Mailxify
Legal & Trust

Data Retention Policy

Effective Date: 2026-09-01
Last Updated: 2026-09-07

Data Retention — Key Points (Plain English)

This summary covers the most important retention rules. Please read the full policy below for complete detail.

  • Your Account data is kept while your Account is active and deleted within 30 days after Account closure.
  • Your Recipients (Contacts) are processed data. They are deleted with your Workspace or Account, subject to a 30-day grace period for recovery.
  • Unsubscribe records (Suppression Lists) are kept indefinitely because deleting them would cause re-sending to people who asked to stop receiving emails.
  • Legal request records are kept longer (up to 3 years) for regulatory compliance and dispute resolution purposes.
  • Security logs are rolled over every 90 days except where CERT-In directions require longer retention for qualifying incidents.
  • You can request deletion of your personal data at any time via /privacy-requests. Deletion takes place within 30 days of verification.
Full Data Retention Policy

1. Introduction & Principles

1.1 Purpose. This Data Retention Policy ("Retention Policy") describes how long Mailxify retains different categories of data, the reasons for which specific retention periods are applied, the conditions under which data is deleted, and the exceptions that apply to standard retention periods. This Policy is incorporated into and forms part of the Privacy Policy and the Terms of Service.

1.2 Core Principles. Mailxify's retention practices are guided by the following principles:

  • Purpose Limitation: Data is retained only for as long as it is necessary for the specific purpose for which it was collected, as required by Applicable Law, or to establish, exercise, or defend legal claims;
  • Data Minimisation: Mailxify does not retain data beyond the applicable retention period simply because storage is inexpensive or technically convenient;
  • Accuracy: Mailxify will delete data that is no longer accurate, relevant, or necessary for its stated purpose, and will respond to correction requests that affect ongoing retention decisions;
  • Security during Retention: During the retention period, data is protected by the technical and organizational security measures described in the Security Policy; and
  • Lawful Basis for Retention: Where continued retention of data is required beyond the User's deletion request, Mailxify identifies and documents the specific legal basis for continued retention.

1.3 Applicable Law. Retention periods in this Policy are designed to comply with, inter alia, the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011, and the CERT-In directions issued thereunder, to the extent applicable.

2. Retention Roles

2.1 Data Mailxify Retains as Controller (Data Fiduciary). Mailxify retains Account data, session data, legal request records, and system logs as the Data Fiduciary in its own right. The retention rules for this data are set by Mailxify in this Policy and implemented by Mailxify's systems. Users exercise their rights in respect of this data by contacting Mailxify directly.

2.2 Data Mailxify Retains as Processor. Mailxify retains Recipient (Contact) data in its database as a Data Processor, acting on the Controller's (User's) instructions. The User, as Controller, determines the purpose and duration of retention for this data. Mailxify's retention of Recipient data is bounded by: (a) the User's own data management decisions (e.g., deleting a Contact or Workspace); and (b) the term of the Agreement. Mailxify will delete Recipient data after Account closure as specified in Section 4. This distinction between Controller and Processor retention roles is important for understanding which party is accountable for specific data retention decisions.

2.3 Suppression Records — Joint Interest. Suppression list records (opt-out records) serve both the User's compliance needs and Mailxify's own obligation to prevent continued sending to suppressed addresses. Mailxify maintains suppression records for the duration of the relevant Workspace, even if the User deletes individual Contact records, because deletion of opt-out records could result in Mailxify's systems sending further emails to people who have opted out.

3. Customer Content (User Data)

3.1 Account Registration Data

DataRetention TriggerRetention PeriodDeletion Condition
Full nameAccount creationDuration of Account + 30-day grace periodAccount closure or confirmed deletion request
Email addressAccount creationDuration of Account + 30-day grace periodAccount closure or confirmed deletion request
Password hashAccount creationDuration of AccountAccount closure
Account role assignmentAccount creationDuration of AccountAccount closure

3.2 Reason for 30-Day Grace Period. The 30-day post-closure grace period exists to allow Users who close their Account inadvertently or who change their mind shortly after closure to recover their Account without permanent data loss. After 30 days, deletion is permanent and irreversible.

3.3 Workspace Data

DataRetention PeriodDeletion Condition
Workspace record (name, ID, settings)Duration of Account + 30-day graceAccount closure or explicit Workspace deletion
Workspace membership recordsDuration of membership or WorkspaceMember removal or Workspace deletion
Campaign templatesDuration of WorkspaceWorkspace deletion

3.4 Legal Acceptance Records

Legal acceptance records (the record that you accepted a specific version of the Terms of Service and Privacy Policy at a specific date and time) are retained for the longer of:

  • The duration of your Account plus the applicable limitation period under Indian law for contractual claims (currently three (3) years under the Limitation Act, 1963 for simple contracts); or
  • Such longer period as may be required by Applicable Law.

The basis for this retention is the legal and regulatory requirement to maintain evidence of informed consent. These records may be required in the event of a legal challenge to the enforceability of the Terms or a data processing dispute.

4. Recipient (Contact) Data

Data CategoryRetention TriggerRetention PeriodDeletion ConditionException
Contact records (name, email, company, custom fields)Upload to WorkspaceDuration of Workspace + 30-day grace post-Account-closureUser deletes Contact; User deletes Workspace; Account closureSuppression status remains even after Contact record deletion (see Section 5)

4.1 User-Controlled Deletion. Within the Service, Users can delete individual Contact records from their Workspace at any time. Deleted Contact records are permanently removed from the Mailxify database.

4.2 No Retention Beyond Workspace Lifecycle. Mailxify does not retain Contact data after a Workspace has been deleted and the 30-day post-closure grace period has expired. Mailxify has no business basis for retaining Recipient data beyond the term of the Agreement.

4.3 Impact of Deletion on Campaigns. If a Contact record is deleted while a Campaign is in progress, the deletion will prevent further Messages from being sent to that Recipient. Already-transmitted Messages cannot be recalled.

5. Suppression Records (Opt-Out / Unsubscribe)

5.1 Indefinite Retention by Default. Suppression list records — records of email addresses for which further Campaign sending has been prohibited as a result of an unsubscribe request, spam complaint, or hard bounce — are retained indefinitely by default. This is not an arbitrary decision; it reflects the operational and legal importance of suppression records:

  • Deleting a suppression record would cause that email address to be treated as an unsuppressed Recipient, potentially resulting in further Messages being sent to a person who has explicitly requested to stop receiving them;
  • Under this ASP and applicable consumer protection law, re-contacting a person who has unsubscribed is prohibited; and
  • Indefinite retention of suppression records is industry standard practice.

5.2 User Override. A User (Workspace Owner) may remove an email address from the Suppression List if they have verifiable evidence that the Recipient has affirmatively re-consented to further communications. The User assumes full responsibility for the lawfulness of re-enabling a previously suppressed address.

5.3 Suppression Data Content. Suppression records contain only the email address, the date of suppression, and the reason (e.g., "unsubscribe", "hard bounce", "complaint"). They do not contain Campaign content, message bodies, or other personal data beyond the email address.

5.4 Post-Account-Closure. Suppression records associated with a closed Account are retained for a period sufficient to prevent resumed sending in the event the Account is re-opened, and then deleted. After permanent Account deletion, suppression records associated with that Account are also deleted.

7. Billing & Transaction Records

7.1 Current Status. Commercial billing is not currently active. No payment records, invoice data, or transaction records are currently held by Mailxify.

7.2 Future Retention (When Billing is Activated). When commercial billing is activated, billing and transaction records will be retained for:

  • The longer of eight (8) years from the date of the transaction, or such other period as may be required by applicable tax law (e.g., the period prescribed for maintenance of books of accounts under the Companies Act, 2013, or applicable GST rules), whichever is longer;
  • Or for the duration of any ongoing payment dispute, chargeback, or legal proceeding related to the transaction, whichever is longer.

This retention period reflects applicable accounting and tax record-keeping requirements and is separate from, and longer than, the retention period for personal data in User accounts. Billing data retained for tax or accounting purposes will be protected with appropriate access controls.

8. System & Security Logs

Log TypeRetention PeriodReason
Application error logs90 days (rolling)Debugging and operational monitoring
HTTP request/access logs90 days (as managed by Vercel)Security monitoring; operational analytics
Authentication event logs90 daysSecurity monitoring; anomaly detection
Security incident investigation logs180 days minimum (CERT-In requirement for qualifying incidents); or until incident resolution + 30 daysCERT-In compliance; incident investigation

8.1 Operational logs are purged automatically on a rolling basis. Logs from Mailxify's hosting infrastructure (Vercel) are subject to Vercel's own log retention practices, which may differ from Mailxify's application-level retention.

9. Session & Authentication Data

9.1 Active sessions are stored in the database with the following lifecycle:

  • Sessions are deleted from the database upon logout;
  • Inactive sessions expire after a configurable period (currently seven (7) to thirty (30) days of inactivity) and are deleted from the database at expiry;
  • All sessions associated with an Account are deleted when the Account is closed.

9.2 Session tokens stored in browser cookies expire in accordance with the cookie's configured lifetime and are removed from the browser on logout.

10. CERT-In Log Retention

10.1 The Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013, as amended by the CERT-In directions dated April 28, 2022 (the "CERT-In Directions"), require that qualifying Service Providers and Body Corporates maintain ICT infrastructure logs for a minimum period of 180 days and make them available to CERT-In upon direction.

10.2 Scope of CERT-In Obligation. The CERT-In Directions apply to qualifying ICT security logs (e.g., access logs, authentication logs, system event logs relevant to cybersecurity incidents). These directions apply specifically to logs relevant to cybersecurity and do not extend to:

  • Campaign content or message templates created by Users;
  • Recipient Contact data uploaded by Users;
  • Support or grievance request content unrelated to a cybersecurity incident;
  • General user account data not involved in a cybersecurity incident.

10.3 Compliance. Mailxify will retain qualifying security-relevant logs for the minimum period required by the CERT-In Directions (currently 180 days) and will cooperate with CERT-In in the event of a cybersecurity incident investigation request.

11. Deletion Process & Mechanics

11.1 Standard Deletion (Account Closure). When an Account is closed (whether by the User or by Mailxify), the following deletion sequence occurs:

  • Immediate: Account access is revoked; active sessions are terminated;
  • Within 30 days: All Account data, Workspace data, Contact data, Campaign data, and associated content are scheduled for permanent deletion from the primary database;
  • Database backup expiry: Data may persist in Neon's automated backup snapshots for the duration of Neon's backup retention window. This is outside Mailxify's direct control and is governed by Neon's backup policies; and
  • Exceptions apply: Legal acceptance records, grievance/legal records, and security logs are retained for their applicable periods as described in Sections 3.4, 6, and 8.

11.2 Manual Deletion Requests. A User may request deletion of their personal data at any time, even without closing their Account, via /privacy-requests. Upon verification of the requestor's identity, Mailxify will process the deletion request within thirty (30) days, subject to the retention exceptions described in Section 12.

11.3 Irreversibility. All deletions described in this Policy are permanent and irreversible. Once data is deleted, it cannot be recovered. Users are responsible for exporting any data they wish to retain before requesting deletion or closing their Account.

12. Retention Exceptions

12.1 Notwithstanding any other provision of this Policy, Mailxify may retain personal data beyond the standard retention period in the following circumstances:

  • Legal Hold: Where personal data is relevant to pending or reasonably anticipated litigation, regulatory investigation, or dispute resolution proceedings, Mailxify may place a legal hold on relevant data for the duration of the proceedings;
  • Regulatory Direction: Where a competent regulatory authority (including CERT-In or a data protection authority) directs Mailxify to retain specific data for a specified period, Mailxify will comply with that direction;
  • Fraud Investigation: Where data is relevant to an active fraud or abuse investigation, it may be retained until the investigation is concluded and any enforcement action completed;
  • Statutory Obligation: Where specific data is required to be retained by operation of Applicable Law (e.g., tax records, CERT-In security logs), it will be retained for the legally required period; or
  • Dispute Resolution: Where data is relevant to a pending User dispute, appeal, or complaint, it will be retained until the dispute is fully resolved.

12.2 Where Mailxify retains data beyond a User's deletion request pursuant to one of the exceptions in Section 12.1, Mailxify will: (a) inform the User that retention is continuing and the reason; and (b) limit further processing of the retained data to the purpose for which it is being retained.

13. Data Principal Rights

13.1 Under the Digital Personal Data Protection Act, 2023 and this Policy, you have the right to:

  • Request confirmation of what personal data Mailxify retains about you (Right of Access, Section 11 DPDPA);
  • Request correction of inaccurate personal data (Right of Correction, Section 12 DPDPA);
  • Request erasure of your personal data, subject to the retention exceptions in Section 12 of this Policy (Right of Erasure, Section 12 DPDPA);
  • Withdraw consent for processing based on consent, at any time (Right to Withdraw Consent).

13.2 Rights requests are submitted at /privacy-requests. Mailxify will verify your identity before processing a rights request and will respond within thirty (30) days of receiving a complete request.

14. Subprocessor Retention

14.1 Data processed by Mailxify's subprocessors (Vercel and Neon) may be subject to those providers' own internal retention and backup policies. In particular:

  • Vercel retains server-side logs for its own operational period (currently, application function logs for up to one week within Vercel's logging product, subject to plan);
  • Neon retains database backup snapshots for a configurable period. Database deletions (rows deleted from tables) will eventually be purged from backup snapshots as those snapshots age out.

14.2 Mailxify includes data deletion obligations in its agreements with subprocessors and will request confirmation of deletion upon Account closure where practically feasible.

15. General Provisions

15.1 Amendments. Mailxify may update this Data Retention Policy. Material changes will be communicated to registered Users with reasonable advance notice. The effective date and update date are shown at the top of this Policy.

15.2 Governing Law. This Policy is governed by the laws of India. All disputes are subject to the dispute resolution provisions of the Terms of Service.

15.3 Relationship to Other Policies. This Policy forms part of the Privacy Policy and must be read together with the Privacy Policy and the Terms of Service. In the event of any inconsistency, the Terms of Service shall prevail.