Data Lifecycle Management

Data Retention Policy

Minimizing risks by minimizing data. Here is how we manage, store, and securely dispose of information throughout its lifecycle.

Updated: February 15, 2026
Archive Purge Cycle: 12 Months
Secure Erasure Standard

Data Minimization Principle

Callexa retains personal data only for as long as is strictly necessary to fulfil the purpose for which it was collected, to provide the services you use, and to comply with our legal obligations. When the legitimate purpose of holding any data has expired, that data is securely and irreversibly deleted or anonymized.

No “Just in Case”

Every category of data we process has a defined maximum retention period. If we don't need it, we delete it.

1.

Purpose and Scope

1.1 Purpose of This Policy

This Data Retention Policy ("Policy") establishes the principles, obligations, procedures, and specific retention schedules that govern how Callexa manages the lifecycle of personal data and other information collected through the Callexa mobile application. Data retention is a critical component of responsible data governance. Retaining data for longer than necessary creates unnecessary privacy risks. This Policy strikes the correct balance by defining precisely how long each category of data is held, on what legal or operational basis, and exactly what happens when the retention period expires.

1.2 Scope of Application

This Policy applies to:

  • All categories of personal data and non-personal data processed by Callexa;
  • All storage media: local storage, cloud servers, backup systems, crash reporting tools;
  • All personnel of Inflancer Technologies;
  • All third-party service providers (data processors);
  • Data pertaining to personal users, Business Account holders, and prospective users.

1.3 Relationship to Other Policies

This Policy is part of Callexa's integrated data governance framework and must be read with our Privacy Policy, Terms and Conditions, and Security Policy. In conflicts regarding retention, this Policy takes precedence.

1.4 Applicable Legal Framework

Regulation / FrameworkRelevance
GDPR (EU) 2016/679Storage Limitation principle: data must not be kept longer than necessary.
UK GDPREquivalent UK-law requirement following Brexit.
CCPA / CPRARight to deletion and data minimization for California residents.
COPPAProhibits retention of children's info beyond necessity.
Google Play / Apple StoreSpecific platform retention and deletion guidelines.
2.

Definitions

TermDefinition
Retention PeriodMaximum duration for which data is held before deletion or anonymization.
Retention TriggerEvent from which a retention period begins to count (e.g. account deletion).
Secure DeletionIrreversible removal of data such that it cannot be reconstructed.
AnonymizationIrreversible process so data can no longer be attributed to an individual.
Local DataStored exclusively on user's device, not transmitted to servers.
Server-Side DataTransmitted from the user's device to Callexa's cloud infrastructure.
Purge CycleAutomated schedule for permanent backup deletion.
3.

Core Data Retention Principles

  • Purpose Limitation: Data only retained for specific, legitimate purposes.
  • Storage Limitation: Kept only as long as necessary for processing purposes.
  • Legal Hold: Regulatory override for pending litigation or investigations.
  • Accuracy & Relevance: Outdated, inaccurate data must be deleted.
  • User Control: User's valid deletion requests take priority over convenience.
  • Secure Disposal: Irreversible disposal across all storage environments.
  • Proportionality: Retention periods proportionate to data category risk.
4.

Master Data Retention Schedule

4.1 Local Device Data

Stored exclusively on user's device. No transmission to external servers. Controlled by you.

Data CategoryRetention PeriodBasis & Control
SMS / MMS
Indefinite
User-Controlled deletion.
Call Log
Indefinite
User-Controlled deletion.
Device Contacts
Indefinite
Managed via native Contacts/App.
App SettingsUntil UninstallDeleted on uninstall or data clear.
Message DraftsUntil UninstallLocal storage until send or uninstall.

4.3 Business Account Data (Server-Side)

Data CategoryRetention PeriodControl
Business Profile
Active + 30 days post-deletion
Deleted from public in 24h.
Phone Number(s)
Active + 30 days post-deletion
Removed with profile simultaneously.
Verification DocsStatus + 5 years (min)Encrypted secure storage for audit.
Audit Log7 years from verificationCompliance trail retained for resolution.
Analytics
Indefinite
Anonymized/Aggregated statistics only.

4.4 Technical, Diagnostic, and System Data

Data CategoryRetention PeriodBasis
Crash Reports90 daysAutomatically purged by Firebase.
Performance Logs30 daysSupport for incident diagnosis.
API Request Logs30 daysSecurity monitoring and investigation.
Incident Logs2 yearsSecurity monitor and incident investigation.
Aggregated Analytics
Indefinite
Product development and planning.

4.5 Account, Legal, and Compliance Records

Data CategoryRetention PeriodNotes
Deletion Requests2 years from requestRecord of actions for compliance.
Privacy Rights Logs2 years from requestEvidence of compliance auditing.
Legal HoldsHold + 1 year post-resolutionExempt from normal purge cycles.
Business Contracts7 years from end dateDefense for potential disputes.
Regulatory Disclosures7 years from disclosureInternal compliance audit purposes.
5.

User Control and Self-Service Deletion

5.1 In-App Deletion Tools

Meaningful tools to manage your data directly:

ActionHow to Perform It
Delete SMS ThreadSwipe thread or Thread Menu > Delete Thread.
Clear All MessagesOverflow menu > Delete All (System-wide).
Clear Call HistoryCall Log Menu > Clear Call History.
Account DeletionSettings > Business Account > Delete Account.
Reset All DataDevice Settings > Apps > Callexa > Clear Data.

5.4 Formal Deletion Request

For server-side data (e.g. Business Account), submit a formal request:

  • In-App: Settings > Privacy > Request Data Deletion;
  • Email: privacy@callexa.app from account email;
  • Postal: Inflancer Technologies Attention: Privacy Rights Team.
6.

Data Deletion Procedures

Personal data is marked for deletion in primary systems immediately. Database deletion jobs run on a 24-hour cycle. Images on CDN are cached for 24h and permanently deleted in 7 days. Verification documents follow an enhanced cryptographic overwrite protocol.

24h Job Cycle

Marked data purged within one day.

CDN Clean-up

Media cleared from edge nodes in 7 days.

Audit Ready

Destruction certificates stored for 7 years.

7.

Special Categories and Exceptions

7.1 Legal Hold Procedure

A mandatory suspension of normal deletion for pending litigation or investigation. Hold reviewed every 90 days. Data preserved in isolated environments.

7.4 Mandatory Regulatory Retention

If mandatory law conflicts with our standard periods, legal periods prevail (e.g. 7 years for Tax/Accounting records).Data held in archived restricted access.

8.

Governance and Oversight

8.1 Ownership and Responsibility

Oversight by Chief Privacy Officer, Data Governance Team, Legal Team, and Infrastructure Engineering.

10.

Contact Information

PurposeContact
Retention Inquiriesprivacy@callexa.app
Deletion Requestsprivacy@callexa.app (Subject: Data Deletion Request)
Security Concernssecurity@callexa.app
Website Referencewww.callexa.app/legal/retention

Your Data, Your Control

Callexa is built on transparency. If you have any further questions about our data retention or would like to request an adjustment to your account specifically, our privacy team is standing by.