Effective
2026-05-03
Last verified
2026-07-17
Status
legal-review
Owner
Legal and Product

NetQnect Data Retention Schedule

Draft status: for legal review before publication.

Effective date: 2026-05-03

Contact: legal@netqnect.com

1. About This Schedule

This schedule sets target retention periods for NetQnect personal data. It must be aligned with the implemented deletion, export, backup, archive and processor controls before publication.

2. Retention Principles

NetQnect:

  • keeps personal data only for as long as needed;
  • minimises data used in logs, traces and analytics;
  • deletes or anonymises data when the purpose ends;
  • retains limited audit records where needed for security, legal, accounting or rights-request proof;
  • avoids retaining full personal-data archives after user deletion unless there is a documented lawful basis and expiry period.

3. Target Retention Periods

Account data

  • Active account lifetime.
  • Delete or anonymise within 30 days of account deletion, except limited records needed for legal, security or accounting reasons.

Profile data

  • Active profile lifetime.
  • Delete or anonymise within 30 days of profile or account deletion.

Connections, QR scans and Qnect activity

  • Active account lifetime.
  • Delete or anonymise within 30 days of account deletion, including nested notes, tasks, memory, opportunities and related subcollections.

User-to-user messages and conversation metadata

  • Active account lifetime while the conversation remains needed by at least one participant.
  • A user may archive their own conversation copy where the product supports it.
  • If a participant deletes their account or a connection is removed, disable new messages in the shared conversation and delete or anonymise the departing participant's personal data within 30 days of account deletion, while preserving the other participant's own messages where they still need their record.
  • Do not retain all app message content solely because separate support email, business, tax or accounting records may have longer legal retention. Limited security, abuse, dispute, rights-request, legal-hold and backup exceptions must be documented.

User media and uploaded files

  • Active account, profile, team, event or message lifetime, depending on the feature that uses the file.
  • Delete account-owned files under the user's account Storage area within 30 days of account deletion where practical.
  • Shared, team, event, imported-provider or organiser-controlled media may need deletion, anonymisation, reassignment, retention under another user's or organiser's lawful basis, or a documented exception.
  • NetQnect does not retain media solely because a file existed in technical storage; retention follows the feature purpose, legal/security exception or backup expiry rule.

Assistant messages and AI outputs

  • Active account lifetime unless the user deletes a thread earlier.
  • Delete or anonymise within 30 days of account deletion.

AI traces, debug logs and safety review records

  • Production target: 7 days unless retained for a live security, abuse, legal or support issue.
  • Staging and development target: 10 to 21 days, using redacted or test data where practical.

Embeddings, vector records and graph records

  • Active profile, event or relationship lifetime.
  • Delete or rebuild without the user's data within 30 days of profile, event or account deletion.

Event attendance and check-ins

  • Active account or event organiser need.
  • Delete or anonymise user-linked records within 30 days of account deletion, unless an organiser has an independent lawful basis to retain records.

Connected-service tokens

  • While the integration is connected.
  • Delete immediately on disconnect where practical, and within 24 hours as a service target.
  • Calendar OAuth tokens are stored as encrypted token envelopes while Google Calendar or Microsoft Calendar is connected. Disconnect deletes local token records and pending OAuth state immediately where practical; Google OAuth revocation is attempted when a revocable token is available. Provider-account access that remains outside NetQnect's control must be handled through the provider account settings or documented provider process.

Imported connected-service data

  • While needed for the connected feature.
  • Delete or refresh when the integration is disconnected, consent is withdrawn or the account is deleted.
  • Calendar availability checks must not import raw calendar history. Free/busy checks are requested only for bounded windows, defaulting to a maximum of 168 hours unless a narrower environment limit is configured, and the assistant-facing result is limited to provider id plus busy start/end windows. There is no calendar-specific application cache in the current source path; any persisted assistant trace that contains availability output follows the AI trace retention target above.
  • Calendar OAuth state records are short-lived, contain no token material, expire after 10 minutes, and are cleaned after callback, disconnect, account deletion or the scheduled expired-state cleanup.
  • Calendar connection metadata, capability preferences, write-back preferences and selected provider calendar id/label targets are retained only for the active connected-service/account purpose, then deleted or cleared on disconnect or account deletion. Calendar consent history follows the consent-history retention row.
  • NetQnect-created provider event references on assistant meetings are retained for the active meeting/account purpose. Successful write-back records the synced user id so export and erasure follow the user whose provider calendar received the event. Account deletion best-effort deletes the NetQnect-created provider event before local token deletion where token/capability access remains available, including stored-event cleanup if the write-back launch scope is later disabled; provider events that cannot be reached need controlled evidence or an approved provider-side exception.

Analytics and product usage data

  • Identifiable product analytics target: up to 14 months.
  • Aggregate or anonymised analytics may be kept longer if users are no longer identifiable.

Crash, performance and diagnostic data

  • Target: up to 90 days for identifiable records unless needed for a live incident.

Consent history

  • Active account lifetime plus up to 6 years after closure or deletion where needed to prove consent, withdrawal, policy version or rights handling.
  • Store minimal evidence, not full activity histories.

Billing, invoices and tax records

  • Up to 7 years where required for tax, accounting, chargeback, audit or legal obligations.

Support requests and contact forms

  • Up to 24 months after resolution unless needed for legal, security or customer relationship reasons.

Security logs and abuse records

  • Up to 12 months, or longer where needed for an investigation, legal claim or platform security.

Backups

  • Rolling backup retention target: up to 35 days.
  • Backups must be encrypted and must expire automatically within the rolling window above.

Marketing preferences and suppression records

  • Until withdrawn or replaced.
  • Suppression records may be retained to make sure users are not contacted again after opt-out.

4. Deletion Requirements

Account deletion covers:

  • Firebase Auth user records;
  • Firestore account, profile, connection, nested relationship and event data;
  • user-to-user message content and conversation metadata, using deletion, archive, read-only or anonymisation behavior appropriate to multi-party records;
  • assistant messages, actions, traces and token usage;
  • Firebase Storage media;
  • vectors and embeddings;
  • graph database records;
  • worker databases, queues and caches;
  • connected-service tokens and imported data;
  • analytics identifiers where deletion is supported by the provider.

5. Review

This schedule must be reviewed before launch and whenever retention behaviour changes.