Data Retention & Deletion Policy
1. Objective & balancing philosophy
Invoizify adheres to the principle of storage limitation: data should be kept only for as long as necessary to fulfill the operational purpose for which it was gathered, or to satisfy statutory obligations.
- Operational Reality: Invoizify is an invoicing platform. Users rely on Invoizify to maintain multi-year invoice records for client reference, GST verification, and internal accounting. Therefore, we preserve invoice records throughout the lifespan of your active subscription unless you affirmatively request their deletion.
2. Data retention schedule
| Data Classification | Description of Records | Active Retention Period | Post-Termination / Deletion Window | Legal & Operational Rationale |
|---|---|---|---|---|
| User Account Credentials | Mobile number, business name, profile settings, verified email. | Duration of active subscription. | Deleted within Account-deletion window (e.g. 30–60 days) of verified account closure. | Operational access and account authentication. |
| Issued Invoices & Commercial Documents | Generated PDF invoices, client rosters, line items, pricing, tax breakdowns. | Maintained continuously during active account status. | Retained for Post-cancellation export window (e.g. 30 days) post-cancellation to allow export, then permanently purged or irreversibly anonymized. | Core service utility. Note: User must export for independent 72-month GST compliance. |
| Temporary WhatsApp Voice Notes | Raw inbound .ogg / .mp3 audio files sent via WhatsApp for transcription. |
Retained transiently for Voice-note retention (e.g. 7 days) post-transcription to handle retries. | Automated background deletion script runs daily. | Data minimisation; voice recordings are sensitive and unnecessary once transcribed. |
| Temporary OCR & Uploaded Images | Inbound photos of physical receipts, supplier bills, or handwritten notes. | Retained transiently for Receipt-photo retention (e.g. 14 days) after data parsing. | Hard deleted from temporary blob storage. | Once text fields are extracted into the invoice draft, source photos are obsolete. |
| Subscription & Payment Logs | Transaction IDs, subscription renewal timestamps, payment gateway tokens, tax invoices issued by Invoizify. | Retained for eight (8) financial years following transaction date. | Held in secure financial archive; not purged upon standard account deletion. | Mandatory compliance under Indian Income Tax Act, 1961, Companies Act, 2013, and CGST Act, 2017. |
| System Security & Audit Logs | IP addresses, login timestamps, API call traces, rate-limit logs, error traces. | Retained on rolling basis for Security-log retention (e.g. 180 days). | Automatically overwritten or purged. | Information Security, cyber threat tracking, and compliance with CERT-In cyber incident reporting directions. |
| Customer Support Chats & Tickets | Inbound support messages, grievance emails, technical troubleshooting threads. | Retained for Support-ticket retention (e.g. 2 years) from resolution date. | Purged after retention window expires. | Quality assurance, contract dispute resolution, and defending legal claims. |
3. Account deletion workflow
3.1. User-Initiated Deletion: A Customer may submit an account deletion request via:
(a) The web dashboard settings page; or
(b) An email sent from their registered address to Privacy / grievance email.
3.2. Identity Verification: To prevent malicious deletions, Invoizify will verify your identity via an OTP (One-Time Password) sent to your registered WhatsApp mobile number.
3.3. Execution Phase: Upon verification:
- Your account status is marked as “Deactivated” immediately.
- A Deletion grace period (e.g. 14-day grace period) may apply during which you can cancel accidental deletion.
- Following the grace period, our automated deletion pipeline executes: database records are stripped of identifiers, document storage volumes are purged, and backups cycle out naturally according to their rolling retention schedule (typically Backup roll-off (e.g. 30 days)).
3.4. Irreversible Anonymization: Where operational logs cannot be excised without breaking database referential integrity, records are permanently anonymized such that they cannot be re-linked to any natural person or specific business entity.