Henex AI Data Retention Policy
Last updated: July 13, 2026
Retention Principle
We keep personal data only for as long as it is reasonably necessary for the purpose for which it was collected, to provide a requested service, or to meet a documented legal, security, accounting, dispute, or audit need. We consider the data's nature and sensitivity, processing purpose, risk of harm, contractual commitments, and applicable limitation and statutory periods.
Active Accounts And Workspace Content
Account, business, product, campaign, creative, connected-platform, and performance records are generally retained while the account or workspace is active so users can operate the service and preserve business history. Customers should not submit personal data that is unnecessary for their marketing workflow.
Security, Audit, And Transaction Records
Authentication events, security records, audit trails, campaign-action receipts, billing records, consent evidence, and incident records may be retained after account closure where needed to prevent fraud, investigate misuse, demonstrate compliance, resolve disputes, enforce agreements, or satisfy tax and other legal duties. Access to retained records is restricted to the relevant purpose.
Operational Security Data
Short-lived verification tokens and database session records are removed in bounded scheduled batches after their expiry and a limited recovery grace period. Expired MFA challenges are retained briefly for security investigation and then removed, while rate-limit buckets are retained for a limited abuse-analysis window. These cleanup jobs do not delete campaign history, billing records, customer assets, or immutable action and audit records.
Deletion And De-Identification
When data is no longer necessary and no lawful reason requires retention, we delete it, render it inaccessible through scheduled system or provider processes, or de-identify it so it can no longer reasonably identify an individual. De-identified aggregate information may be retained for analytics, security, and service reliability.
Backups And Third-Party Systems
Deleted data may remain temporarily in encrypted backups or provider recovery systems until those copies rotate or are securely overwritten. Such data is isolated from ordinary use and restored only for continuity or recovery. Connected advertising platforms and other independent providers apply their own retention policies to data they control.
Legal Holds And Preservation
We may suspend deletion for narrowly scoped records when required by law, a valid preservation request, litigation, an investigation, or the establishment, exercise, or defence of legal claims. A hold does not authorise unrelated use and ends when the preservation duty expires.
Requests And Review
Follow our Data Deletion Instructions or email privacy@henexai.com. We periodically review retention criteria and update operational schedules as systems, risks, and legal requirements change.