Data Retention Policy
Last Updated: September 18, 2025
1. Purpose
This policy outlines how Qualtiva retains and deletes customer data across its cloud subscription services, including analytiQa and integrated systems. It ensures privacy, transparency, and compliance while promoting responsible resource usage.
2. Scope
Applies to all customer-generated and system-derived data stored, processed, or transmitted by Qualtiva during and after the subscription period. Coverage includes:
- For analytiQa platform: Insights data, diagnostic events, dashboard visualizations and metrics
- Email, access credentials, and contact form data
- API usage statistics and project metadata
3. Fair-Use Data Storage
To maintain performance and equitable service delivery, each customer is subject to a 10GB fair-use data cap across their dedicated tenant:
- Applies to cumulative data, including logs, dashboards, visualizations, snapshots, and email records.
- Customers will receive proactive alerts upon reaching 80% and 100% of their cap.
- Optional premium tiers are available for expanded storage needs.
4. Retention Timeline
| Data Category | Retention Duration | Description | 
|---|---|---|
| Active Subscription | 36-months (can be increased on request) | Full access to all features and data | 
| Backup \ Snapshots | 1-year | Daily for 2-week cadence Then monthly | 
| Subscription Cancellation | 30 days post-cancellation | Grace period for data export | 
| Post-30-Day Window | Permanent deletion | Secure purge across production and backup systems | 
5. Data Deletion Process
- Data is securely erased using automated scripts and validated purging protocols.
- Personally identifiable information (PII) is scrubbed in accordance with privacy regulations (e.g., GDPR).
- Data under legal hold is retained until the matter is resolved.
6. Pre-Deletion Notification
- Customers are notified 7 days in advance of any irreversible deletion.
- Notifications include instructions for exporting data and available support options.
7. Encryption & Access Control
- Encryption protocols: TLS 1.3 (transit), AES-256 (at rest).
- Role-based access control (RBAC) restricts data visibility to authorized users.
- Each tenant operates in isolated environments to prevent cross-contamination.
8. Exceptions & Compliance
- Legal disputes, audits, or regulatory obligations (e.g., HIPAA, GDPR, CDR) may override standard retention timelines.
- Extended storage options are available upon request for compliance-sensitive data.
9. Policy Review
This policy will be re-evaluated annually or upon substantial changes to technologies, services, or legal frameworks.
10. Contact Us
If you have any questions, please contact us at:
Email: admin[at]qualtiva.solutions Company: Qualtiva Pty Ltd
