Data Governance
Data Retention Policy
Retention principles for account data, tenant configuration, call metadata, recordings, transcripts, logs, and clickwrap evidence.
Last updated May 31, 2026
Status: Draft for legal and security review Document key: dataRetentionPolicy Version: 2026-05-31
This policy describes intended retention categories for Happy Light AI. Final retention periods should be confirmed by counsel and reflected in backend configuration.
1. Principles
- Keep data only as long as needed for service, support, billing, legal, security, compliance, or contractual purposes.
- Avoid retaining PHI in public, referral, or marketing systems.
- Retain audit and clickwrap evidence long enough to support legal and compliance obligations.
- Support tenant-level retention configuration where feasible.
2. Suggested Retention Categories
| Data Category | Suggested Retention | Notes |
|---|---|---|
| Tenant configuration | Life of account plus legal retention period | Includes schedule, insurance, billing settings, team permissions |
| Call metadata | Tenant-configurable, default to operational need | Should remain tenant/branch scoped |
| Call recordings | Tenant-configurable | Store privately; protected proxy access only |
| Transcripts and summaries | Tenant-configurable | Avoid use in public analytics or model training |
| AI provider processing buffers | Provider-controlled ephemeral handling for approved workloads | OpenAI eligible API workloads should use the executed BAA and activated Zero Data Retention posture; Happy Light should not rely on provider-side retained call content as a system of record |
| Audit logs | Long-term compliance retention | Avoid raw secrets and unnecessary PHI |
| Clickwrap evidence | Long-term legal retention | Store document key, version, hash, acceptedAt, user, tenant |
| Billing records | According to tax/accounting requirements | Stripe remains payment processor source |
| Referral records | According to payout/tax requirements | Needed for commission history and disputes |
| Support tickets | Operational/legal retention period | PHI should be scrubbed unless secure support process applies |
| Public website analytics | Short business retention | No PHI |
| Raw secrets | Until rotated or revoked | Store only in Secret Manager or approved secret store |
3. Deletion and Return
Upon termination, Happy Light Tech should return or delete customer data according to contract, BAA, legal requirements, and technical feasibility. If deletion is not feasible, remaining data should continue to be protected and used only for the purpose that prevents deletion.
4. Backups
Backups may retain data temporarily after deletion from active systems. Backup retention should be documented, access-controlled, and protected.
5. Legal Hold
Data subject to legal hold, dispute, security investigation, audit, payment dispute, or regulatory obligation may be retained beyond standard periods.
6. Review
Retention settings should be reviewed before production launch and whenever recording, transcript, support, or audit behavior changes.
