Keldio Data Retention and Erasure Policy
Document version: 2026-09-29 Last updated: 29 September 2026 Effective date: 29 September 2026
This Data Retention and Erasure Policy explains how long Keldio keeps personal data, how Keldio handles requests to erase personal data, and when Keldio must or may keep data for longer, for example under a legal hold or the Dutch 7-year retention obligation for accounting records.
It supplements the Keldio Privacy Policy, for personal data that Keldio controls, and the Keldio Data Processing Agreement ("DPA"), for personal data that Keldio processes on behalf of its customers. Capitalised terms have the meaning given in the Platform Terms of Service and the DPA.
1. Two roles, two sets of rules
Keldio handles personal data in two different roles:
- Keldio as controller. Keldio decides how long it keeps personal data about website visitors, people who contact Keldio, Keldio's own leads and marketing contacts, and Tenants, Admin Users, and account owners in their relationship with Keldio (account, billing, support, security, and legal records). Section 3 sets out the retention periods for this data.
- Keldio as processor. When a Tenant uses Keldio to store or process personal data about its own contacts, customers, members, and other End-Users, the Tenant is the controller and decides how long that data is kept. Keldio keeps and deletes that data on the Tenant's instructions, as described in section 4 and the DPA.
2. General principles
- Keldio keeps personal data only for as long as it is needed for the purpose for which it was collected, or for as long as the law requires or allows Keldio to keep it.
- The periods in section 3 are maximum periods. Keldio may delete data earlier where it is no longer needed.
- A longer period applies where a legal obligation, a pending or reasonably anticipated legal claim, or a legal hold requires it (section 6).
- When a retention period ends, Keldio deletes the data or anonymises it so that it can no longer be linked to a person. Aggregated and anonymised statistics may be kept.
- Some periods are enforced automatically. For example, agent invocation logs and agent or MCP connection-attempt receipts are deleted automatically after 90 days. Other periods are applied by periodic review and deletion. Keldio reviews retained data against this policy at least once a year.
- Deleted data can remain in backups until the backup expires on the normal rolling backup cycle (usually within 30 days). Keldio does not restore deleted personal data from backups except to recover from an incident, and then re-applies deletions.
3. Retention periods: data that Keldio controls
| Category of data | Examples | Retention period | Main reason |
|---|---|---|---|
| Enquiries and contact-form submissions from people who do not become customers | Name, email address, company, message content | 2 years after the last contact | Responding to and following up on the enquiry |
| Keldio's own marketing contacts and leads | Email address, name, source, subscription status, engagement with Keldio emails | Until you unsubscribe, or 2 years after your last interaction with Keldio's emails, website, or offers, whichever is earlier | Consent or legitimate interest in direct marketing |
| Opt-out and suppression records | Email address or a hashed identifier, opt-out date and channel | As long as needed to make sure Keldio does not contact you again | Respecting your objection and legal obligations |
| Proof of consent and opt-out | Consent and opt-out events, the text or source of the consent | For as long as Keldio relies on the consent, and 5 years after that | Demonstrating consent (Article 7(1) GDPR) and defending claims |
| Customer account and Workspace administration | Owner and Admin User identity, Workspace settings, plan, trial and subscription state, team invitations | For the duration of the customer relationship; afterwards as described in section 4.3, except where another row applies | Performing the contract |
| Billing, orders, invoices, and payments | Orders, invoices, credit notes, subscriptions, payment plans and installments, coupon redemptions, billing adjustments, payment-provider identifiers | 7 years from the end of the financial year to which the record relates | Dutch tax and accounting law (Article 52 of the General Tax Act (AWR) and Article 2:10 of the Dutch Civil Code) |
| Legal documents and acceptance records | Document versions accepted, acceptance date and method, accepting person and organisation, IP address, user agent, related order or Workspace identifiers, notices and re-acceptance records | For the duration of the customer relationship and 7 years after it ends; longer while a claim or legal hold is pending | Evidencing contract formation and defending legal claims |
| Support conversations with Keldio | Support messages, attachments, diagnostics, Keldio's replies | 2 years after the conversation is closed, unless the conversation is part of a billing record, claim, or security case, in which case that retention period applies | Providing support and managing the customer relationship |
| Security, access, and audit logs | Sign-in and magic-link events, admin and support-access actions, API key metadata, audit-log entries | Up to 2 years, unless needed longer to investigate a security incident or defend a claim | Securing the platform and accounts |
| Agent invocation logs and agent or MCP connection-attempt receipts | Tool calls, outcomes, timestamps, diagnostic results | 90 days (deleted automatically) | Troubleshooting and security |
| Abuse, fraud, enforcement, and provider-risk records | Reports, evidence, decisions, chargeback and dispute records, provider notices | For the duration of the case and 5 years after it is closed; longer while a claim or legal hold is pending | Protecting Keldio, its customers, providers, and the public, and defending claims |
| Onboarding and activation records | Onboarding milestones, guided-mission runs, reminder and welcome-email delivery evidence | For the duration of the customer relationship and up to 12 months after it ends | Providing and improving onboarding |
| Analytics and technical logs for Keldio's own website | Page views, anonymous visitor identifiers, referrers, campaign parameters, IP address, user agent | Up to 26 months after collection | Measuring and securing the website |
| Cookies and similar technologies | Identifiers stored in your browser | As described in the Cookie Policy and your browser settings | See the Cookie Policy |
| Affiliate, referral, and commission records | Commission calculations, holds, payouts, self-billing records | 7 years from the end of the financial year to which the record relates | Dutch tax and accounting law |
4. Customer Personal Data in Workspaces (Keldio as processor)
4.1 The Tenant decides
The Tenant, as controller, decides how long it keeps personal data in its Workspace, and is responsible for telling its End-Users about its own retention periods. Keldio keeps Customer Personal Data for as long as the Tenant keeps it in the Workspace and the agreement is in force, and deletes it on the Tenant's instructions. Keldio provides tools that allow the Tenant to delete contacts and other records itself.
4.2 Technical retention windows
Some technical records are kept for fixed periods regardless of the Tenant's settings, for example agent invocation logs and connection receipts (90 days, deleted automatically), certain webhook and job-processing records used to prevent duplicate processing (for example, 30 days for social publishing webhook and job records), and backups (usually within 30 days on the rolling backup cycle).
Comments that third parties post on content a Tenant published through Keldio, and that Keldio imports into the Tenant's inbox, are kept until the Tenant deletes them or the Workspace is deleted.
4.3 End of the agreement
When the agreement ends, the Tenant has an export window (usually 30 days). After that, Keldio deletes Customer Personal Data from active systems within a further 30 days, and the data then expires from backups on the normal backup cycle. Keldio may keep data after these deadlines only where section 6 or §13.5 of the DPA applies. Section 13 of the DPA governs.
5. Erasure requests
5.1 Requests about data that Keldio controls
You can ask Keldio to erase personal data that Keldio controls by emailing info@keldio.com. Keldio may ask you to verify your identity. Keldio responds within one month of receiving the request. Where a request is complex or Keldio receives many requests, Keldio may extend this by up to two further months and will tell you why within the first month.
Keldio erases the personal data that it no longer needs, and tells you which data it must or may keep, why, and for how long (section 6). Keldio also informs the recipients to whom it disclosed the data, where required and possible.
5.2 Requests about data in a Tenant's Workspace
If you are a contact, customer, member, or other End-User of a Keldio customer, that customer is the controller of your data. Please send your request to that customer. If Keldio receives your request, Keldio forwards it to the customer without undue delay (usually within 5 working days) and assists the customer on the customer's instructions, as set out in the DPA.
5.3 How Keldio carries out an erasure
When Keldio carries out an erasure of a person's data, whether for itself or on a Tenant's instructions, it uses a documented procedure:
- Request record. Keldio records the request, who made it, when, the legal basis, and the version of the procedure applied. To link the steps together, Keldio stores a hashed form of the person's email address, not the address itself.
- Store-by-store plan. Keldio lists every place where the person's data is held and what happens to it:
- deleted: data that exists only because of the person, such as tags, activity timelines, tracking and page-view events, email engagement events, marketing-automation state, campaign membership, lead and event registrations, reminders, community reactions, reviews, shopping carts, correspondence with the person, and course or community access and progress;
- redacted: records that must remain for other people or for business history, such as bookings, webinar chat lines, community posts and replies that others have responded to, and message send records kept for billing and volume counts; the name, contact details, and content are removed;
- kept: records that Keldio or the Tenant must keep by law or as evidence, such as orders, invoices, subscriptions, installments, billing adjustments, coupon redemptions, and commission records (7 years), legal acceptance evidence, and proof of consent and opt-out; where possible, the link to the deleted person record is removed;
- handled outside the database: data held by email and messaging providers in their delivery logs, and files that the person sent or received (such as attachments and uploads). Keldio requests or carries out the deletion and records the reference. Connected systems that subscribe to Keldio events receive a signal that the person was erased, without the person's details. Payment providers keep their own payment records under the same statutory retention obligations.
- Execution and completion. Each step records its own result. The person record itself is deleted only after all other steps in the database have succeeded, so that an interrupted erasure never leaves a partly deleted person. The request is marked complete, with a summary, once every step, including steps outside the database, is done.
5.4 What an erasure does not remove immediately
An erasure does not immediately remove data from backups (which expire on the rolling backup cycle), from provider logs that are subject to the provider's own retention period until the provider completes the deletion, or from data kept under section 6.
6. Legal hold and other exceptions
Keldio keeps personal data for longer than the periods above, or does not erase it on request, only where one of the following applies, and only for the data and period needed:
- Legal obligation. For example, accounting and tax records must be kept for 7 years under Dutch law.
- Legal claims. Data needed to establish, exercise, or defend a legal claim (Article 17(3)(e) GDPR), until the claim is finally resolved or can no longer be brought.
- Legal hold. Where litigation, an investigation by a supervisory or other authority, a court order, or a lawful request from a law-enforcement authority is pending or reasonably anticipated, Keldio suspends deletion of the specific data concerned. Keldio documents the hold, restricts access to the held data, and lifts the hold when it is no longer needed, after which the normal retention periods apply.
- Proof of consent and opt-out. Keldio keeps the records it needs to demonstrate consent and to keep honouring an opt-out.
- Security and abuse. Evidence needed to investigate or respond to a security incident, fraud, or abuse, for the period set out in section 3.
7. Changes and language
Keldio may update this policy when its services, providers, or legal obligations change. The version published on this page applies from the date shown above. Keldio keeps earlier versions. This policy is available in English and Dutch. If the versions differ, the English version prevails to the extent permitted by applicable law.
8. Contact
Questions about this policy and erasure requests for data that Keldio controls can be sent to info@keldio.com. Formal notices can be sent as described in the Platform Terms.