Data Retention Policy

Understanding how long we keep your data and your rights to request deletion.

Last Updated: February 2026 | Version 1.2

Overview

Our principles for data retention.

WinIQ retains your data only for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. This policy outlines our retention periods for different types of data and your rights regarding data deletion.

Minimal
We keep only what's necessary
Transparent
Clear retention periods
Controllable
You can request deletion

Retention Schedule by Data Type

How long we keep different categories of data.

Data Category Examples Retention Period Basis
Account Data
Name, email, company, role, login credentials Account lifetime + 30 days Contract performance
Content Data
Proposals, documents, generated content, templates Account lifetime + 30 days Contract performance
AI Interaction Data
Prompts, AI responses, conversation history 90 days (rolling) Service improvement
Usage Analytics
Feature usage, page views, click data 26 months Legitimate interest
Billing Data
Invoices, payment records, transaction history 7 years Legal obligation
Audit Logs
Login events, security events, admin actions 2 years Security & compliance
Support Data
Support tickets, chat logs, feedback 3 years Service improvement
System Backups
Database backups, file system snapshots 30 days (rolling) Business continuity

AI Provider Data Retention

Zero retention at the AI processing layer.

Zero-Retention Agreements

All our AI providers operate under zero-retention agreements. Data sent to AI APIs is processed in real-time and immediately discarded. No prompts, responses, or user data is stored by our AI providers for any purpose including model training.

OAI OpenAI

API Data Retention: 0 days
Used for Training: No

A Anthropic

API Data Retention: 0 days
Used for Training: No

G Google Gemini

API Data Retention: 0 days
Used for Training: No

Az Azure OpenAI

API Data Retention: 0 days
Used for Training: No

For complete details, see our No Training Data Policy and Subprocessors List.

Account Deletion & Data Removal

Your rights and our deletion process.

When You Delete Your Account

1

Immediate Access Removal

Your account is immediately deactivated and access is revoked.

2

30-Day Grace Period

Data is held for 30 days in case you change your mind. Contact us to restore.

3

Permanent Deletion

After 30 days, all deletable data is permanently removed from primary systems.

4

Backup Removal

Data is purged from backups within 30 additional days (rolling backup cycle).

Data We Must Retain

Certain data must be retained for legal, tax, or security reasons even after account deletion:

Billing & Tax Records 7 years

Required by tax authorities in most jurisdictions

Security Audit Logs 2 years

For security incident investigation if needed

Anonymized Analytics Indefinite

Aggregated, non-identifiable usage statistics

Your Data Rights

Rights available to all users, with enhanced rights for EEA residents.

Right to Access

Request a copy of all personal data we hold about you. We'll provide it within 30 days in a machine-readable format.

Right to Rectification

Update or correct any inaccurate personal data. Most data can be updated directly in your account settings.

Right to Erasure

Request deletion of your personal data. We'll delete all data not required for legal compliance within 30 days.

Right to Portability

Export your data in a commonly used, machine-readable format (JSON, CSV) to transfer to another service.

Right to Restrict Processing

Request that we limit how we use your data while you contest its accuracy or our right to process it.

Right to Object

Object to processing based on legitimate interests or for direct marketing purposes.

How to Exercise Your Rights

Simple ways to make a data request.

In-App Settings

Export or delete your data directly from Account Settings → Privacy → Data Management

Email Request

Send your request to from your registered email address

Formal Request

Submit a formal DSAR (Data Subject Access Request) for comprehensive data reports

Response Time: We respond to all data requests within 30 days. For complex requests, we may extend this by up to 60 additional days with notice. Identity verification may be required.

Questions About Data Retention?

Our privacy team is here to help you understand how your data is handled and to assist with any data requests.

DPO:
Response within 30 days