OneagencyOS

Retention and Deletion Policy

Effective July 23, 2026

1. Purpose

This policy describes how OneagencyOS LLC retains, exports, deletes, and disposes of information. We retain information only for legitimate service, security, contractual, accounting, dispute, and legal purposes and take reasonable measures to prevent unauthorized access during retention and disposal.

2. Active Agency Data

Customer Data is retained while an agency subscription is active and as configured by the agency. Authorized agency users may delete supported records, apply document categories, and configure sharing and retention controls. Deleting a user does not automatically delete agency records created or managed by that user.

3. Default Retention Schedule

4. Agency-Controlled Retention

An agency may choose longer or shorter periods where supported. The agency is responsible for preserving applications, policy records, signed forms, communications, recordings, consumer-report authorizations, and other regulated records for the legally required period. OneagencyOS may reject or delay a configuration that would conflict with a known legal hold, active investigation, contractual commitment, or system-integrity requirement.

5. Export and Termination

Before termination, an agency should export the records it is required to keep. During the standard 30-day export window, authorized administrators may request a supported export. Access may be limited to export functions if fees are overdue or continued access creates a security risk. After the export window, OneagencyOS may delete the workspace and is not obligated to restore it.

6. Verified Deletion Requests

Agency administrators may request workspace deletion by contacting hello@oneagencyos.com. OneagencyOS will verify the requester, authority, agency, affected systems, and legal-hold status before deletion. Individual clients and employees should generally submit requests to the agency controlling their records. OneagencyOS will assist the agency as required by the signed data-processing terms.

7. Legal Holds and Exceptions

Deletion may be suspended when information is reasonably needed for litigation, subpoena, regulatory inquiry, security investigation, fraud prevention, payment dispute, insurance claim, or another legal obligation. Access to held information will be restricted. When the hold ends, the ordinary deletion schedule resumes.

8. Backups and Disaster Recovery

Backups are encrypted or otherwise access-restricted according to system design and are used for resilience and disaster recovery, not ordinary business access. Deleted information may persist in backup media until the media is overwritten. If a backup is restored, applicable deletion records will be reapplied before the data is returned to normal use where technically feasible.

9. Subprocessors and Connected Services

OneagencyOS will direct subprocessors to delete or return Customer Data according to applicable agreements. Disconnecting a third-party service stops future access but does not necessarily delete data already saved to the OneagencyOS workspace. Deletion from OneagencyOS does not delete data held independently by an agency, carrier, email provider, payment provider, or other connected service.

10. Secure Disposal

When information is no longer retained, OneagencyOS uses reasonable disposal measures appropriate to the medium, such as logical deletion, cryptographic erasure, provider-managed media destruction, or secure destruction of physical records. Audit evidence of deletion requests and approvals may be retained without the deleted content.

11. Changes and Contact

We may revise default periods as technology, legal obligations, and service needs change. Material changes will be posted with a revised effective date. Questions and verified requests may be sent to hello@oneagencyos.com.