Data Retention & Archival Policy
FVI retains customer data only as long as required to deliver the service, satisfy legal and regulatory obligations, and support audit. Tenants may extend retention per data class; reductions below the platform minimum are not permitted.
| Data class | Retention | Basis |
|---|---|---|
AI usage telemetry Per-call usage and cost metering supporting AI governance and chargeback. | 730 days | AI governance audit trail (2 years) |
aidp_output_recon_invalidations | 90 days | AIDP→Recon invalidation index — short-lived |
aidp_pages | 90 days | AIDP page binaries — short-lived working set |
Audit log Hash-chained, append-only system audit. Never auto-purged — held for the full SOX 7-year window and archived to immutable cold storage thereafter. | 2557 days | SOX / SOC2 / 7-year regulatory minimum |
Email delivery log Transactional and digest email delivery records for CAN-SPAM and bounce diagnostics. | 365 days | CAN-SPAM / deliverability investigation window |
recon_exceptions | 395 days | Break management evidence (13 months) |
recon_matches | 395 days | Match audit trail (13 months) |
Reconciliation runs Tenant-configurable. Default is 13 months to cover regulatory year-end review windows. | 395 days | Tenant default 13 months; overridable per tenant |
Security events Authentication, MFA, SSO and step-up events for SOC 2 CC7.2 investigation. | 730 days | SOC2 CC7.2 incident detection (2 years) |
What we store and why
We store the records you upload (statements, trades, GL extracts), the matches and breaks our engine produces, and the operational metadata needed to audit, secure, bill, and improve the service. We do not sell customer data and we do not use it to train third-party models.
Tenant overrides
Tenant administrators can extend retention for any tenant-configurable class up to 10 years from Tenant Admin → Settings → Data retention. Reductions below the platform floor are rejected by the database. The audit_log class is regulatory-fixed and not configurable.
Purge cadence & cold-storage archive
Nightly server-side jobs purge data past its effective retention; every purge bucket emits a security_events row of type retention.purge. Where an archive prefix is configured, rows are copied to write-once, region-pinned object storage with SHA-256 anchoring before deletion.
How to request a copy of your data (GDPR Art. 15)
Email [email protected] from the account-owner address. We respond within 30 days with a verified-identity machine-readable export covering every system of record listed above.
How to request deletion (GDPR Art. 17)
Account-closure deletion completes within 30 days. Records we are obliged to retain by law — primarily the hash-chained audit log under SOX / SOC 2 — are preserved in immutable storage until their statutory window expires, and you receive a written list of what was retained and why.
Sub-processors
Our current sub-processor list, with regions and processing purposes, lives at /sub-processors and is versioned in the Trust Center.
Changes to this policy
Material changes are governed by the Terms of Service and notified by email to billing and security contacts at least 30 days before they take effect. Historical versions are kept in the Trust Center.
Questions? Contact [email protected].