Data Governance

Data Retention & Destruction Policy

This policy defines the exact data lifecycle rules governing how MarketMind AI stores, retains, and destroys customer data. It is designed to satisfy enterprise procurement requirements and align with SOC 2, GDPR, and CCPA data minimization principles.

Last updated: September 2026

1. Data Classification & Retention Periods

Customer Data & Vector Embeddings

Retained for the active term of the subscription. Upon termination, all tenant vector stores, database schemas, and associated records are permanently purged within 30 days.

Metadata & Index Records

Operational metadata (query logs, API call metadata, agent execution traces) is retained for 90 days for debugging and audit purposes, then automatically deleted.

Log Files

Application and infrastructure logs are retained for 90 days in Cloud Logging, with security-relevant audit logs retained for 365 days per SOC 2 requirements.

Cached Vectors & Inference Artifacts

Cached vector results and intermediate inference artifacts are transient — persisted only for the duration of the active request, with a maximum TTL of 24 hours for session-scoped caches.

2. Deletion & Destruction Procedures

Automated Termination Purge

Upon subscription termination or written request, an automated workflow initiates a complete data purge within 30 days. This includes all tenant databases, vector indexes, backups, and cached artifacts.

Backup Expiration

Encrypted backups are retained for 30 days following termination, after which they are automatically expired and overwritten. No backup survives beyond the 30-day post-termination window.

Hard-Drive / Cloud Storage Sanitization

All storage media sanitization follows NIST SP 800-88 Rev. 1 guidelines. Cloud storage deletion relies on GCP's cryptographic erasure — data is rendered cryptographically inaccessible upon key destruction.

3. Verification & Audit

Deletion Verification

Upon request, MarketMind AI provides a Certificate of Destruction confirming that all customer data has been purged in accordance with this policy and the executed DPA.

Audit Trail

All deletion events are logged in immutable Cloud Audit Logs, providing a verifiable chain of custody for the data destruction process.

4. Data Subject & Regulatory Requests

Expedited Deletion

Customers may request expedited deletion of specific data sets outside of the standard termination cycle. Requests are processed within 15 business days.

Regulatory Compliance

Retention periods may be extended where required by applicable law, regulation, or legal hold. Customers will be notified of any such extension.

This policy is provided for informational purposes and is incorporated by reference into the MarketMind AI Data Processing Addendum (DPA). In the event of any conflict with the executed DPA, the signed agreement controls.