Data Retention Policy
Data Retention — Key Points (Plain English)
This summary covers the most important retention rules. Please read the full policy below for complete detail.
- Your Account data is kept while your Account is active and deleted within 30 days after Account closure.
- Your Recipients (Contacts) are processed data. They are deleted with your Workspace or Account, subject to a 30-day grace period for recovery.
- Unsubscribe records (Suppression Lists) are kept indefinitely because deleting them would cause re-sending to people who asked to stop receiving emails.
- Legal request records are kept longer (up to 3 years) for regulatory compliance and dispute resolution purposes.
- Security logs are rolled over every 90 days except where CERT-In directions require longer retention for qualifying incidents.
- You can request deletion of your personal data at any time via /privacy-requests. Deletion takes place within 30 days of verification.
1. Introduction & Principles
1.1 Purpose. This Data Retention Policy ("Retention Policy") describes how long Mailxify retains different categories of data, the reasons for which specific retention periods are applied, the conditions under which data is deleted, and the exceptions that apply to standard retention periods. This Policy is incorporated into and forms part of the Privacy Policy and the Terms of Service.
1.2 Core Principles. Mailxify's retention practices are guided by the following principles:
- Purpose Limitation: Data is retained only for as long as it is necessary for the specific purpose for which it was collected, as required by Applicable Law, or to establish, exercise, or defend legal claims;
- Data Minimisation: Mailxify does not retain data beyond the applicable retention period simply because storage is inexpensive or technically convenient;
- Accuracy: Mailxify will delete data that is no longer accurate, relevant, or necessary for its stated purpose, and will respond to correction requests that affect ongoing retention decisions;
- Security during Retention: During the retention period, data is protected by the technical and organizational security measures described in the Security Policy; and
- Lawful Basis for Retention: Where continued retention of data is required beyond the User's deletion request, Mailxify identifies and documents the specific legal basis for continued retention.
1.3 Applicable Law. Retention periods in this Policy are designed to comply with, inter alia, the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011, and the CERT-In directions issued thereunder, to the extent applicable.
2. Retention Roles
2.1 Data Mailxify Retains as Controller (Data Fiduciary). Mailxify retains Account data, session data, legal request records, and system logs as the Data Fiduciary in its own right. The retention rules for this data are set by Mailxify in this Policy and implemented by Mailxify's systems. Users exercise their rights in respect of this data by contacting Mailxify directly.
2.2 Data Mailxify Retains as Processor. Mailxify retains Recipient (Contact) data in its database as a Data Processor, acting on the Controller's (User's) instructions. The User, as Controller, determines the purpose and duration of retention for this data. Mailxify's retention of Recipient data is bounded by: (a) the User's own data management decisions (e.g., deleting a Contact or Workspace); and (b) the term of the Agreement. Mailxify will delete Recipient data after Account closure as specified in Section 4. This distinction between Controller and Processor retention roles is important for understanding which party is accountable for specific data retention decisions.
2.3 Suppression Records — Joint Interest. Suppression list records (opt-out records) serve both the User's compliance needs and Mailxify's own obligation to prevent continued sending to suppressed addresses. Mailxify maintains suppression records for the duration of the relevant Workspace, even if the User deletes individual Contact records, because deletion of opt-out records could result in Mailxify's systems sending further emails to people who have opted out.
3. Customer Content (User Data)
3.1 Account Registration Data
| Data | Retention Trigger | Retention Period | Deletion Condition |
|---|---|---|---|
| Full name | Account creation | Duration of Account + 30-day grace period | Account closure or confirmed deletion request |
| Email address | Account creation | Duration of Account + 30-day grace period | Account closure or confirmed deletion request |
| Password hash | Account creation | Duration of Account | Account closure |
| Account role assignment | Account creation | Duration of Account | Account closure |
3.2 Reason for 30-Day Grace Period. The 30-day post-closure grace period exists to allow Users who close their Account inadvertently or who change their mind shortly after closure to recover their Account without permanent data loss. After 30 days, deletion is permanent and irreversible.
3.3 Workspace Data
| Data | Retention Period | Deletion Condition |
|---|---|---|
| Workspace record (name, ID, settings) | Duration of Account + 30-day grace | Account closure or explicit Workspace deletion |
| Workspace membership records | Duration of membership or Workspace | Member removal or Workspace deletion |
| Campaign templates | Duration of Workspace | Workspace deletion |
3.4 Legal Acceptance Records
Legal acceptance records (the record that you accepted a specific version of the Terms of Service and Privacy Policy at a specific date and time) are retained for the longer of:
- The duration of your Account plus the applicable limitation period under Indian law for contractual claims (currently three (3) years under the Limitation Act, 1963 for simple contracts); or
- Such longer period as may be required by Applicable Law.
The basis for this retention is the legal and regulatory requirement to maintain evidence of informed consent. These records may be required in the event of a legal challenge to the enforceability of the Terms or a data processing dispute.
4. Recipient (Contact) Data
| Data Category | Retention Trigger | Retention Period | Deletion Condition | Exception |
|---|---|---|---|---|
| Contact records (name, email, company, custom fields) | Upload to Workspace | Duration of Workspace + 30-day grace post-Account-closure | User deletes Contact; User deletes Workspace; Account closure | Suppression status remains even after Contact record deletion (see Section 5) |
4.1 User-Controlled Deletion. Within the Service, Users can delete individual Contact records from their Workspace at any time. Deleted Contact records are permanently removed from the Mailxify database.
4.2 No Retention Beyond Workspace Lifecycle. Mailxify does not retain Contact data after a Workspace has been deleted and the 30-day post-closure grace period has expired. Mailxify has no business basis for retaining Recipient data beyond the term of the Agreement.
4.3 Impact of Deletion on Campaigns. If a Contact record is deleted while a Campaign is in progress, the deletion will prevent further Messages from being sent to that Recipient. Already-transmitted Messages cannot be recalled.
5. Suppression Records (Opt-Out / Unsubscribe)
5.1 Indefinite Retention by Default. Suppression list records — records of email addresses for which further Campaign sending has been prohibited as a result of an unsubscribe request, spam complaint, or hard bounce — are retained indefinitely by default. This is not an arbitrary decision; it reflects the operational and legal importance of suppression records:
- Deleting a suppression record would cause that email address to be treated as an unsuppressed Recipient, potentially resulting in further Messages being sent to a person who has explicitly requested to stop receiving them;
- Under this ASP and applicable consumer protection law, re-contacting a person who has unsubscribed is prohibited; and
- Indefinite retention of suppression records is industry standard practice.
5.2 User Override. A User (Workspace Owner) may remove an email address from the Suppression List if they have verifiable evidence that the Recipient has affirmatively re-consented to further communications. The User assumes full responsibility for the lawfulness of re-enabling a previously suppressed address.
5.3 Suppression Data Content. Suppression records contain only the email address, the date of suppression, and the reason (e.g., "unsubscribe", "hard bounce", "complaint"). They do not contain Campaign content, message bodies, or other personal data beyond the email address.
5.4 Post-Account-Closure. Suppression records associated with a closed Account are retained for a period sufficient to prevent resumed sending in the event the Account is re-opened, and then deleted. After permanent Account deletion, suppression records associated with that Account are also deleted.
6. Legal, Grievance & Compliance Records
| Record Type | Retention Period | Reason |
|---|---|---|
| Grievance submissions | 3 years from resolution | SPDI Rules grievance record requirements; potential regulatory review |
| Privacy request submissions (access, correction, erasure) | 3 years from resolution | Evidence of DPDPA compliance; limitation period for contractual claims |
| Abuse reports received | 3 years from resolution | Evidence of enforcement activity; potential legal dispute record |
| Legal request submissions from Users | 3 years from resolution | Dispute resolution; legal obligation compliance evidence |
| Court orders, regulatory demands | As required by the specific order or applicable law | Legal obligation — duration determined by the order or applicable statute |
6.1 CERT-In Specific Note. CERT-In directions (Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013, as amended) require that qualifying body corporates retain certain ICT-related logs for a period of 180 days and report qualifying incidents to CERT-In. These obligations apply to qualifying security incidents and ICT infrastructure logs. They do not extend to customer-generated content (e.g., Campaign templates, Recipient contact lists) or to general correspondence unrelated to cybersecurity incidents. Mailxify does not use CERT-In as a justification for retaining Customer Content beyond the periods specified in Sections 3 and 4 of this Policy.
7. Billing & Transaction Records
7.1 Current Status. Commercial billing is not currently active. No payment records, invoice data, or transaction records are currently held by Mailxify.
7.2 Future Retention (When Billing is Activated). When commercial billing is activated, billing and transaction records will be retained for:
- The longer of eight (8) years from the date of the transaction, or such other period as may be required by applicable tax law (e.g., the period prescribed for maintenance of books of accounts under the Companies Act, 2013, or applicable GST rules), whichever is longer;
- Or for the duration of any ongoing payment dispute, chargeback, or legal proceeding related to the transaction, whichever is longer.
This retention period reflects applicable accounting and tax record-keeping requirements and is separate from, and longer than, the retention period for personal data in User accounts. Billing data retained for tax or accounting purposes will be protected with appropriate access controls.
8. System & Security Logs
| Log Type | Retention Period | Reason |
|---|---|---|
| Application error logs | 90 days (rolling) | Debugging and operational monitoring |
| HTTP request/access logs | 90 days (as managed by Vercel) | Security monitoring; operational analytics |
| Authentication event logs | 90 days | Security monitoring; anomaly detection |
| Security incident investigation logs | 180 days minimum (CERT-In requirement for qualifying incidents); or until incident resolution + 30 days | CERT-In compliance; incident investigation |
8.1 Operational logs are purged automatically on a rolling basis. Logs from Mailxify's hosting infrastructure (Vercel) are subject to Vercel's own log retention practices, which may differ from Mailxify's application-level retention.
9. Session & Authentication Data
9.1 Active sessions are stored in the database with the following lifecycle:
- Sessions are deleted from the database upon logout;
- Inactive sessions expire after a configurable period (currently seven (7) to thirty (30) days of inactivity) and are deleted from the database at expiry;
- All sessions associated with an Account are deleted when the Account is closed.
9.2 Session tokens stored in browser cookies expire in accordance with the cookie's configured lifetime and are removed from the browser on logout.
10. CERT-In Log Retention
10.1 The Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013, as amended by the CERT-In directions dated April 28, 2022 (the "CERT-In Directions"), require that qualifying Service Providers and Body Corporates maintain ICT infrastructure logs for a minimum period of 180 days and make them available to CERT-In upon direction.
10.2 Scope of CERT-In Obligation. The CERT-In Directions apply to qualifying ICT security logs (e.g., access logs, authentication logs, system event logs relevant to cybersecurity incidents). These directions apply specifically to logs relevant to cybersecurity and do not extend to:
- Campaign content or message templates created by Users;
- Recipient Contact data uploaded by Users;
- Support or grievance request content unrelated to a cybersecurity incident;
- General user account data not involved in a cybersecurity incident.
10.3 Compliance. Mailxify will retain qualifying security-relevant logs for the minimum period required by the CERT-In Directions (currently 180 days) and will cooperate with CERT-In in the event of a cybersecurity incident investigation request.
11. Deletion Process & Mechanics
11.1 Standard Deletion (Account Closure). When an Account is closed (whether by the User or by Mailxify), the following deletion sequence occurs:
- Immediate: Account access is revoked; active sessions are terminated;
- Within 30 days: All Account data, Workspace data, Contact data, Campaign data, and associated content are scheduled for permanent deletion from the primary database;
- Database backup expiry: Data may persist in Neon's automated backup snapshots for the duration of Neon's backup retention window. This is outside Mailxify's direct control and is governed by Neon's backup policies; and
- Exceptions apply: Legal acceptance records, grievance/legal records, and security logs are retained for their applicable periods as described in Sections 3.4, 6, and 8.
11.2 Manual Deletion Requests. A User may request deletion of their personal data at any time, even without closing their Account, via /privacy-requests. Upon verification of the requestor's identity, Mailxify will process the deletion request within thirty (30) days, subject to the retention exceptions described in Section 12.
11.3 Irreversibility. All deletions described in this Policy are permanent and irreversible. Once data is deleted, it cannot be recovered. Users are responsible for exporting any data they wish to retain before requesting deletion or closing their Account.
12. Retention Exceptions
12.1 Notwithstanding any other provision of this Policy, Mailxify may retain personal data beyond the standard retention period in the following circumstances:
- Legal Hold: Where personal data is relevant to pending or reasonably anticipated litigation, regulatory investigation, or dispute resolution proceedings, Mailxify may place a legal hold on relevant data for the duration of the proceedings;
- Regulatory Direction: Where a competent regulatory authority (including CERT-In or a data protection authority) directs Mailxify to retain specific data for a specified period, Mailxify will comply with that direction;
- Fraud Investigation: Where data is relevant to an active fraud or abuse investigation, it may be retained until the investigation is concluded and any enforcement action completed;
- Statutory Obligation: Where specific data is required to be retained by operation of Applicable Law (e.g., tax records, CERT-In security logs), it will be retained for the legally required period; or
- Dispute Resolution: Where data is relevant to a pending User dispute, appeal, or complaint, it will be retained until the dispute is fully resolved.
12.2 Where Mailxify retains data beyond a User's deletion request pursuant to one of the exceptions in Section 12.1, Mailxify will: (a) inform the User that retention is continuing and the reason; and (b) limit further processing of the retained data to the purpose for which it is being retained.
13. Data Principal Rights
13.1 Under the Digital Personal Data Protection Act, 2023 and this Policy, you have the right to:
- Request confirmation of what personal data Mailxify retains about you (Right of Access, Section 11 DPDPA);
- Request correction of inaccurate personal data (Right of Correction, Section 12 DPDPA);
- Request erasure of your personal data, subject to the retention exceptions in Section 12 of this Policy (Right of Erasure, Section 12 DPDPA);
- Withdraw consent for processing based on consent, at any time (Right to Withdraw Consent).
13.2 Rights requests are submitted at /privacy-requests. Mailxify will verify your identity before processing a rights request and will respond within thirty (30) days of receiving a complete request.
14. Subprocessor Retention
14.1 Data processed by Mailxify's subprocessors (Vercel and Neon) may be subject to those providers' own internal retention and backup policies. In particular:
- Vercel retains server-side logs for its own operational period (currently, application function logs for up to one week within Vercel's logging product, subject to plan);
- Neon retains database backup snapshots for a configurable period. Database deletions (rows deleted from tables) will eventually be purged from backup snapshots as those snapshots age out.
14.2 Mailxify includes data deletion obligations in its agreements with subprocessors and will request confirmation of deletion upon Account closure where practically feasible.
15. General Provisions
15.1 Amendments. Mailxify may update this Data Retention Policy. Material changes will be communicated to registered Users with reasonable advance notice. The effective date and update date are shown at the top of this Policy.
15.2 Governing Law. This Policy is governed by the laws of India. All disputes are subject to the dispute resolution provisions of the Terms of Service.
15.3 Relationship to Other Policies. This Policy forms part of the Privacy Policy and must be read together with the Privacy Policy and the Terms of Service. In the event of any inconsistency, the Terms of Service shall prevail.