Legal

Data Retention and Deletion Policy

ANDY PARTNER DATA RETENTION AND DELETION POLICY

1. Introduction

This Data Retention and Deletion Policy explains how Andesphere SpA and Andesphere Ltd. (collectively, the "Provider") retain, delete, anonymize and protect data processed in Andy Partner, including personal data, usage data, messages, files, integrations and operational records.

This policy supplements the Andy Partner Privacy Policy and Terms and Conditions. If there is a conflict, the rule that provides greater protection to the data subject will apply unless an applicable legal obligation requires otherwise.

2. Scope

This policy applies to:

  • User and administrator accounts.
  • Agents, configurations, knowledge bases, messages, files and conversations.
  • User-connected integrations, including WhatsApp Business, Meta, Stripe, Clerk, Convex, PostHog, Sentry and other technical providers used to deliver the Service.
  • Tokens, identifiers, metadata, webhooks and operational logs required to maintain, audit, debug and secure the Service.

3. Retention Principles

The Provider retains data only while there is a legitimate and reasonable purpose, including:

  • Providing and maintaining the Service.
  • Security, abuse prevention, operational continuity and technical debugging.
  • Compliance with legal, tax, accounting, regulatory or contractual obligations.
  • Support requests, audits or dispute resolution.
  • Statistical analysis and Service improvement, preferably using aggregated or anonymized data when possible.

4. Infrastructure and Storage

Andy Partner uses managed infrastructure and service providers, including Convex for application data storage, Vercel for deployment and execution, PostHog for analytics, Clerk for authentication, Stripe for payments and Sentry for error monitoring.

Data may be stored or processed outside Chile. The Provider applies reasonable technical and organizational measures, including access controls, encryption where appropriate, credential separation and operational access limits.

5. Retention by Data Category

Unless a different legal obligation or legitimate operational need applies, the Provider uses the following criteria:

  • Account data: retained while the account is active and for a reasonable period after termination for support, audit, compliance and dispute resolution.
  • Messages, conversations, documents and knowledge bases: retained while the user maintains the corresponding agent, conversation, document or account, unless manually deleted or subject to a valid deletion request.
  • Integration data: account identifiers, numbers, encrypted tokens, webhooks, statuses and metadata are retained while the integration is active. When an integration is disconnected, the Provider deletes or disables operational credentials when they are no longer needed for legal, security or audit obligations.
  • Credentials and tokens: stored encrypted when the Service must retain them to operate an integration. They are not shown back to the user after being saved.
  • Technical and security logs: activity logs, errors, webhooks, delivery events, IP addresses, user agents and technical identifiers may be retained for reasonable periods for security, fraud prevention, debugging, audit and compliance.
  • Billing data: retained for periods required by applicable tax, accounting, contractual and fraud-prevention rules.
  • Anonymized or aggregated data: may be retained indefinitely where it cannot reasonably identify a natural person or specific customer.

6. User Deletion Requests

Users may request deletion of personal data, accounts, agents, documents, conversations or integrations through www.andesphere.com or the official channels available in Andy Partner.

The request must reasonably identify the data subject, affected account and scope of data to be deleted. The Provider may require additional verification before executing the request.

7. Meta and WhatsApp Integration Deletion

For Meta and WhatsApp Business integrations:

  • The user may disconnect the integration from Andy Partner where available or request disconnection through Provider support.
  • When the integration is disconnected or deleted, the Provider will revoke, delete or render unusable operational credentials, including encrypted tokens, when no longer needed.
  • The Provider may retain minimal records for audit, security, billing, compliance or abuse-prevention where there is a legal or contractual basis.
  • WhatsApp messages and metadata linked to an agent or account are deleted or anonymized when the user deletes the agent/account or submits a valid deletion request, unless retention is necessary for law, security or dispute resolution.

8. Response Times

The Provider will attempt to respond to deletion requests within a reasonable time, usually within 30 calendar days after receiving enough information to verify and execute the request. Complex, incomplete, legally sensitive requests or requests involving backups, external providers or disputes may require additional time.

9. Backups and Technical Copies

Data deleted from active systems may temporarily remain in backups, snapshots, caches or technical logs until overwritten, expired or deleted within the normal operating cycles of the relevant provider.

During that period, the Provider keeps that data subject to security controls and avoids restoring it to active systems unless required for operational continuity, security, legal compliance or incident recovery.

10. Exceptions to Deletion

The Provider may reject, limit or defer a deletion request where retention is necessary to:

  • Comply with legal, tax, accounting, regulatory or judicial obligations.
  • Prevent fraud, abuse, spam, unauthorized access or security incidents.
  • Resolve disputes, collect outstanding amounts or enforce contracts.
  • Maintain minimal audit and compliance records.
  • Protect the rights, safety or legitimate interests of the Provider, users or third parties.

11. Contact

For deletion, retention or privacy requests, users may contact the Provider through www.andesphere.com.

12. Governing Law

This policy is governed by the laws of the Republic of Chile. Any dispute will be submitted to the Ordinary Courts of Justice of the city of Puerto Montt, unless mandatory applicable law provides otherwise.