Hang tight while we load the page.
Hang tight while we load the page.
This Data Retention Policy explains how long we keep your personal data, why we retain it, and when we delete it. This policy complies with GDPR Article 5(1)(e) (storage limitation) and SOC 2 requirements.
We retain personal data only as long as necessary for:
After the retention period expires, we permanently delete or anonymize your data.
Retention: As long as your account remains active
Includes:
Why: Necessary to provide our services and maintain your account.
Retention: 90 days after account deletion
When you delete your account, your data is immediately soft-deleted (hidden from the platform) but retained for 90 days to allow for:
Hard Delete: After 90 days, your data is permanently and irreversibly deleted via our automated data retention cron job.
💡 Recovery Window: If you deleted your account by mistake, contact privacy@dailyquest.com within 90 days to request restoration.
Retention: 7 years from transaction date
Includes:
Why: Legal obligation for tax audits, financial reporting, and fraud prevention (IRS requires 7 years).
Note: Even if you delete your account, transaction records are retained for 7 years for legal compliance. Personal identifiers may be pseudonymized.
Retention: 3 years after consent withdrawal
Includes:
Why: GDPR Article 7(1) requires proof that consent was obtained. We must demonstrate compliance if challenged by a data protection authority.
Retention: 13 months (SOC 2 requirement)
Includes:
Why: Security monitoring, fraud detection, and SOC 2 audit compliance.
Retention: Until you unsubscribe or withdraw consent
Includes:
Deletion: When you unsubscribe, your email is removed within 30 days. Historical campaign metrics may be retained in anonymized form.
Retention: 3 years from conversation close date
Includes:
Why: Quality assurance, training, dispute resolution, and continuity of service.
Retention: 90 days after deletion
Includes:
Note: When you delete a review, it's soft-deleted for 90 days (same as account deletion). After 90 days, it's permanently removed.
Retention: 30 days (rolling backups)
We maintain automated database backups for disaster recovery. Your data may persist in backups for up to 30 days after deletion from the live system.
Note: Backups are encrypted, access-controlled, and used solely for disaster recovery (not for restoring individual user data after the 90-day soft delete period).
We use an automated cron job that runs daily to permanently delete data that has exceeded its retention period:
All deletions are logged to deletion_audit_log for SOC 2 compliance.
Before deleting your account, you can request a complete copy of your personal data:
Download all your personal data in machine-readable JSON format (GDPR Article 20 - Right to Data Portability).
Go to Privacy SettingsWe may retain certain data beyond standard retention periods if:
In such cases, we will notify you and resume normal deletion schedules once the exception no longer applies (unless prohibited by law).
For certain use cases, we may anonymize or pseudonymize data instead of deleting it:
Anonymized data is no longer considered personal data under GDPR and is not subject to retention limits.
You have the right to:
We may update this Data Retention Policy to reflect changes in legal requirements or business practices. When we make material changes:
If you have questions about our data retention practices: