1. Principles
DIRI AI keeps identifiable data only while it is reasonably needed to provide the service, meet a legal obligation, protect accounts, prevent abuse or establish and defend claims. We minimise the data, restrict access, separate active data from legal records and delete or irreversibly anonymise it when the purpose ends.
An organisation may select a shorter supported retention period for its workspace. A longer period requires a documented purpose and legal basis. A workspace setting cannot shorten a statutory invoice retention period or override a legal hold.
2. Default schedule
| Data or record | Default maximum | Trigger and notes |
|---|---|---|
| Browser session | up to 8 hours | expires at configured session end; server revocation may occur earlier |
| Account profile and workspace membership | contract term plus up to 30 days | active copy deleted after closure/export window, except records below |
| Training transcript, scenario, score, report and session metadata | up to 365 days | earlier deletion where offered; organisation may choose a shorter supported period |
| Stored input recording | storage off by default; if expressly enabled, up to 30 days | must display recording state and shorter workspace setting before capture |
| Temporary voice rendering/quality artefact | up to 14 days | only where operationally required and access-restricted |
| User-prepared privacy/export archive | normally 24 hours after availability | signed link and stored object expire after the displayed availability period |
| Security and administrative audit log | normally 12 months | may be isolated longer for a documented incident, fraud case, legal hold or claim |
| Rate-limit/cache/queue state | seconds to operationally necessary short periods | no longer than required for delivery, security or retry |
| Transactional email outbox, delivery and webhook record | normally 90 days | message content minimised; complaint/legal evidence retained only as needed |
| Support request and consumer complaint | normally 3 years after closure | longer for an open claim or mandatory record; unnecessary attachments removed earlier |
| Trial-abuse prevention evidence | normally 3 years after trial end | provider tokens/signals minimised; never store a full card number |
| Payment, invoice, accounting and tax record | statutory period, potentially up to 10 years | stored separately from training content where possible |
| First-party application activity window | up to 35 days from the 15-minute UTC window start | HMAC tenant/user pseudonyms, allowlisted locale/device/source and bounded timing only; no raw identifier, IP address or content |
| First-party application analytics query audit | up to 90 days after the authorised query | HMAC administrator/query pseudonyms and bounded query facts; access restricted and no free text |
| Marketing consent proof other than the browser-only analytics choice | while relied on and normally 3 years after last reliance | minimal opt-out/suppression record may remain as long as necessary to honour the choice |
| Browser analytics consent choice | accepted: 365 days; rejected: 6 UTC calendar months | local browser storage only; invalidated by a material notice or provider-configuration change |
| Pre-consent sanitized campaign values | up to 30 minutes while the current page document remains loaded | volatile JavaScript memory only; no cookie, local storage or session storage; consumed on consent and cleared on refusal, GPC, withdrawal, invalid consent, reload or document replacement |
| Campaign closure marker | while the current page document remains loaded | volatile JavaScript memory only; contains no campaign value and prevents recapture during the same mounted document |
| GA4 first-party cookie identifiers | up to 365 days from first consent on the current host | not renewed on each page load; deletion attempted on withdrawal |
| GA4 user-level and event-level data | 2 months | the property uses this setting; reset on new activity is off |
| GA4 standard aggregated reports | not governed by Google's two-month user/event retention control | retained only while needed for the stated measurement purpose and deleted with the property/data when that purpose ends |
| Security incident and breach case | case life plus normally 5 years | scope adjusted to claim, authority and limitation-period needs |
These periods are maximum defaults, not guaranteed minimum availability. Product pages must not promise access for the entire retention period. Where a user deletes eligible content, the active copy should enter deletion promptly rather than waiting for the maximum.
The browser analytics record stores only the choice, timestamp, EN/CS notice locale, notice version and GA4 provider-configuration version. It is not joined to an account. The GA4 event payload is separately restricted to allowlisted public host/path/event data and bounded properties, without User-ID, account/customer identifiers, call content, transcripts, payment data, free text, query strings or URL fragments.
First-party application activity records are separate server-side operational analytics. They use independently keyed HMAC tenant and user pseudonyms, a 15-minute UTC window, bounded timestamps and allowlisted locale, device and source values. They contain no raw tenant or user identifier, name, email address, telephone number, IP address, user agent, precise location, URL, campaign value, Customer Content, call content, transcript, prompt, support message, payment data, free text or arbitrary metadata. They are not joined to GA4 identifiers or reports. HMAC pseudonyms remain personal data while DIRI AI can recompute them.
Google states that the Analytics retention control applies to user-level and event-level data and that expired data is deleted through a monthly process. Google also states that this control does not affect standard aggregated reports. DIRI AI therefore does not describe all Google Analytics data as deleted after two months. Aggregated reporting remains subject to the purpose-limitation rule in section 1 and must not be repurposed for advertising or individual profiling.
3. Account closure and subscription end
Cancellation normally leaves access through the paid period. After access ends, DIRI AI should provide the stated self-service or requested export opportunity and then begin active-system deletion. The active deletion target is 30 days after the applicable closure/export window, subject to identity verification, legal hold, security and mandatory records.
Payment failure or suspension alone does not immediately erase content. The customer must still have reasonable billing, cancellation, rights-request and export paths where possible.
Marketing analytics is not tied to a DIRI AI account and uses no Analytics User-ID. Closing an account therefore does not by itself identify a browser record in GA4. A visitor can withdraw in Cookie settings and clear browser storage; DIRI AI uses available Google deletion controls where a request can be matched without collecting additional identifiers.
First-party application activity is tied to an authenticated account only through short-lived HMAC pseudonyms. Activity HMAC key versions are retained for the 35-day activity-record lifetime; administrator/query HMAC key versions are retained for the full 90-day query-audit lifetime. For a verified access, export or approved deletion request, DIRI AI recomputes the relevant pseudonyms across every key version retained for the applicable lifetime, then exports or deletes matching activity and query-audit records subject to lawful exceptions. This process does not create a GA4 link.
4. Backups and provider copies
Deletion propagates to processors through documented lifecycle functions. Isolated encrypted backups may retain a copy until their normal verified expiration cycle. During that period the copy remains protected, is not searched or restored for ordinary business and will be deleted again if a disaster-recovery restoration occurs.
The applicable provider backup cycle is recorded in the Vendor and Transfer Register. Information about that cycle is available from privacy@diriai.com subject to security and confidentiality.
The configured Google Analytics property uses two-month user-level and event-level retention with reset on new activity off. Its deletion controls and account/property lifecycle apply alongside Google's processing terms, which state that supported deletion requests are completed as soon as reasonably practicable and within a maximum of 180 days unless applicable law requires storage. This contractual maximum does not replace the shorter two-month Analytics property setting where that setting applies.
5. Legal holds and exceptions
DIRI AI may suspend deletion of narrowly relevant data when reasonably necessary for a binding legal request, unresolved complaint, security incident, fraud investigation or establishment or defence of a claim. The hold must record scope, owner, reason, start and review date. Unrelated data continues through normal deletion. The hold ends when the need ends.
We may retain de-identified or aggregated information only where re-identification is not reasonably likely and controls prevent use to reconstruct a person or Customer Content. A Google Analytics standard report is not automatically treated as anonymous merely because it is aggregated.
6. Customer and user controls
Workspace administrators are responsible for selecting an appropriate supported retention setting and informing users. Individual users may delete supported content or request deletion, but an organisation's controller instructions and lawful records may govern organisation workspace data. Privacy requests go to privacy@diriai.com.
Visitors can reject or withdraw optional analytics through Cookie settings. Withdrawal stops future
Google Analytics collection, removes the tag, reloads a tag-free page and attempts to delete the
first-party _ga cookies from the current host. Browser or provider copies already created are
handled under the periods and controls above.
This optional GA4 choice does not control the first-party application records needed to provide, secure and maintain the service. Those records follow the separate 35-day activity and 90-day query audit limits above, legitimate-interest objection rights and verified access/export/deletion process.
7. Reviews and changes
DIRI AI tests expiry and deletion for database records, first-party application activity windows,
analytics query audits, object storage, cache/queue state, exports, email records, provider model
inputs where configurable and restored backups. GA4 uses one Analytics
property and one web stream for diriai.com and www.diriai.com, two-month user/event retention,
reset on new activity off, and disabled Enhanced Measurement, Google Signals, advertising features,
advertising personalisation, audiences, Google Ads links and User-ID. A material extension of a
public retention period requires a documented purpose, updated notice and, where required, a new
legal basis or consent.
Version: 1.2.0. Effective date: 30 August 2026.