Data Retention Statement
Effective date: July 19, 2026
This statement explains Xpitro's product-level retention approach at a high level. It is not a substitute for customer-specific legal advice or the platform's internal retention architecture.
Principle
Xpitro retains data only for as long as reasonably necessary to provide the services, maintain security and operational integrity, support auditability and customer support, comply with legal and contractual obligations, and preserve backup integrity and disaster-recovery resilience.
Categories
At a high level, Xpitro may retain account and organisation records, authentication and audit logs, billing and transaction records, customer support records, customer content and related platform records, and backup copies for bounded operational periods.
Contract-End Handling
At the end of a contract or trial, active access may be removed or reduced, and customer-controlled data may be returned, exported, deleted, or retained according to the contract, DPA, operational backup cycles, and applicable law.
Backups
Deleted or expired records may persist temporarily in protected backups until normal backup rotation removes them.
Exceptions
Xpitro may retain relevant data beyond ordinary operational periods where required for legal hold, dispute handling, fraud or abuse investigation, security investigation, or regulatory requirement.
Customer Responsibility
Customers remain responsible for defining their own legal and regulatory retention requirements, exporting data before account closure where needed, and configuring internal retention decisions appropriately within the product where such controls exist.
Questions about retention should be sent to privacy@xpitro.com or legal@xpitro.com.