Skip to content
aicial
Legal

Data Retention & Deletion Policy

Version: 1.0

Effective date: 19 August 2026

Last reviewed: 19 August 2026

This Data Retention & Deletion Policy explains how long Aperim Pty Ltd, which operates the aicial brand, keeps personal information, and how we delete or de-identify it once we no longer need it. It is a companion to our Privacy Policy, which explains what personal information we collect and why, and our Data Processing Agreement, which sets out the deletion process for a customer’s data when their service or account terminates.

1. About this policy

Aperim Pty Ltd (ABN 46150699737; ACN 150699737) is incorporated in New South Wales, Australia and operates the aicial brand. In this policy, “aicial” refers to that brand; “we”, “us” and “our” refer to Aperim Pty Ltd; and “you” refers to an individual whose personal information we handle.

This policy explains how long we keep the personal information described in our Privacy Policy, and how we delete or de-identify it. It applies to personal information we hold as controller in our own right. Where we process personal data as a customer’s processor or service provider under our Data Processing Agreement (DPA), the DPA’s own deletion process governs, and this policy describes how that process interacts with the categories below.

This policy expands on the retention and deletion commitments already made in the Privacy Policy and the DPA. It does not reduce or override either document: where the Privacy Policy or the DPA states a specific period or process for particular information, that period or process continues to apply, and this policy should be read consistently with it.

2. Our retention principle

We retain personal information only for as long as reasonably necessary for the purpose for which we collected it, to comply with a contractual or legal obligation, to resolve a dispute, or to establish, exercise or defend a legal claim. This is the same principle the Privacy Policy states in its data quality, retention and deletion section. This policy does not change that principle; it sets out what it means in practice for the main categories of information we hold.

We do not keep personal information indefinitely by default. Once none of the purposes above still applies to a piece of information, we delete or de-identify it, subject to the backup treatment described in section 5 and the legal and contractual exceptions described in section 7.

3. Retention periods by category

We apply the principle in section 2 differently depending on the type of information and why we hold it. The following are our standard retention periods for the categories of personal information described in the Privacy Policy’s information we collect section. A longer period can apply where section 7 requires it.

Account and billing information. We retain account, contact and billing information for as long as the relevant account is open, and then for a further period after closure to meet our own legal, tax, accounting and dispute-resolution obligations. Our default for that further period is 7 years after account closure, consistent with the financial record-keeping period required of Australian companies under corporate law, and comfortably exceeding applicable taxation record-keeping requirements.

Connected-account and content data. Where a customer connects a social account or submits content for analysis or content creation, we hold the resulting connected-account and content data for the life of that connection. Consistent with the Privacy Policy, we delete an OAuth connection token promptly once a connection is disconnected. Where a single connection is disconnected but the customer’s account or service otherwise continues, we delete or de-identify the remaining connected-account and content data for that connection — for example, cached account and post information, engagement and performance metrics, and analysis outputs — within 30 days of disconnection, as our standard working period for closing out that data. Where a customer’s entire account or service terminates instead — whether by disconnecting every connection or by closing the account or service itself — deletion instead follows the DPA’s return and deletion of data process: a 30-day window for the customer to elect deletion or return of their data, followed by deletion within a further 60 days if no election is made.

Waitlist information. Consistent with the Privacy Policy, we delete waitlist information when you ask us to delete it, when you are enrolled as a customer, or when our waitlist programme concludes, whichever happens first. In addition to those events, we treat a waitlist entry that has had no activity — no response to our communications and no update to the entry — for 24 months as stale, and delete it as part of our routine retention practice.

Automatically collected information. We retain the device, browser, IP address, log, diagnostic, security and usage information described in the Privacy Policy’s information we collect section for as long as needed for security, troubleshooting and service-improvement purposes, and in any event for no longer than 24 months from collection, after which we delete or de-identify it. The separate Cookie Policy explains retention of cookies and similar technologies specifically.

Partner-referral prospect information. Where a partner refers a prospective customer to us under our Reseller and Partner Program Agreement, we retain the referred contact information for as long as needed to make contact and assess interest, and in any event for no longer than 12 months from referral if the prospect does not become a customer, after which we delete it.

Aggregate and de-identified benchmark data. Our deal, rate, payment-experience and other benchmarks are built from information that customers contribute to our benchmark panel. We hold a contribution in identifiable form for as long as the customer’s panel consent remains in force, and we aggregate and de-identify it into a qualifying benchmark as our own operational commitment under this policy. Once information has genuinely been aggregated and de-identified in that way, it is no longer personal information — consistent with the Responsible AI Usage Policy’s aggregate-before-individual principle for how we present benchmark insight — and we retain it indefinitely to keep our benchmarks accurate and useful over time. If you withdraw consent for a contribution before it has been aggregated and de-identified, we honour that withdrawal by deleting or excluding the not-yet-aggregated contribution, consistent with the Responsible AI Usage Policy’s consent commitments. We do not attempt to re-identify de-identified information.

4. How we delete information

Deleting personal information means removing it from our production systems so that it is no longer accessible or usable, using secure deletion methods appropriate to where it is stored. Where deleting a particular record is not practicable — for example, because it is embedded in an aggregate figure or a system log — we irreversibly de-identify it instead, so that it can no longer be linked back to an identifiable individual. Either approach satisfies a deletion commitment in this policy. Where the DPA or the Privacy Policy states a deletion obligation, that obligation applies on its own terms.

Where personal information subject to a deletion or de-identification commitment has also been shared with a service provider or sub-processor on our Sub-processor List, we propagate that deletion or de-identification to them, consistent with the Responsible AI Usage Policy’s consent-before-collection principle and the DPA’s sub-processor obligations.

These deletion and de-identification methods are consistent with the technical and organisational measures described in the DPA’s obligations as your processor section and the Privacy Policy’s security section.

5. Backups

Our database provider gives us a point-in-time recovery capability that keeps recent versions of our production database available for a limited window, currently up to 30 days, so that we can restore recent data after an incident or operational error. Deleting a record from our production systems does not immediately remove every version of it that this recovery window still holds. A deleted record may remain recoverable through this window for up to 30 days by default, until that window elapses in the ordinary course. If we bring additional backup infrastructure into use as our services develop, we will update this section to describe how it affects this period.

We do not use this recovery capability to reintroduce personal information that has been deleted in the ordinary course, and we do not use it to circumvent an active deletion request. We access it only to restore service, investigate an incident, or meet a legal obligation.

6. Requesting deletion

You can ask us to delete personal information we hold about you by emailing privacy@aicial.com. The Privacy Policy’s privacy rights section describes how we handle a request like this, including that we may need to verify your identity and authority before acting, and that we do not discriminate against anyone for making one. If you are an individual whose information appears in a customer’s connected account or content rather than in a direct relationship with us, the Privacy Policy explains why we generally direct that request to the customer in the first instance, and how we support the customer in responding to it.

We act on a deletion request within a reasonable period. Where the Privacy Policy sets an applicable response target for your request — for example, the one-month target that applies to a United Kingdom or European Union erasure request — we aim to meet it; otherwise we aim to act within a similarly reasonable timeframe. This is all subject to the categories, working periods and backup treatment described in this policy, and the exceptions in section 7.

8. Changes to this policy

We may update this policy to reflect changes to our services, our practices or our legal obligations. The version, effective date and last-reviewed date shown at the top identify the current policy. We publish the updated policy on our website and, where a change is material, provide additional notice through the service or by email before the change takes effect.

9. Contact us

For questions about this policy, or to request deletion of your data, contact:

Aperim Pty Ltd, which operates the aicial brand
ABN 46150699737
ACN 150699737
New South Wales, Australia
Email: privacy@aicial.com