Retention and Deletion Policy
Effective July 23, 2026
1. Purpose
This policy describes how OneagencyOS LLC retains, exports, deletes, and disposes of information. We retain information only for legitimate service, security, contractual, accounting, dispute, and legal purposes and take reasonable measures to prevent unauthorized access during retention and disposal.
2. Active Agency Data
Customer Data is retained while an agency subscription is active and as configured by the agency. Authorized agency users may delete supported records, apply document categories, and configure sharing and retention controls. Deleting a user does not automatically delete agency records created or managed by that user.
3. Default Retention Schedule
- Agency workspace and client records: for the active subscription and the post-termination export window.
- Post-termination export window: 30 days unless the signed agreement states another period.
- Production deletion: targeted within 60 days after the export window ends or a verified deletion request is approved.
- Backups: deleted production data may remain in protected backups for up to an additional 90 days before aging out.
- Security and activity logs: generally 12 months, longer when needed to investigate abuse or an incident.
- Completed signature records and audit certificates: seven years by default, subject to agency configuration and applicable law.
- Billing, tax, and transaction records: seven years or the period required by applicable law.
- Demo and sales inquiries: up to 24 months after the last meaningful interaction unless consent is withdrawn or law requires otherwise.
- Support records: generally three years after closure, unless linked to a longer-lived dispute, incident, or account record.
4. Agency-Controlled Retention
An agency may choose longer or shorter periods where supported. The agency is responsible for preserving applications, policy records, signed forms, communications, recordings, consumer-report authorizations, and other regulated records for the legally required period. OneagencyOS may reject or delay a configuration that would conflict with a known legal hold, active investigation, contractual commitment, or system-integrity requirement.
5. Export and Termination
Before termination, an agency should export the records it is required to keep. During the standard 30-day export window, authorized administrators may request a supported export. Access may be limited to export functions if fees are overdue or continued access creates a security risk. After the export window, OneagencyOS may delete the workspace and is not obligated to restore it.
6. Verified Deletion Requests
Agency administrators may request workspace deletion by contacting hello@oneagencyos.com. OneagencyOS will verify the requester, authority, agency, affected systems, and legal-hold status before deletion. Individual clients and employees should generally submit requests to the agency controlling their records. OneagencyOS will assist the agency as required by the signed data-processing terms.
7. Legal Holds and Exceptions
Deletion may be suspended when information is reasonably needed for litigation, subpoena, regulatory inquiry, security investigation, fraud prevention, payment dispute, insurance claim, or another legal obligation. Access to held information will be restricted. When the hold ends, the ordinary deletion schedule resumes.
8. Backups and Disaster Recovery
Backups are encrypted or otherwise access-restricted according to system design and are used for resilience and disaster recovery, not ordinary business access. Deleted information may persist in backup media until the media is overwritten. If a backup is restored, applicable deletion records will be reapplied before the data is returned to normal use where technically feasible.
9. Subprocessors and Connected Services
OneagencyOS will direct subprocessors to delete or return Customer Data according to applicable agreements. Disconnecting a third-party service stops future access but does not necessarily delete data already saved to the OneagencyOS workspace. Deletion from OneagencyOS does not delete data held independently by an agency, carrier, email provider, payment provider, or other connected service.
10. Secure Disposal
When information is no longer retained, OneagencyOS uses reasonable disposal measures appropriate to the medium, such as logical deletion, cryptographic erasure, provider-managed media destruction, or secure destruction of physical records. Audit evidence of deletion requests and approvals may be retained without the deleted content.
11. Changes and Contact
We may revise default periods as technology, legal obligations, and service needs change. Material changes will be posted with a revised effective date. Questions and verified requests may be sent to hello@oneagencyos.com.