Data Retention Policy

Data Retention Policy

Effective date: May 22, 2026
Last reviewed: August 23, 2026

Policy owner: Security and Privacy
Entity: Pacific Apps, Inc., provider of iDialogue
Contact: support@idialogue.app

Purpose

This policy establishes requirements for retaining and deleting data used to provide iDialogue. Retention is determined by data class, product feature, customer agreement, provider configuration, and applicable operational, legal, and financial requirements.

Retention principles

  • Retain data only for a defined service, security, contractual, financial, or legal purpose.
  • Determine retention based on the applicable data class, feature, customer agreement, and provider configuration.
  • Restrict access to retained data according to role and operational need.
  • Support verified customer deletion and export requests within contractual, legal, and technical boundaries.
  • Document retention exceptions, including legal holds, security investigations, fraud prevention, disputes, backups, tax, and financial records.

Data classes

Data class Retention and lifecycle considerations
Dialogue history and approved context Retained when needed to provide dialogue continuity, review, support, usage reconciliation, and other agreed purposes
Task inputs Processed for the requested document, OCR, image, or transactional task without being added to dialogue history; retained only when needed for that workflow or another stated operational, contractual, or legal purpose
Repository files and generated artifacts Retained when requested or configured for secure storage, delivery, retrieval, publication, or contractual obligations
Experience and Room content Retained when required for customer review, forms, checklists, uploads, invitations, membership, document sharing, eSignature, activity history, support, or contractual obligations. Approved customer input or completed outcomes may also be written to Salesforce through the configured workflow
Business outcomes Records created or updated through an approved transaction follow the lifecycle of the applicable customer system and workflow
Indexed knowledge Retained while the relevant knowledge source or customer account remains active, subject to applicable deletion workflows and contract terms
Operational and security logs Retained according to incident response, reliability, fraud-prevention, legal, and provider requirements
Billing and credit records Retained for accounting, tax, dispute, audit, and contractual requirements
Provider processing records Governed by the applicable provider service, provider account, available controls, and provider contract
Backups Expire according to the applicable backup lifecycle and recovery design rather than immediate deletion from every backup copy

OpenAI data handling

Under the iDialogue-managed OpenAI integration, customer data sent through the OpenAI API is not used to train OpenAI models.

iDialogue may maintain approved conversation context to provide dialogue continuity. This allows users to continue an agent conversation without re-teaching the agent or repeating earlier discussions. Document generation, OCR, image analysis, and transactional work are task-based and do not create conversational memory.

Requested repository files, generated artifacts, and operational records are separate data classes with their own purposes and lifecycles. Provider application state used to retrieve, continue, monitor, or complete an API operation is separate from model training and from iDialogue dialogue, repository, Experience, Room, operational, and billing records. Other provider processing records are governed by the applicable provider service, provider account, available controls, and contractual terms. A customer-provided OpenAI key places provider-level administration with the customer but does not by itself change iDialogue's workflow, dialogue, repository, or operational-record lifecycles.

See AI & Agent Governance, the OpenAI Connection guide, and OpenAI's official data controls.

Experiences and Document Rooms

iDialogue Experiences and Document Rooms support customer-facing review and collaboration. They can contain documents, uploaded files, forms, checklists, member records, activity, review decisions, and eSignature records.

A configured workflow may write approved customer-provided information or completed outcomes to Salesforce. Once written, the Salesforce copy follows the customer's Salesforce access and retention policies. The iDialogue Experience, Room activity, and repository artifacts follow their applicable iDialogue lifecycle and customer agreement.

Documents shared for review or eSignature may remain available in the Room until the Room is archived, access is revoked, the customer agreement requires removal, or another documented lifecycle event applies.

Account and service lifecycle

Retention requirements can change when a feature is disabled, a customer account is terminated, or a verified deletion request is received. Data that is no longer required for an active service purpose is subject to the applicable deletion process.

Ending a Room or Experience may require archiving the workspace, revoking member access, preserving or deleting shared documents, resolving active eSignature steps, and determining whether related Salesforce records or attachments remain subject to the customer's own retention policy.

Legal obligations, security investigations, unresolved disputes, active sharing workflows, provider processing records, backups, and financial records may require separate treatment.

Deletion process

A verified deletion request may require coordinated action across:

  1. the source Salesforce record or File, including Salesforce writeback or attachments created from the workflow;
  2. dialogue history and approved conversation context;
  3. repository files, generated artifacts, Experience and Room content, forms, checklists, uploads, shared documents, eSignature state, member and activity records, or indexed knowledge;
  4. provider processing records or uploaded files;
  5. operational and security logs; and
  6. backups and financial records.

Pacific Apps validates the requestor's authorization, identifies in-scope systems and data classes, records applicable exceptions, performs or schedules supported deletion, and communicates material limitations.

Immediate physical removal from every backup is not guaranteed. Deleted data may remain in protected backup media until the applicable backup expires or is overwritten.

Review and exceptions

New features and processing providers must identify the data classes they create or receive, the processing purpose, expected lifecycle, deletion method, and responsible owner before production use.

Exceptions require documented justification, approval, compensating controls where applicable, and periodic reassessment.

Related information

Generated 2026-09-04T22:14:56.301451Z
iDialogue Agent

Ask about this page, related knowledge or specific iDialogue product and support features.