Skip to content
AI Consulting & Implementation
  • AI in ActionIn Action
Discuss Your Business
Xpancom/Trust/Retention

Data retention and deletion

How long information stays, and how it leaves.

Retention is a published schedule, not a guess in a proposal. The same periods drive the deletion job. A legal hold pauses deletion. A signed statement of work may shorten a period; it may not silently extend one without notice.

Effective
15 September 2026
Updated
15 September 2026
Version
1.0
On this page01The schedule02Deletion, export, and holds03Classification

01 / Section

The schedule.

Xpancom retention schedule
Data classPeriodNotes
Marketing inquiries24 months after last meaningful contact30 days after a verified deletion request if no legal hold applies.
Intake drafts (never submitted)Link expiry plus 30 daysAnswers are deleted. Hashed link metadata is kept 12 months for abuse forensics.
Intake submitted, no engagement24 monthsDeleted or anonymized unless a legal hold or active discussion applies.
Intake and workspace records bound to an engagementLife of the engagement plus 7 yearsContract and tax retention. A statement of work may specify earlier deletion.
Auth accounts and access grantsLife of the grant plus 90 days after revokeInvitation-only. No public signup accounts exist.
Session network metadata (IP, user agent)90 daysScrubbed from session rows after 90 days. Sessions themselves expire with Better Auth.
Transactional email (SendGrid)Up to 24 months in provider logsMessage bodies are not kept in Neon. Do not put secrets in mail.
SMS one-time codes (Twilio)Better Auth verification expiry (minutes)Used only when SMS sign-in is enabled for an invited person.
Privacy and deletion requests7 yearsKept as evidence that the request was received and completed.
Security and incident evidence7 yearsAccess reviews, incident records, and restore-test records.
Operational security logs12 monthsHosting and application logs needed to operate the system.
BackupsRolling 30 daysNeon point-in-time recovery window. Deleted data may persist in backups until that window closes.
Workforce transition recordsEngagement plus 7 years, unless the workforce schedule says otherwisePurpose-limited. Not used for surveillance or automated employment decisions.

02 / Section

Deletion, export, and holds.

A client offboarding exports workspace records in a reasonable electronic form, then deletes them according to this schedule. Privacy requests are answered within 45 days, or sooner where a shorter statutory period applies. Legal holds override deletion until the hold is released.

Deleted rows may remain in the rolling backup window for up to 30 days. Intake draft answers are removed after the link expires plus 30 days; the hashed link metadata remains for 12 months so we can investigate abuse without reconstructing the URL.

Privacy PolicyEmail privacy@xpancom.com

03 / Section

Classification.

Intake free text and workspace documents default to Confidential. Restricted data is prohibited in Xpancom systems. If Restricted data is sent by mistake, we will delete it and notify the sender.

Public
Intended for the open web, such as this marketing site.
Internal
Xpancom operating information that is not published.
Confidential
Client and prospect information, including intake answers and workspace records. Default classification.
Restricted
Credentials, payment card data, protected health information, and raw employee files. Prohibited in Xpancom systems including intake free text.
Acceptable Use

AI consulting, implementation, and managed operations for established businesses.

Your AI operating partner.

AI services

All AI servicesAI Opportunity AssessmentAI Workflow ImplementationManaged AI Operations

People & trust

People and trustWorkforce ContinuityHuman authority and controlAI in action

Trust

Trust CenterSecuritySubprocessorsData retention

Company

About XpancomPerspectivesLegalDiscuss your business
© 2026 Xpancom, LLC. AI consulting, implementation, and managed operations.
LegalPrivacyTermsCookiesAccessibilityServices termsDPA