Legal
Data Retention Policy
How long MKH Suite keeps each category of data, who can delete it, and how automated cleanup enforces these standards.
Overview
This policy defines retention periods for personal and business data on MKH Suite. Incorporated by reference into our Privacy Policy and Terms of Service.
Account & Identity Data
| Data type | Retention | Deletion trigger | Who can delete |
|---|---|---|---|
| Name, email, profile | Account active + 30 days | Account deletion request | User (self) |
| Password hash | Account active + 30 days | Account deletion | Auto-purged |
| Profile photo | Until removed or deleted | Manual removal | User (self) |
| Session tokens | Until expiry or logout | Session end | Auto-purged |
| Login metadata | 90 days rolling | Rolling auto-purge | Auto-purged |
Billing & Financial Data
| Data type | Retention | Who can delete |
|---|---|---|
| Invoices and receipts | 7 years | Cannot delete — legal requirement |
| Subscription history | 7 years | Cannot delete |
| Paddle transaction IDs | 7 years | Cannot delete |
| Payment method tokens | Until removed in Paddle portal | User (via billing portal) |
| Raw card numbers | Never stored | N/A |
Workspace & CRM Data
| Data type | Retention | Who can delete |
|---|---|---|
| Leads, deals, and clients | Until deleted or workspace removal | Workspace owner |
| Emails and attachments | Until deleted or workspace removal | Workspace owner |
| Email events (opens, clicks, bounces) | 12 months rolling | Auto-purged / user delete |
| AI agent configs and knowledge base | Until deleted or account removal | Workspace owner |
| Projects and uploaded files | Until deleted or workspace removal | Workspace owner |
| Booking pages and appointments | Until deleted or workspace removal | Workspace owner |
Usage & Analytics Data
| Data type | Retention | Who can delete |
|---|---|---|
| API and application logs | 12 months | Auto-purged |
| Feature usage metrics | 12 months, then anonymized | Auto-purged |
| Aggregated analytics (no PII) | Indefinitely | N/A |
Security & Audit Data
| Data type | Retention | Who can delete |
|---|---|---|
| Audit trail (workspace actions) | 24 months | Immutable during retention |
| IP and request logs | 90 days | Auto-purged |
| Error and crash logs | 90 days | Auto-purged |
| Security incident records | 7 years | Operator only |
| Spam/abuse investigation records | Investigation + 7 years | Operator only |
Communication Data
| Data type | Retention | Who can delete |
|---|---|---|
| Support email correspondence | 3 years | Operator only |
| In-app feedback | 2 years | Operator only |
Who Can Delete What
Tier 1 — Account owner
- Own profile and preferences
- Leads, deals, clients, projects, and files
- Integration credentials
- Own account (triggers deletion flow)
Tier 2 — Team members (Team plan)
- Own profile data
- Content they created, subject to owner policies
- Cannot delete workspace or other members' data without owner permissions
Tier 3 — Operator
- Process GDPR erasure requests
- Apply legal holds on fraud or dispute investigations
- Emergency deletion after confirmed breaches
Automated Deletion Jobs
Scheduled jobs enforce retention. Failures alert the infrastructure team.
| Job | Frequency | Action |
|---|---|---|
| purge-expired-sessions | Hourly | Remove sessions past expiry |
| purge-error-logs | Daily | Delete error logs older than 90 days |
| purge-ip-logs | Daily | Delete IP logs older than 90 days |
| purge-email-events | Daily | Delete tracking events older than 12 months |
| purge-deleted-accounts | Daily | Hard-delete accounts past 30-day grace |
| purge-usage-logs | Monthly | Delete usage logs older than 12 months |
| anonymize-audit-logs | Monthly | Replace PII in audit logs older than 12 months |
Key Timeframes Summary
Immediately
30 days
Day 31
90 days
12 months
24 months
7 years
Changes to This Policy
Material changes communicated via email or in-app notice. Previous versions available on request at privacy@mkhsuite.com.
Contact
Data retention questions
Deletion requests
Response time: within 30 days.
Related policies
MKH Suite is operated by Muhammad Kabir Hussain. These policies describe how we handle data for the platform at mkhsuite.com. For jurisdiction-specific legal advice, consult a qualified attorney.