Legal

Data Retention Policy

How long MKH Suite keeps each category of data, who can delete it, and how automated cleanup enforces these standards.

Version 1.0Effective July 7, 2026GDPR Article 5(e)
1

Overview

This policy defines retention periods for personal and business data on MKH Suite. Incorporated by reference into our Privacy Policy and Terms of Service.

Data minimization: We retain data only as long as necessary to provide the Service, meet legal obligations, or resolve disputes.
2

Account & Identity Data

Data typeRetentionDeletion triggerWho can delete
Name, email, profileAccount active + 30 daysAccount deletion requestUser (self)
Password hashAccount active + 30 daysAccount deletionAuto-purged
Profile photoUntil removed or deletedManual removalUser (self)
Session tokensUntil expiry or logoutSession endAuto-purged
Login metadata90 days rollingRolling auto-purgeAuto-purged
3

Billing & Financial Data

Billing records must be retained for 7 years. They cannot be deleted early, even on erasure request.
Data typeRetentionWho can delete
Invoices and receipts7 yearsCannot delete — legal requirement
Subscription history7 yearsCannot delete
Paddle transaction IDs7 yearsCannot delete
Payment method tokensUntil removed in Paddle portalUser (via billing portal)
Raw card numbersNever storedN/A
4

Workspace & CRM Data

Data typeRetentionWho can delete
Leads, deals, and clientsUntil deleted or workspace removalWorkspace owner
Emails and attachmentsUntil deleted or workspace removalWorkspace owner
Email events (opens, clicks, bounces)12 months rollingAuto-purged / user delete
AI agent configs and knowledge baseUntil deleted or account removalWorkspace owner
Projects and uploaded filesUntil deleted or workspace removalWorkspace owner
Booking pages and appointmentsUntil deleted or workspace removalWorkspace owner
5

Usage & Analytics Data

Data typeRetentionWho can delete
API and application logs12 monthsAuto-purged
Feature usage metrics12 months, then anonymizedAuto-purged
Aggregated analytics (no PII)IndefinitelyN/A
6

Security & Audit Data

Data typeRetentionWho can delete
Audit trail (workspace actions)24 monthsImmutable during retention
IP and request logs90 daysAuto-purged
Error and crash logs90 daysAuto-purged
Security incident records7 yearsOperator only
Spam/abuse investigation recordsInvestigation + 7 yearsOperator only
7

Communication Data

Data typeRetentionWho can delete
Support email correspondence3 yearsOperator only
In-app feedback2 yearsOperator only
8

Who Can Delete What

Tier 1 — Account owner

  • Own profile and preferences
  • Leads, deals, clients, projects, and files
  • Integration credentials
  • Own account (triggers deletion flow)

Tier 2 — Team members (Team plan)

  • Own profile data
  • Content they created, subject to owner policies
  • Cannot delete workspace or other members' data without owner permissions

Tier 3 — Operator

  • Process GDPR erasure requests
  • Apply legal holds on fraud or dispute investigations
  • Emergency deletion after confirmed breaches
9

Automated Deletion Jobs

Scheduled jobs enforce retention. Failures alert the infrastructure team.

JobFrequencyAction
purge-expired-sessionsHourlyRemove sessions past expiry
purge-error-logsDailyDelete error logs older than 90 days
purge-ip-logsDailyDelete IP logs older than 90 days
purge-email-eventsDailyDelete tracking events older than 12 months
purge-deleted-accountsDailyHard-delete accounts past 30-day grace
purge-usage-logsMonthlyDelete usage logs older than 12 months
anonymize-audit-logsMonthlyReplace PII in audit logs older than 12 months
10

Key Timeframes Summary

Immediately

Sessions revoked on deletion request

30 days

Grace period — deletion can be cancelled

Day 31

Hard deletion for eligible data

90 days

Technical and IP logs purged

12 months

Email events and usage logs purged

24 months

Audit logs anonymized, then purged

7 years

Billing records — legally required
11

Changes to This Policy

Material changes communicated via email or in-app notice. Previous versions available on request at privacy@mkhsuite.com.

12

Contact

Data retention questions

Deletion requests

Response time: within 30 days.

Related policies

MKH Suite is operated by Muhammad Kabir Hussain. These policies describe how we handle data for the platform at mkhsuite.com. For jurisdiction-specific legal advice, consult a qualified attorney.