Data Retention & Deletion Policy

 

1. Introduction

This Data Retention & Deletion Policy explains how Verumate (“Verumate”, “we”, “our”, or “us”) retains, deletes, and manages Customer Data, account information, Connected Services, OAuth credentials, and related information.

Our goal is to retain information only for as long as necessary to provide the Services, comply with legal obligations, maintain platform security, and support legitimate business operations.

This policy should be read together with our Privacy Policy and Terms of Service.


2. Our Retention Principles

Verumate follows these principles:

  • Customer Data belongs to the Customer.

  • We retain only the information necessary to provide the Services.

  • We minimize retained personal information wherever practical.

  • Customers remain in control of Connected Services.

  • OAuth credentials are removed when no longer required.

  • Secure deletion practices are applied where appropriate.


3. Account Information

Account information may include:

  • Name

  • Email address

  • Organization name

  • Account settings

  • Workspace configuration

  • Subscription information

Account information is retained while your account remains active.

Following account deletion, account information is deleted or anonymized unless retention is required to:

  • comply with applicable law;

  • resolve disputes;

  • prevent fraud or abuse; or

  • enforce legal agreements.


4. Connected Services

Customers may connect or disconnect Connected Services at any time.

When a Connected Service is disconnected:

  • Verumate immediately stops retrieving new information from that service.

  • Existing Customer Data previously retrieved remains subject to this policy.

  • OAuth credentials associated with the disconnected service are securely removed when no longer required for operational or recovery purposes.

Disconnecting a Connected Service does not automatically delete historical reports or analyses previously generated from Customer Data unless requested or required by applicable law.


5. OAuth Credentials

Where Connected Services support OAuth, Verumate stores OAuth credentials in encrypted form.

OAuth credentials are retained only while an active authorization exists.

OAuth credentials are securely removed when:

  • a Customer disconnects a Connected Service;

  • authorization is revoked;

  • an account is deleted; or

  • the credentials are no longer required to provide the Services.

Verumate never stores Connected Service passwords.


6. Customer Data

Customer Data is retained while required to provide the Services requested by the Customer.

Customer Data may include:

  • Business metrics

  • Analytics information

  • Advertising performance

  • Search performance

  • Reports

  • Uploaded datasets

  • API responses

  • Investigation results

Customers may request deletion of Customer Data, subject to applicable legal or contractual obligations.


7. AI Conversations and Reports

Conversation history, AI-generated responses, investigations, and reports may be retained to:

  • maintain Workspace history;

  • support collaboration;

  • improve continuity between sessions; and

  • provide requested functionality.

Customers may delete conversations or request account deletion in accordance with this policy.

Verumate does not use Customer Data or Google API Data contained within conversations to develop, improve, or train generalized artificial intelligence or machine learning models.


8. Logs and Security Records

To protect the Services, Verumate maintains operational and security logs.

These may include:

  • Authentication events

  • Error logs

  • Diagnostic information

  • Security events

  • Audit records

  • System performance information

Logs are retained only for operational, security, compliance, and troubleshooting purposes and are periodically deleted or anonymized according to our internal retention procedures.


9. Backups

Encrypted backups may contain Customer Data and system information.

Backups are maintained to support:

  • disaster recovery;

  • business continuity;

  • restoration following infrastructure failures; and

  • operational resilience.

Backups are retained only for a limited period and are securely overwritten or deleted according to Verumate’s backup lifecycle.

Where technically impractical, deleted information may remain within backup media until those backups naturally expire.

Backups are not used to restore information to an active Workspace except as required for disaster recovery.


10. Account Deletion

Customers may request deletion of their Verumate account.

Following a verified deletion request:

  • access to the Workspace is disabled;

  • Connected Services are disconnected;

  • OAuth credentials are removed;

  • Customer Data is scheduled for deletion;

  • personal information is deleted or anonymized unless retention is legally required.

Some information may remain temporarily within encrypted backups until those backups expire.


11. Legal Retention

Certain information may be retained beyond normal retention periods where necessary to:

  • comply with applicable law;

  • respond to lawful requests;

  • resolve disputes;

  • enforce agreements;

  • investigate fraud or security incidents; or

  • protect the rights, safety, or security of Verumate, its Customers, or others.

Such information will be retained only for as long as reasonably necessary for those purposes.


12. Secure Deletion

Where information is deleted, Verumate applies reasonable administrative and technical measures designed to securely remove or anonymize data from active systems.

Deletion processes may include:

  • removal from production databases;

  • deletion of encrypted credentials;

  • removal from application storage;

  • anonymization where deletion is not practical.

Residual copies may temporarily remain within encrypted backups until normal backup expiration.


13. Changes to This Policy

We may update this Data Retention & Deletion Policy from time to time to reflect changes in our Services, legal requirements, or operational practices.

Material changes will become effective after appropriate notice where required.

The “Last Updated” date at the top of this document reflects the most recent revision.


14. Contact

If you have questions regarding this Data Retention & Deletion Policy or wish to request deletion of your information, please contact:

Privacy Team

Email: privacy@verumate.com

For additional information regarding privacy, security, and data handling practices, please refer to our Privacy Policy and Trust documentation.