Data Retention & Deletion

This Data Retention & Deletion Policy describes how Ovaloop retains, archives, exports, and deletes customer data and personal information processed through the Ovaloop platform.


Data Retention & Deletion
Purpose
Scope
Data Ownership
Retention Periods
Customer Data Export
Deletion Requests
Deletion Process
Personal Data Requests
Security of Retained Data
Exceptions to Deletion
De-Identified and Aggregated Data
Policy Review
Contact Information

1. Purpose

This Data Retention & Deletion Policy describes how Ovaloop retains, archives, exports, and deletes customer data and personal information processed through the Ovaloop platform.

The purpose of this policy is to ensure that data is retained only for as long as necessary to provide services, comply with legal obligations, resolve disputes, maintain security, and support legitimate business operations.

2. Scope

This policy applies to:

Customers using Ovaloop services

Customer business data

Personal data processed by Ovaloop

Employees and contractors with access to customer data

Third-party service providers acting on behalf of Ovaloop

3. Data Ownership

All customer business data stored within Ovaloop remains the property of the customer.

Customer data may include:

Inventory records

Sales records

Purchase records

Customer records

Supplier records

Employee records

Financial records

Reports and analytics

Documents and attachments

Transaction histories

Ovaloop does not claim ownership of customer data.

4. Retention Periods

Active Customer Accounts: Customer data is retained for the duration of the active subscription period.

Account Suspension: Where an account is suspended due to non-payment or policy violations, data may remain stored for up to ninety (90) days following suspension.

Account Termination: Upon account termination, Ovaloop may retain customer data for up to ninety (90) days to allow:

Data export requests

Account recovery requests

Resolution of disputes

Compliance reviews

Following this period, customer data may be permanently deleted in accordance with this policy.

Backup Systems: Archived backups may contain customer data for up to one hundred and eighty (180) days after deletion from production systems. Backup data is automatically overwritten according to Ovaloop's backup retention schedule.

Legal and Regulatory Retention: Ovaloop may retain specific records beyond standard retention periods where required:

By law

By court order

For tax obligations

For audit requirements

For fraud investigations

For security investigations

5. Customer Data Export

Customers may request a copy of available business data before deletion.

Data export formats may include:

CSV

Excel

PDF

JSON

Other available formats supported by Ovaloop

Ovaloop reserves the right to verify customer identity before releasing data exports.

6. Deletion Requests

Customers may request deletion of their data by contacting support@ovaloop.com or through designated account management features.

Ovaloop may require verification of account ownership before processing deletion requests.

7. Deletion Process

Upon approval of a deletion request:

Production Systems: Customer data will be removed from active production environments.

User Accounts: Associated user accounts may be disabled or removed.

Third-Party Services: Where applicable, Ovaloop will instruct relevant service providers to remove customer data under their control.

Backup Systems: Data contained within backup systems will be removed according to backup lifecycle schedules and may remain inaccessible until automatic expiration.

8. Personal Data Requests

Individuals whose personal data is processed through Ovaloop may request:

Access to personal information

Correction of inaccurate information

Deletion where legally permitted

Restriction of processing

Objection to certain processing activities

Requests shall be evaluated in accordance with applicable data protection laws.

9. Security of Retained Data

Retained data remains subject to Ovaloop's security controls, including:

Access restrictions

Monitoring

Authentication controls

Encryption where applicable

Audit logging

Only authorized personnel may access retained data.

10. Exceptions to Deletion

Ovaloop may refuse or delay deletion requests where:

Retention is required by law

A legal dispute exists

Fraud investigations are ongoing

Security investigations are ongoing

Regulatory obligations require preservation

In such circumstances, retained data will be restricted to authorized purposes only.

11. De-Identified and Aggregated Data

Ovaloop may retain anonymized, aggregated, or de-identified information that cannot reasonably identify a customer or individual.

Such information may be used for:

Product improvement

Analytics

Research

Benchmarking

Service optimization

12. Policy Review

This policy may be reviewed and updated periodically. Updated versions shall be published through Ovaloop's website or platform. Continued use of Ovaloop services constitutes acceptance of the updated policy.

13. Contact Information

If you have any questions or concerns regarding data retention and deletion, please contact us: