Canonical page: https://tellenze.com/legal/retention

# Data retention & deletion

Document version

Version: 2026-10-10.draft-1

How to plan retention, request an export or deletion, and distinguish ending access from removing stored information.

Retention means keeping information for a defined purpose. Deletion means removing information from the systems and copies covered by an instruction. This document explains the decisions needed for Tellenze records and where the current product supports only part of the process.

This is a draft for owner, operational and legal review. Exact production retention periods, complete export arrangements and deletion procedures remain to be confirmed. Version 2026-10-10.draft-1 is a draft date, not an effective date or a new service commitment.

## 1. Keep information for a defined reason

At a glance: A valid purpose sets the retention period; a convenient storage setting does not.

Personal information should be kept only for as long as it is needed for its lawful purpose. A relevant legal duty or claim can justify keeping a limited record longer. Continued storage must have a reason, an end point and appropriate access limits.

A retention schedule should identify the record, its purpose, who decides, when the period starts and what happens at the end. It should also cover revisions, attachments, generated files, logs, provider copies and backups where they contain the same information.

This draft does not approve exact production periods. The earlier statement about keeping affected data for three months after deletion is unverified. It is not a general grace period and must not delay a deletion that the law requires.

## 2. Who decides and who can help

At a glance: Your organisation normally decides about workspace content. The operator handles its own service records and assists with customer requests.

The organisation responsible for a workspace normally decides why personal information goes into its work and how long it is needed. Its authorised contact gives retention, return and deletion instructions under the applicable Data Processing Agreement. A workspace administrator manages access, but must also have the authority needed for an export or deletion instruction.

João Pedro Marques Morais, the Tellenze operator, is responsible for decisions about Tellenze's own website, account-administration, security and business records. The Privacy Policy explains those purposes and privacy roles.

If information about you appears in your employer's, client's or another organisation's workspace, you can ask that organisation or contact general@tellenze.com for help identifying the responsible party. Contacting an administrator first is not a condition that removes your legal rights.

## 3. Record categories and decisions to confirm

At a glance: Each category needs its own trigger, process and approved period.

The table is a review schedule, not a claim that cleanup is already automated. A trigger tells the responsible party when to review a record. It does not by itself set a deletion date or authorise removal of information still needed for a lawful purpose.

The final schedule must replace each unresolved process with an approved procedure and period. It should be checked when a purpose ends, a customer gives an instruction or a relevant feature, provider, contract or legal requirement changes.

| Record category | Purpose | Review trigger | Process to confirm |
| --- | --- | --- | --- |
| Member, account and access records | Identify members and control service access. | Membership ends, an account closes or access is no longer needed. | Separate active access from authorship, security and necessary account records; confirm cleanup and any retained identifiers. |
| Work content, forms, workshops and revisions | Provide the customer's work and knowledge history. | The customer's purpose ends or it requests return, restriction or deletion. | Agree scope and format; cover current records, earlier versions, related content and attachments. |
| Attachments and stored files | Keep files supplied for authorised work. | A file is removed, its parent record is deleted or the service ends. | Confirm active object removal, related records, derived files, storage versions and residual copies. |
| AI conversations, instructions and results | Provide the requested AI-assisted feature and relevant history. | A conversation or source is closed, the purpose ends or deletion is requested. | Confirm saved history, selected files, job records and provider copies; closing a view is not proof of erasure. |
| Agent connections and usage records | Authorise access and record operations or supplied usage evidence. | Access expires, a connection is revoked or the reporting purpose ends. | Separate credential removal from connection metadata, saved work, activity and usage history; approve each category's period. |
| Website, meeting, demo and waitlist records | Handle the requested contact, access or onboarding. | The request closes, a permission is withdrawn or the information becomes inactive. | Review the request and reply history, onboarding context, delivery records and independent consent choices. |
| Consent and marketing suppression records | Show the choice made and respect future contact restrictions. | Permission changes or the relevant communication purpose ends. | Keep only the evidence needed for the lawful purpose; confirm suppression scope and its review period. |
| Email and generated export records | Deliver service messages and provide requested files. | Delivery is resolved, a file reaches its displayed expiry or the service ends. | Confirm receipt and file cleanup separately, including failed jobs, private storage and any provider-held copy. |
| Billing and required business records | Administer the agreed service and meet relevant legal duties. | The service or required recordkeeping purpose ends. | Identify the applicable duty, affected records and period; isolate information kept for a specific claim. |
| Security, audit and diagnostic records | Protect the service and investigate relevant events. | The event is resolved or the justified security purpose ends. | Approve proportionate scope, access and periods; document any specific investigation or hold. |
| Live public-tool rooms | Run the room and show its current contributions. | The room closes or reaches its configured expiry, where set. | Verify cache and session behavior separately from exports, logs, backups and anonymous insight records. |
| Anonymous public-tool insights | Improve supported tools using counts, timing and round statistics. | The improvement purpose changes or anonymity needs reassessment. | Confirm the dataset remains anonymous, including small groups and links to other records; set an appropriate product review policy. |
| Backups and Tellenze-appointed provider copies | Support the agreed service, recovery or provider function. | A deletion instruction is completed, the service ends or a copy reaches its approved expiry. | Confirm provider-specific cleanup, restricted residual storage, restore handling and evidence of completion. |

## 4. Actions that do different things

At a glance: Archiving, ending access and cancelling a plan are different from deleting every stored copy.

Choose the action that matches the outcome you need. Product controls can change visibility or access while leaving work, history or business records in storage. A saved status or a closed page is not evidence that all affected information has been erased.

For a deletion or return request, describe the actual information and copies concerned. The responsible party must assess the request under the applicable agreement and law. An unavailable product control does not remove those obligations.

| Action | What it addresses | What still needs a separate decision |
| --- | --- | --- |
| Archive work | Move work out of normal active use or views. | Whether content, revision history and files should be returned or erased. |
| Remove a member | End that person's workspace access. | Their contributed work, authorship, other records and any personal-information request. |
| Disconnect or revoke an agent | Stop future access through that connection. | Saved Tellenze work, operation history and copies already received by another provider. |
| Cancel a plan | End or change the commercial service under its agreement. | End date, return arrangements, deletion instructions and lawful business records. |
| Delete a record or file | Request or perform removal within the supported scope. | Related content, versions, exports, backups and provider copies. |
| Clear browser storage | Remove selected local cookies, preferences or drafts from that browser. | Server-side records and copies in other browsers, devices or services. |

## 5. Existing exports and the complete-export gap

At a glance: Current exports cover selected information. A complete workspace return needs an agreed scope and process.

The product supports project and team work-item CSV exports. Completed files appear in Your exports in personal settings, with their current expiry. Source access is checked again before download. These files contain the supported work-item fields; they are not a complete archive of documents, conversations, attachments and every earlier version.

Authorised review drafts and editions can be exported as PDF, Markdown or HTML. Accessible attachments have their own download controls. Public retrospective and pre-mortem rooms provide Markdown summaries, and prioritisation workshops provide Markdown or CSV exports while the room is available.

Each export follows the source's access and feature rules. Exported files become copies that the recipient must protect and manage. A withdrawn source, expired file or lost permission can affect later access, so check the relevant export before ending access.

For a complete workspace return or a broader personal-information request, contact the responsible organisation and general@tellenze.com. The parties must agree the data scope, format, secure delivery, retrieval arrangements and any missing categories. No complete workspace export button or automatic account archive is established by this draft.

## 6. How to request access, return or deletion

At a glance: Tell us the outcome you need and enough detail to find the information safely.

Email general@tellenze.com with the relevant workspace or website request, the information concerned and whether you want access, correction, restriction, return or deletion. You do not need legal wording. If you act for an organisation or another person, explain your authority.

We may need proportionate information to confirm your identity, authority or the records concerned. Use an appropriate secure channel for sensitive evidence. Do not send passwords, access tokens or a full identity document in an ordinary email without a justified secure process.

For customer-controlled content, we assist the responsible organisation under the Data Processing Agreement. For our own controller records, the operator assesses the request. A request may concern both kinds of record; the response should make the responsibilities clear.

The General Data Protection Regulation, or GDPR, requires information about action on a rights request without undue delay and within one month. A necessary extension of up to two further months requires reasons and notice during the first month. This response rule is not a promise that every export or deletion completes within one month.

- Identify the workspace, record or contact address involved, where you know it.
- Describe the scope, including attachments or earlier versions if relevant.
- Say whether you need a copy before deletion and how you can receive it securely.
- Tell us about a relevant deadline or risk so it can be assessed.

## 7. Confirm the process before treating deletion as complete

At a glance: A deletion plan needs a verified scope and results; planning controls do not carry out complete workspace deletion.

The agreed process must locate the affected active records, related files, history and operational copies. It must identify which information can be erased, which must be restricted or retained lawfully, and who carries out each step.

The current workspace retirement controls support preparation and review. Complete retirement execution is unavailable. A reviewed plan does not establish that a workspace database, stored files, provider copies or backups have been removed.

A request beyond current product controls needs a confirmed operational procedure and verification. Any completion record should state the scope actually handled and unresolved copies or exceptions. It should not describe a prepared plan, failed operation or unverified cleanup as completed deletion.

Where Article 17 of the GDPR requires erasure, the responsible controller must act without undue delay, subject to applicable exceptions. The absence of an automated button does not create permission to retain information indefinitely.

## 8. Backups and restoration

At a glance: Backups need their own approved period, access restrictions and restore procedure.

A backup may contain an earlier copy of information that has been removed from the active system. The final schedule must identify the relevant backup types, locations, expiry and any lawful residual storage. This draft promises no exact backup period or immediate erasure from every backup.

Residual copies must be protected and limited to the purpose that justifies keeping them. The agreed process must explain how deletion instructions remain effective if a backup is restored, including how completed removals are reapplied.

Operational review must verify that the process runs and produces evidence. A configured expiry or a successful active-system deletion alone does not prove that every backup has expired or been removed.

## 9. Provider copies and files already shared

At a glance: Identify who holds each copy and which agreement or rights request applies.

Tellenze-appointed providers may hold information for email, AI, storage, backup or another agreed service purpose. Their copy handling must follow the applicable processing terms and the confirmed provider-specific procedure. The Subprocessor Register identifies the paths that need review.

A customer's own integration account or an independent recipient can hold a separate copy. This can include information sent to ChatGPT, a mail recipient, an external publishing service or a person who downloaded an export. Disconnecting Tellenze does not send every holder a completed deletion instruction.

Your organisation may need to use the recipient's controls or make a separate request. We remain responsible for the duties that apply to copies under our control and our appointed providers. Contact general@tellenze.com for help identifying the relevant path.

## 10. Required records and legal holds

At a glance: A lawful exception needs a documented reason, limited scope and review.

A legal duty or a specific claim may require certain information to be kept. A legal hold means preserving identified records for that reason. It is not a general preference to keep everything or use it for another purpose.

The responsible party must identify the relevant ground, affected information, authorised access and event that ends the need. Customer data processed on instruction must remain subject to the Data Processing Agreement and the law that applies to that role.

Where lawful and possible, the response should explain what is retained and why. Keep the affected information separate or restricted as appropriate, review the need and remove it when the lawful reason ends under the confirmed procedure.

## 11. Live rooms, anonymous insights and browser copies

At a glance: Room content, tool statistics and local drafts follow different processes.

Public tools keep the live room information needed for participants to work together. Check the room's configured expiry where one is set. Planning poker can allow a room without automatic expiry; closure and cache behavior still affect its availability. The final review must confirm the deployed settings and removal process.

Supported tools also retain separate anonymous room and round insights, such as counts, timing and distributions of revealed votes. These insight records exclude participant names, discussion text and ballots linked to an individual, and can remain after the live room ends. Their anonymous status must be checked in practice, including small groups and possible links to other information.

A room export, infrastructure log or backup is a separate copy. Expiry of a live room does not establish that those copies or the insight records have been deleted.

Some public tools and workspace functions save preferences, draft answers or local state in your browser. The Cookie Notice explains those categories. Clearing relevant browser storage can remove a local copy, but does not delete server-side information or a file already downloaded elsewhere.

## 12. What a useful response should confirm

At a glance: Ask what was handled, what remains and which next action is needed.

A return or deletion response should identify the scope, responsible party, actions completed and evidence available. It should explain any lawful exception, remaining provider or backup process and any separate action needed from the customer or recipient.

If a request is not acted on, the responsible controller must give reasons and explain complaint and court remedies within the applicable legal period. The Privacy Policy explains the rights and complaint route. An unresolved technical process should be made clear rather than presented as a finished outcome.

Contact João Pedro Marques Morais at general@tellenze.com for help with this document or a Tellenze processing path. The final schedule should be reviewed when purposes, product behavior, providers, agreements or legal duties change. Until those details are approved and verified, this remains a draft decision and review document.

## Sources used for this document

- [EDPB: retention and data protection principles](https://www.edpb.europa.eu/sme/find-practical-info/faq_en?page=1)
- [GDPR: rights requests, erasure and processing agreements](https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng)
- [EDPB: individual privacy rights](https://www.edpb.europa.eu/sme/be-compliant/respect-individuals-rights_en)

Contact: general@tellenze.com
