Skip to content
DIRI AI

DIRI AI legal

DIRI AI Data Retention and Deletion Policy

Version 1.0.0Effective 26 August 2026Owner-approved English version

OWNER-APPROVED ENGLISH VERSION — EFFECTIVE 26 AUGUST 2026. Version 1.0.0. Independent Czech legal review is recommended but has not been obtained. This English document applies only where English satisfies applicable language requirements. Publication does not enable paid signup, Stripe Live, a blocked territory or an unverified product capability.

1. Principles

DIRI AI keeps identifiable data only while it is reasonably needed to provide the service, meet a legal obligation, protect accounts, prevent abuse or establish and defend claims. We minimise the data, restrict access, separate active data from legal records and delete or irreversibly anonymise it when the purpose ends.

An organisation may select a shorter supported retention period for its workspace. A longer period requires a documented purpose and legal basis. A workspace setting cannot shorten a statutory invoice retention period or override a legal hold.

2. Default schedule

Data or recordDefault maximumTrigger and notes
Browser sessionup to 8 hoursexpires at configured session end; server revocation may occur earlier
Account profile and workspace membershipcontract term plus up to 30 daysactive copy deleted after closure/export window, except records below
Training transcript, scenario, score, report and session metadataup to 365 daysearlier deletion where offered; organisation may choose a shorter supported period
Stored input recordingstorage off by default; if expressly enabled, up to 30 daysmust display recording state and shorter workspace setting before capture
Temporary voice rendering/quality artefactup to 14 daysonly where operationally required and access-restricted
User-prepared privacy/export archivenormally 24 hours after availabilitysigned link and object must expire; minimum/maximum implementation bounds require verification
Security and administrative audit lognormally 12 monthsmay be isolated longer for a documented incident, fraud case, legal hold or claim
Rate-limit/cache/queue stateseconds to operationally necessary short periodsno longer than required for delivery, security or retry
Transactional email outbox, delivery and webhook recordnormally 90 daysmessage content minimised; complaint/legal evidence retained only as needed
Support request and consumer complaintnormally 3 years after closurelonger for an open claim or mandatory record; unnecessary attachments removed earlier
Trial-abuse prevention evidencenormally 3 years after trial endprovider tokens/signals minimised; never store a full card number
Payment, invoice, accounting and tax recordstatutory period, potentially up to 10 yearsstored separately from training content where possible
Marketing consent proofwhile relied on and normally 3 years after last relianceminimal opt-out/suppression record may remain as long as necessary to honour the choice
Cookie consent choicepositive choice no more than 12 months; refusal normally not re-requested for at least 6 monthsshorter after material change or loss of browser storage
Security incident and breach casecase life plus normally 5 yearsscope adjusted to claim, authority and limitation-period needs

These periods are maximum defaults, not guaranteed minimum availability. Product pages must not promise access for the entire retention period. Where a user deletes eligible content, the active copy should enter deletion promptly rather than waiting for the maximum.

3. Account closure and subscription end

Cancellation normally leaves access through the paid period. After access ends, DIRI AI should provide the stated self-service or requested export opportunity and then begin active-system deletion. The active deletion target is 30 days after the applicable closure/export window, subject to identity verification, legal hold, security and mandatory records.

Payment failure or suspension alone does not immediately erase content. The customer must still have reasonable billing, cancellation, rights-request and export paths where possible.

4. Backups and provider copies

Deletion propagates to processors through documented lifecycle functions. Isolated encrypted backups may retain a copy until their normal verified expiration cycle. During that period the copy remains protected, is not searched or restored for ordinary business and will be deleted again if a disaster-recovery restoration occurs.

No exact backup-deletion deadline is promised until each active provider's configuration and contractual cycle are recorded in the Vendor and Transfer Register.

5. Legal holds and exceptions

DIRI AI may suspend deletion of narrowly relevant data when reasonably necessary for a binding legal request, unresolved complaint, security incident, fraud investigation or establishment or defence of a claim. The hold must record scope, owner, reason, start and review date. Unrelated data continues through normal deletion. The hold ends when the need ends.

We may retain de-identified or aggregated information only where re-identification is not reasonably likely and controls prevent use to reconstruct a person or Customer Content.

6. Customer and user controls

Workspace administrators are responsible for selecting an appropriate supported retention setting and informing users. Individual users may delete supported content or request deletion, but an organisation's controller instructions and lawful records may govern organisation workspace data. Privacy requests go to privacy@diriai.com.

7. Verification and changes

Paid activation remains disabled until tests prove expiry/deletion for database records, object storage, cache/queue state, exports, email records, provider model inputs where configurable and restored backups. A material extension of a public retention period requires a documented purpose, updated notice and, where required, a new legal basis or consent.

Effective version: 1.0.0. Effective date: 26 August 2026.

DIRI AI Data Retention and Deletion Policy | DIRI AI