Deletion Procedures

Data is automatically deleted according to the retention schedules above. Our automated systems run daily to identify and securely delete data that has exceeded its retention period.

You can request deletion of your data at any time through: Self-Service using the "Delete Account" feature in your Privacy Settings, or by submitting a Data Subject Request through our Contact page under "Privacy & Data Rights".

Deletion process: (1) Identity verification to prevent unauthorized deletion. (2) 7-day grace period to cancel accidental deletion requests. (3) Soft delete: data is marked for deletion and removed from active systems. (4) Hard delete: within 30 days, data is permanently removed from all systems including backups. (5) Confirmation sent once deletion is complete.

Certain data must be retained for legal compliance even after account deletion: financial transaction records (7 years for tax compliance), security incident logs related to your account, anonymized aggregate analytics data, and data required for ongoing legal proceedings.

Backup & Archive Practices

Backup schedule: Real-time replication of critical data to secondary systems. Daily full system backups every 24 hours. Weekly snapshots retained for disaster recovery. Daily backups retained for 30 days; weekly backups retained for 90 days; monthly backups retained for 1 year. When you delete your data it is removed from active systems immediately; backup copies are overwritten through the natural backup rotation cycle within 30-90 days.

Special Circumstances

Legal holds: If data is subject to a legal hold or ongoing investigation, retention periods may be extended until the legal matter is resolved. Enterprise customers may have customized retention periods as specified in their Data Processing Agreement. Some industries (healthcare, finance) may require extended retention periods.

Your Rights

Under GDPR and similar regulations you have the right to: access your data (request a copy of all personal data we hold), data portability (export your data in a machine-readable format), request correction of inaccurate information, request deletion of your personal data, restrict processing, and object to certain types of data processing. Submit requests via our Data Subject Request form or contact support@chaoscircle.ai.

Privacy Policy | Data Processing Agreement | Data Subject Request