Data Storage and Retention
This document describes how Aventora stores customer data and applies retention practices. For full policy requirements, see the Personal Data Privacy & Protection Policy and Data Classification and Handling Policy.
Storage components
| Component | Purpose | Protection |
|---|---|---|
| Relational database | Primary data store for accounts, engagements, and platform configuration | Access-controlled database access; encryption in transit and at rest via provider mechanisms |
| Application logs | Operational and security event records | Centralized log retention with controlled retention periods; access restricted to authorized personnel |
| Backups | Point-in-time recovery for production databases | Encrypted where supported; access limited to operations staff |
Data categories and retention
Retention periods depend on data type, product feature, deployment configuration, and contractual terms:
| Category | Typical retention driver |
|---|---|
| Engagement records (calls, SMS, email threads) | Customer agreement; operational requirements; customer-configured settings where available |
| Conversation content and transcripts | Contractual terms; feature enablement; customer deletion requests |
| Account and authentication data | Active account lifetime; legal and contractual obligations after closure |
| API keys and credentials | Active until revoked; metadata retained per operational policy |
| Security and application logs | Defined retention period for investigation and troubleshooting |
| Backups | Rotation cycles aligned with recovery objectives and contractual requirements |
Aventora retains personal information only for as long as reasonably necessary for the purposes described in the Privacy Notice.
Data protection at rest
| Control | Application |
|---|---|
| API credentials | Stored using industry-standard one-way cryptographic protection |
| Passwords | Stored using industry-standard one-way cryptographic protection |
| Secure access tokens | Protected using restricted storage and cryptographic controls before persistence |
| Encryption at rest | Provider-supported encryption for production database volumes and backups |
| Access control | Role-based access to production databases and backup stores |
Deletion and return
Upon contract termination or verified customer request, Aventora deletes or returns customer data in accordance with the applicable agreement, subject to:
- Technical feasibility and defined deletion procedures
- Secure backup expiry cycles (data in backups may persist until rotation completes)
- Legal retention obligations
Secure deletion methods are applied consistent with the Data Classification and Handling Policy.
Legal hold
Where litigation, investigation, or regulatory inquiry requires preservation of data, routine deletion is suspended for affected data sets upon direction by Aventora Security or Legal. Scope and duration are documented.
Customer responsibilities
Customers may configure retention settings within the platform where supported. Customers are responsible for:
- Defining retention requirements during contracting
- Submitting deletion requests for data under their control
- Classifying data they submit according to their own policies
Related documentation
- Data Classification and Handling Policy
- Personal Data Privacy & Protection Policy
- Business Continuity
- Privacy Notice
Changelog
| Date | Change |
|---|---|
| 2026-07-06 | Initial publication of data retention overview. |