Legal
Data Deletion Policy
Last updated: June 13, 2026
1. Overview
This Data Deletion Policy explains how Recentriq LLC (“Recentriq,” “we,” “us,” or “our”) handles requests for deletion of personal and business data from our platform. We are committed to providing clear, accessible mechanisms for users to exercise their right to data deletion in compliance with GDPR, CCPA, and other applicable privacy regulations.
This policy applies to all data stored within the Recentriq platform, including account information, business data, communication records, uploaded files, and automatically collected data.
2. How to Request Data Deletion
You may request deletion of your data through any of the following methods:
2.1 Account Self-Service
Account owners and administrators can delete their organization's data directly within the platform by navigating to Settings → Organization → Delete Account. This initiates the automated deletion workflow described in Section 3.
2.2 Email Request
Send a data deletion request to [email protected] with the subject line “Data Deletion Request.” Please include:
- Your full name and registered email address
- Your organization/company name (if applicable)
- The specific data you wish to have deleted (account data, specific records, or complete tenant deletion)
- Any relevant context to help us locate your data
2.3 Written Request
You may also submit a written request via mail. Contact us at [email protected] for our current mailing address.
3. Deletion Process & Timeline
Upon receiving and verifying your deletion request, the following process applies:
Phase 1: Request Verification (1–3 business days)
We verify your identity and authority to request deletion. For tenant-wide deletions, we confirm you are an authorized account administrator. You will receive a confirmation email once verification is complete.
Phase 2: Soft Deletion (within 7 business days)
Your data is rendered inaccessible through the platform. All active database records in your tenant schema are flagged for deletion. API access to the deleted data is revoked. At this stage, data can still be recovered upon request within the grace period.
Phase 3: Hard Deletion (30 days after soft deletion)
Data is permanently erased from our active database systems. This includes all tenant-scoped data: employee records, client information, financial transactions, communications, documents, and configurations. This deletion is irreversible.
Phase 4: Backup Purging (up to 90 days after hard deletion)
Encrypted database backups are rotated on a 90-day cycle. Data in backups is automatically purged as part of our standard backup rotation. No manual intervention is required for backup deletion.
4. What Data Is Deleted
A complete deletion request covers the following categories of data:
- Account Data: Email, password hash, profile information, session tokens, and authentication records from the public schema.
- Business Data: All records within your tenant schema including employees, clients, leads, orders, projects, tasks, invoices, expenses, journal entries, accounts, inventory, purchasing records, and related metadata.
- Communications: Chat messages, meeting records, email metadata, and inbox conversations.
- Files & Documents: Uploaded files in cloud storage (R2) or local filesystem, including documents, templates, profile images, and attachments.
- Configuration: Tenant settings, role definitions, SMTP configurations, module preferences, and custom fields.
- Audit Logs: Activity logs associated with your account and tenant.
5. Data Excluded from Immediate Deletion
Certain data may be retained beyond the standard deletion timeline in the following circumstances:
- Legal Obligations: Data required to be retained by applicable law, regulation, or legal process (e.g., tax records, financial transaction logs for completed transactions).
- Dispute Resolution: Data reasonably necessary for the establishment, exercise, or defense of legal claims.
- Fraud Prevention: Data necessary to detect, prevent, or investigate fraud, security incidents, or Terms of Service violations.
- Aggregated/Anonymized Data: Data that has been aggregated or anonymized such that it can no longer be associated with an identified individual or organization.
Any data retained under these exceptions is kept only for as long as necessary to fulfill the specified purpose and is subject to the same security protections as active data.
6. Third-Party Data
When we delete your data from our systems, we also instruct our sub-processors and service providers to delete your data from their systems within a reasonable timeframe:
- Cloud Storage (R2): Files and attachments are permanently deleted within 7 days of hard deletion.
- Email Services: Email logs and metadata are deleted in accordance with our provider's data processing agreements.
- Payment Processor (Stripe): You may need to separately request data deletion from Stripe if you provided payment information directly through their interface.
- Analytics: Google Analytics and Meta Pixel data is subject to those platforms' respective data retention settings. We recommend reviewing their policies for complete deletion.
7. Data Export Before Deletion
We recommend exporting your data before requesting deletion. You can export your data through the platform (Settings → Data Export) or request a data export by contacting our support team. Data exports are provided in structured formats (CSV, JSON) within 7 business days. No export fee is charged for data exports requested as part of a deletion request.
8. Confirmation of Deletion
Upon completion of each phase of the deletion process, you will receive email notifications confirming:
- Verification of your deletion request (Phase 1)
- Completion of soft deletion and start of the 30-day grace period (Phase 2)
- Completion of permanent deletion (Phase 3)
9. Canceling a Deletion Request
You may cancel a deletion request at any time during the 30-day grace period (between Phase 2 and Phase 3) by contacting us at [email protected]. Once hard deletion (Phase 3) has been initiated, cancellation is no longer possible.
10. Compliance with Platform Policies
For data deletion requirements imposed by third-party platforms (e.g., Meta/Facebook, Google), we follow the data deletion callbacks and requirements specified by those platforms. If you are directed here by a third-party platform's deletion requirements, the email request method in Section 2.2 is the appropriate channel.
11. Contact
For questions about this Data Deletion Policy or to check the status of a deletion request: