Data Retention & Deletion Policy
Effective 2026-08-31 · Version 1.0
1. Purpose of the Policy
The Data Retention & Deletion Policy (the "Policy") sets out the principles and rules followed by ZynReach, owned and operated by Zyntra Digital ("ZynReach," the "Company," "we," or "us") with respect to the retention, deletion, and secure destruction of data and information.
This Policy aims to ensure that:
- Data is retained for as long as necessary to achieve the legitimate purpose for which it was collected or processed.
- Personal data is not retained for longer than necessary, taking into account applicable legal and contractual requirements.
- Data is appropriately deleted or destroyed once there is no longer a legitimate need to retain it.
- Data is protected throughout the retention period.
- Legal, regulatory, and contractual obligations relating to retention are observed.
- ZynReach's ability to maintain business continuity and disaster recovery is preserved.
- Appropriate controls are applied to backups and technical logs.
- An appropriate balance is achieved between privacy, security, and operational and legal requirements.
2. Scope of Application
This Policy applies to data that ZynReach collects, stores, processes, or manages within:
This Policy does not necessarily apply to every type of data in the same manner, for the same duration, or through the same deletion mechanism.
- The ZynReach website.
- The ZynReach platform.
- Customer accounts.
- User accounts.
- Databases.
- Technical support systems.
- Communication systems.
- System logs.
- Security logs.
- Backups.
- Monitoring systems.
- Analytics systems.
- Account management and billing systems.
- Related internal systems.
- Third-party services that process data on behalf of ZynReach, as applicable.
3. Core Principles of Data Retention
ZynReach adheres to the following principles:
- Purpose Limitation — Data is not retained merely because it might be useful in the future, absent a legitimate and specific purpose.
- Data Minimization — ZynReach seeks to retain the minimum amount of data necessary to achieve the legitimate purpose of processing.
- Defining the Retention Period — The retention period is determined according to the nature of the data, its purpose, and applicable legal, contractual, and operational requirements.
- Security Throughout the Retention Period — Data remains subject to appropriate security controls throughout its retention period.
- Secure Deletion — When the retention period ends or there is no longer a legitimate need for the data, it is deleted, de-identified, or destroyed in accordance with appropriate procedures.
- Observance of Legal Obligations — ZynReach may be required to retain certain data for a longer period due to law, regulatory obligations, disputes, investigations, or accounting or contractual obligations.
4. Categories of Data
For retention management purposes, ZynReach may classify data into various categories, including:
- Account Data — such as: name, email address, account details, login data, organization data, and account settings data.
- Customer Data — data that the customer enters, uploads, stores, or processes through the ZynReach platform.
- Usage Data — such as: login records, service usage information, performance data, technical events, and device/browser information, as necessary and permitted.
- Security Logs — such as: Security Logs, Authentication Logs, Access Logs, Audit Events, and records of access attempts or security activity.
- Support Data — such as: support requests, correspondence, attachments, and technical issue status data.
- Billing Data — such as: subscription data, invoices, payment records, and information necessary to manage the business relationship.
- Website Data — such as: contact forms, trial requests, newsletter subscriptions (where applicable), and website interaction data in accordance with the Privacy Policy.
5. Data Retention Schedule
ZynReach uses a data retention framework based on the purpose of processing, the nature of the data, and applicable legal and contractual obligations. The following table represents the general framework:
Important: This table should not be interpreted as imposing a fixed retention period for all data in every case. The retention period may vary where required by the nature of the data, law, contract, security risk, or operational requirements.
- Customer account data — Account management and service delivery — For the duration of the account and the contractual relationship.
- Customer Data — Provision of services — For the duration of the service, in accordance with the DPA and the contract.
- User data — User and access management — For the duration of account activation, and thereafter in accordance with related obligations.
- Support data — Providing support and evidencing service — For as long as necessary for support, operational, and legal purposes.
- Security logs — Platform protection and incident investigation — In accordance with security, operational, and legal requirements.
- Audit Logs — Auditing, security, and accountability — In accordance with the nature of the log and applicable security and legal requirements.
- Billing data — Billing and accounting — In accordance with applicable legal and accounting requirements.
- Marketing data — Managing marketing communications — Until consent is withdrawn or the purpose ends, depending on the legal basis.
- Contact requests — Responding to inquiries — For as long as necessary to process the request and meet operational and legal needs.
- Backups — Recovery and business continuity — In accordance with the applicable backup cycle.
- Closed account data — Managing termination and obligations — For as long as necessary for legal and contractual obligations and the defense of legal rights.
6. Customer Data & Retention Responsibility
When ZynReach processes Customer Data on behalf of the customer in the capacity of a Processor, the customer remains responsible for determining the appropriate retention period for the data in its capacity as Controller, unless the contract or applicable law provides otherwise.
In accordance with the DPA, ZynReach:
- Processes data in accordance with the customer's instructions.
- Retains it for as long as necessary to provide the services.
- Applies deletion or return procedures upon termination of the relationship, in accordance with the DPA.
- Observes legal requirements that may necessitate retaining certain data.
- Manages backups in accordance with applicable operational controls.
7. End of Customer Subscription & Data Deletion
The end of a customer's subscription or the termination of services does not necessarily mean that all data is deleted immediately at that moment. ZynReach may require a transition period to carry out the following:
The procedures and timeframes specified in the DPA or the commercial agreement serve as the primary reference for Customer Data.
Where deletion of Customer Data is required, ZynReach seeks to delete the data from the relevant operational systems using appropriate technical procedures, which may include the following:
Immediate deletion from all backups may not always be possible due to the nature of backup systems.
- Closing the account.
- Disabling access.
- Processing export or retrieval requests, where available.
- Carrying out deletion operations.
- Removing data from operational systems.
- Handling backups.
- Fulfilling legal or contractual obligations.
- Deleting records from databases.
- Removing stored files.
- Deleting operational copies.
- Removing data from associated storage systems.
- Revoking access permissions.
- Deleting or destroying keys associated with the data, where this is part of the deletion mechanism.
8. Backups
ZynReach uses backups for purposes such as:
Some deleted data may remain present in backups for a limited period in accordance with the applicable backup retention cycle. During this period, the following controls apply:
- Business continuity.
- Disaster recovery.
- Service restoration.
- Protection against data loss.
- Addressing technical or security failures.
- Deleted data is not used for ordinary operational purposes.
- Access to it is restricted.
- Backups remain subject to appropriate security controls.
- It is disposed of or replaced in accordance with the applicable backup cycle.
9. Secure Deletion & Anonymization
ZynReach employs deletion or destruction methods appropriate to the nature of the medium and the data, which may include the following:
ZynReach is not required to use a single deletion method for all types of data or all storage systems.
Where appropriate, ZynReach may use Anonymization or De-identification instead of complete deletion, provided that the resulting data cannot be reasonably linked to an individual's identity under the applicable legal standard. Anonymized data may be used for purposes such as:
Fully anonymized data is not considered personal data where the conditions for the impossibility of re-identification are met under applicable law.
- Logical deletion.
- Deletion from databases.
- Removal of files.
- Destruction of storage media, where necessary.
- Use of encryption mechanisms or destruction of encryption keys, where appropriate.
- Secure device disposal procedures.
- Statistical analysis.
- Product improvement.
- Performance measurement.
- Research and development.
- Operational planning.
10. Legally Required Data & Legal Hold
ZynReach may retain certain data even after its operational purpose has ended where retention is required or permitted under:
In such cases, data is retained only to the extent and for the period necessary to achieve the legal or regulatory purpose.
Where there is a dispute, investigation, legal claim, or a reasonable likelihood of legal proceedings arising, ZynReach may suspend its ordinary deletion processes with respect to the relevant data. This action is known as a Legal Hold, and it may continue until:
Once the reason for retention ends, the data returns to the ordinary retention and deletion cycle.
- Applicable law or regulation.
- A court order.
- Accounting or tax requirements.
- Regulatory obligations.
- Anti-fraud requirements.
- Security requirements.
- Legal proceedings.
- An existing or reasonably anticipated dispute.
- The exercise or defense of legal rights.
- The dispute has ended.
- The investigation has ended.
- The legal need for the data has ended.
- Appropriate direction is issued to lift the legal hold.
11. Individual Deletion Requests
When an individual submits a request for the deletion of personal data, ZynReach evaluates the request in light of the following:
There may be cases in which complete deletion cannot be carried out, such as where retention is legally required. In such cases, processing is limited to what is necessary for the purpose that prevents deletion.
- The identity of the requester.
- The nature of the data.
- ZynReach's role in the processing.
- The legal basis for the processing.
- The applicable contract.
- Relevant laws.
12. Account Data & Inactive Accounts
When a user account is closed, ZynReach may:
ZynReach may apply measures to accounts that remain inactive for extended periods, depending on the type of service and its terms. These measures may include:
These measures are carried out in accordance with the applicable terms of service and contracts, taking into account any legal obligations.
- Disable the account.
- Remove the ability to log in.
- Process the data necessary to close the account.
- Delete data that is no longer necessary.
- Retain data that is legally required.
- Retain records necessary for security, fraud prevention, or the defense of legal rights.
- Send a notice to the user.
- Restrict certain functions.
- Suspend the account.
- Close the account.
- Delete or mask certain data.
13. Marketing Data & Correspondence
Marketing data is managed in accordance with the purpose and legal basis used for its collection. When a user withdraws consent to marketing communications, ZynReach stops sending communications that require that consent, taking into account the following:
ZynReach may retain limited information necessary to ensure that marketing communications are not resent to a person who has unsubscribed.
ZynReach may retain correspondence with customers or users for an appropriate period for various purposes, including:
The end of a conversation does not mean that the data associated with it is deleted immediately.
- Legal requirements.
- Suppression lists.
- Obligations relating to the management of opt-out requests.
- Customer service.
- Dispute resolution.
- Following up on requests.
- Improving support.
- Security.
- Legal obligations.
14. System, Security & Audit Logs
ZynReach may retain system and security logs for a period that differs from the retention period applicable to account data or Customer Data, for purposes such as:
These logs may be retained for a longer period where necessary to achieve a legitimate security or legal purpose.
Audit Logs may contain information regarding:
The retention period for these logs is determined based on:
- Detecting attacks.
- Investigating incidents.
- Preventing misuse.
- Analyzing suspicious activity.
- Auditing access.
- Protecting the platform.
- Business continuity.
- Logins.
- Permission changes.
- Account settings changes.
- Administrative actions.
- Security events.
- Sensitive operations.
- Security risk.
- Operational need.
- Contractual requirements.
- Legal requirements.
15. Sub-processors & Independent Third Parties
When ZynReach uses Sub-processors or external service providers, the Company seeks to impose appropriate requirements regarding:
These relationships are also subject to the Sub-processor Policy, the DPA, and related agreements.
Where a third party processes data as an independent Controller, rather than as a Processor or Sub-processor acting on behalf of ZynReach, the retention of data by that party may be governed by its own privacy and retention policy. ZynReach is not responsible for retention periods determined by an independent Controller outside its legal or contractual control.
- Retention.
- Deletion.
- Data protection.
- Confidentiality.
- Return of data.
- Disposal of data at the end of the service.
16. Data Lifecycle & Classification
ZynReach follows the concept of a data lifecycle: Collection → Processing → Active Storage → Archiving / Restricted Storage → Deletion / Anonymization.
Not all types of data pass through every stage; the data's path is determined according to its nature, purpose, risk, and legal obligations.
ZynReach may classify data according to its sensitivity and protection requirements. Examples of classifications include:
The classification level may affect:
- Public.
- Internal.
- Confidential.
- Restricted.
- Retention period.
- Access permissions.
- Encryption requirements.
- Logging and monitoring requirements.
- Deletion mechanism.
17. Minimum Retention & Periodic Review
ZynReach seeks not to retain personal data for longer than necessary to achieve the purpose for which it was collected or processed.
However, "minimum" does not necessarily mean the shortest possible period of time, as the following factors may require a longer retention period:
ZynReach may review retention periods from time to time to confirm that the need for them continues. Such review may take place upon:
This does not mean that all categories of data will be reviewed at the same time.
- Laws.
- Contracts.
- Security.
- Accounting.
- Fraud prevention.
- Legal defense.
- Business continuity.
- A change to the product.
- A change in the way data is processed.
- The introduction of a new system.
- A change in legal requirements.
- The occurrence of a security incident.
- A change of service provider.
- The purpose of the data ending.
18. Internal Access & Termination of Access
Employees and internal users who have access to ZynReach data must observe the following:
When an employee's or contractor's access to ZynReach systems ends, access permissions are revoked or modified in accordance with identity and access management procedures.
The cancellation of an account or permission does not necessarily mean that records created by that user are deleted, as there may be a need to retain them for purposes of:
- Using data only for authorized business purposes.
- Not retaining unnecessary copies.
- Not transferring data to unauthorized systems.
- Following internal deletion procedures.
- Protecting data during the retention period.
- Reporting any unauthorized loss or disclosure.
- Auditing.
- Security.
- Investigation.
- Compliance.
- Historical records.
19. Temporary & Cached Data, and Technical Logs
Temporary or cached data may be generated during the operation of the services. This data may be automatically deleted or overwritten depending on the technical systems used. Temporary data is not necessarily considered part of permanent Customer Data unless the contract or system provides otherwise.
System logs may contain identifiers or technical information associated with users or accounts. This information is used, when necessary, for purposes of:
It is retained in accordance with the retention cycle appropriate to each system.
- Operations.
- Security.
- Diagnostics.
- Performance.
- Investigating failures.
20. Multi-Phase Deletion at Service Termination & Exceptions
When services are terminated, ZynReach may carry out a multi-phase deletion process, as follows:
Deletion may be suspended or delayed where necessary due to any of the following:
This exception must not be used as a means of retaining data indefinitely without justification.
- Phase One — Disabling access to the account.
- Phase Two — Making available a data export or retrieval mechanism, if available under the contract and service.
- Phase Three — Removing data from operational systems in accordance with the DPA and the contract.
- Phase Four — Allowing the backup cycle containing the data to run its course.
- Phase Five — Handling any data that must be retained by law.
- Phase Six — Closing the data lifecycle.
- A legal obligation.
- A court order.
- An official investigation.
- A dispute.
- A Legal Hold.
- Security requirements.
- Fraud prevention.
- Business continuity.
- Restoration of data from backups.
- Any other legitimate reason permitted by law.
21. Technical Limitations & No Guarantee of Immediate Deletion
ZynReach acknowledges that complete and immediate deletion from all technical systems may not always be possible, particularly in distributed environments or backup and caching systems.
Accordingly, deletion may be carried out on a reasonable technical cycle rather than immediately from every technical layer.
Unless the DPA, applicable law, or an agreement provides otherwise, ZynReach does not guarantee that data deletion will occur at the exact moment a deletion request is submitted.
Deletion is carried out through appropriate technical and operational processes and in a manner consistent with legal and contractual obligations.
22. Proof of Deletion & Customer Requests
Where appropriate or required under a contract, ZynReach may document the deletion process or maintain an internal record evidencing that the action was carried out.
ZynReach is not obligated to issue a separate certificate of deletion for each deletion action unless the contract or applicable law so requires.
Customers may request information or clarification regarding retention and deletion procedures through ZynReach's official channels. The customer may be asked to provide the following:
- Company name.
- Account details.
- The service concerned.
- The data or accounts that are the subject of the request.
- The nature of the request.
- Any information necessary to verify authorization.
23. Relationship to Other Policies
This Policy is to be read in conjunction with the Data Processing Agreement (DPA). In the event of any conflict between this Policy and the DPA, the provisions of the DPA shall govern with respect to Customer Data. In particular, any period or procedure specified in the DPA regarding the following prevails over the general framework set out in this Policy:
ZynReach's Privacy Policy sets out how personal data is collected, used, and disclosed in respect of processing carried out by ZynReach as Controller. This Policy, by contrast, focuses primarily on the data lifecycle and retention and deletion periods. Both documents should be read together.
Data remains subject, throughout the retention period, to the security controls set out in ZynReach's security framework, which may include the following:
- Return of data.
- Deletion of data.
- Retention.
- Backups.
- Termination of service.
- Access control.
- Authentication.
- Encryption.
- Logging.
- Monitoring.
- Vulnerability management.
- Backup.
- Incident response.
24. Compliance & Changes to This Policy
ZynReach seeks to design its retention and deletion processes in a manner consistent with applicable data protection and privacy laws relevant to the processing concerned.
This Policy does not imply that all legal requirements in every country apply to every customer or every type of data.
Relevant legal requirements are determined according to the applicable jurisdiction, the nature of the service, and the role of the parties.
ZynReach may amend this Policy from time to time to reflect:
The updated version is published through the appropriate channels.
- Legal developments.
- Technical changes.
- Changes to services.
- Updates to security procedures.
- Changes to the data lifecycle.
- Customer or market requirements.
- Operational improvements.
25. Order of Precedence & Contact
No provision of this Policy should be interpreted as:
In the event of a conflict between this Policy and any of the following documents, the higher-priority document applies according to the nature of the matter and the contractual relationship, in the following order:
For inquiries relating to the retention and deletion policy, ZynReach may be contacted through the official communication channels published at zynreach.com. The request should preferably include the following:
- A guarantee that all data will be deleted immediately.
- An obligation to retain all types of data for a fixed period.
- A waiver of any legal right.
- An implied amendment to any contract.
- The creation of an independent contractual right not set out in the agreement.
- An obligation to remove data where its retention is legally required.
- Mandatory applicable law.
- The written and signed agreement with the customer.
- The Data Processing Agreement.
- The Terms of Service / Master Services Agreement.
- This Policy.
- The customer's or user's name.
- The email address associated with the account.
- The type of data that is the subject of the request.
- The nature of the request.
- Any additional information necessary for verification and processing.
26. Legal Notice
The following table sets out the document control record for this policy:
This document represents ZynReach's general framework for managing the data lifecycle and its retention and deletion. This Policy does not, in itself, constitute an independent legal obligation beyond what is imposed by applicable laws or agreements entered into with customers.
Actual retention periods and procedures may vary depending on the following:
ZynReach reserves the right to retain information where necessary or legally required, while taking appropriate measures to limit access to and use of such information.
© 2026 Zyntra Digital. All Rights Reserved.
- Document name — Data Retention & Deletion Policy.
- Company — Zyntra Digital.
- Platform — ZynReach.
- Website — zynreach.com.
- Version — 1.0.
- Effective date — August 31, 2026.
- Classification — Public / Legal / Compliance.
- Owner — Privacy / Legal / Security.
- Review — Periodically or upon a material change.
- Related documents — Privacy Policy / DPA / Security & Trust Policy / Sub-processor Policy / Terms of Service.
- Type of data.
- Purpose of processing.
- Nature of the service.
- ZynReach's role in the processing.
- Customer requirements.
- Applicable law.
- Contractual obligations.
- Security and operational requirements.
For privacy-related requests, contact us at privacy@zynreach.com.