Back to list
Annexes

ANNEX 6 – Data Retention and Deletion

Open print view
Version v1.5Last updated 17.08.2026Next review 01.10.2026Contractually binding

Owner: CTO · Approver: CEO

ANNEX 6 – Data Retention and Deletion

Retention Periods (unless law requires otherwise)

User accounts and profiles: contract period + 30 days

Content, drafts, and comments: retained for the contract period; no automatic deletion during the contract term (definable per customer)

Conversation history: contract period; Lyyli stores conversations to deliver the service (not covered by provider ZDR)

Version history: same as content

Meetings, recordings, and transcripts (Meeting Agent): contract period; deletion upon request

Images and attachments: same as content

Inbound email (Inbox): 12 months or customer-specific schedule

Security and audit logs: 180 days

Backups: 30 day rotation

Marketing and prospect data (no customer contract): 24 months or consent withdrawal

AI routes: language models under Zero Data Retention (the model provider does not retain the prompt/response after the request); Lyyli retains conversations as described in this annex. Details: AI model register.

Vendor-specific retention (subprocessors)

Supabase: 30 days post-termination [VARMENNETTAVA]

Clerk: max 90 days [VARMENNETTAVA]

Vercel AI Gateway / model providers: ZDR, no prompt/response retention after the request

Vercel: deletion within a commercially reasonable timeframe (Vercel DPA)

Resend: email data retained 30 days on all plans

Deletion

Customer content deleted from the active system is removed without undue delay. Backups are overwritten after the retention period. Deletion certificate upon request.

Version history