| Entity | AgentLayer Systems Private Limited (Lever AI) |
| Document owner | Security and Compliance, Lever AI |
| Approved by | Kshitij Arora, Founder, Lever AI |
| Effective date | August 2026 |
| Next review | August 2027 |
| Classification | Public |
1. Purpose
This policy sets out how long Lever AI retains each category of data it holds and how that data is disposed of when its retention period ends. Its aim is that the company keeps data no longer than the engagement, its operations, or the law requires, and that customers can predict exactly what happens to their data and when. It gives effect to the storage-limitation and disposal principles of the Data Protection and Privacy Policy: that policy states retention in principle, this policy carries the authoritative retention schedule, and where the two differ on retention or disposal, this policy prevails. It supports the company's obligations under the GDPR and India's Digital Personal Data Protection Act, 2023.
2. Scope
This policy applies to all Lever AI personnel and to any contractor or third party acting on the company's behalf. It covers all data the company holds in any location: the managed database, blob storage, and application-host working directories in the production cloud environment; application logs and telemetry; backups; source control; work devices; and company business records. Data classes are as defined in the Data Classification Policy.
3. Policy
3.1 Principles
Data is retained only as long as its purpose requires, per the default schedule in section 3.2, unless a customer contract (section 3.3), a legal hold (section 3.6), or a statutory retention requirement provides otherwise. Where law requires longer retention — for example for corporate, tax, or employment records — the statutory period applies to those records. Business correspondence the company holds as a controller in its own right — for example website contact enquiries and the follow-up they generate — is retained as long as needed to handle the enquiry and any follow-up, and is then deleted, subject to the same statutory and legal-hold provisions. When a retention period ends, the data is disposed of by the methods in section 3.7; it is not kept “just in case”.
3.2 Default retention schedule
| Data category | What it covers | Default retention |
|---|---|---|
| Engagement (customer) data | Conversations, administrator chat and agent session transcripts, uploaded requirement documents, and file attachments. | Duration of the engagement plus 90 days, then deleted on schedule. |
| Operational telemetry | The per-interaction usage and cost ledger. | 24 months. |
| Application and audit logs | Application logs and audit-relevant event records, including deployment version stamps. | 12 months. |
| Backups | Managed platform backups of the primary data stores. | Per the managed platform's schedule (the Azure Cosmos DB continuous-backup window); deleted data ages out of backups within that window. |
| Source code | Lever AI source code and configuration in version control. Contains no customer data. | Retained indefinitely. |
3.3 Customer contracts prevail
Where a customer contract or data processing agreement specifies retention or deletion terms for that customer's data, the contract always prevails over the defaults in this policy — whether it requires shorter retention, longer retention, or specific deletion procedures. The agreed terms for each engagement are recorded, and the engagement's data is retained and disposed of on those terms.
3.4 Deletion on customer request and at end of engagement
A customer may request deletion of its data at any time, and engagement data is in any case deleted on schedule after the engagement ends (section 3.2). On a deletion request, the data is deleted from the primary data stores and the deletion is verified — confirmed by checking the stores rather than assumed from the deletion command — within 30 days of the request, and the customer receives written confirmation. Deleted data then ages out of managed backups within the backup window described in section 3.5. Requests from individuals about their personal data are routed through the customer as controller, under the Data Protection and Privacy Policy.
3.5 Backups
Backups of the primary data stores are taken and managed by the cloud platform (Azure Cosmos DB continuous backup); Lever AI does not hold separate backup copies of customer data outside the managed platform. Data deleted from the primary stores ages out of these backups within the platform's backup window and is not retained beyond it. Backups are used only to restore service under the Incident Response and Business Continuity Policy; if a restore resurrects data that had been deleted, that data is deleted again as part of completing the recovery. Data processed by subprocessors is retained under their published terms, which are reviewed under the Vendor and Third-Party Risk Management Policy.
3.6 Legal hold
Where data is, or is reasonably likely to be, required for litigation, a regulatory matter, or an ongoing incident investigation, the Founder may place it under legal hold. Disposal of held data is suspended, the hold and its scope are recorded, and normal retention resumes when the Founder lifts the hold.
3.7 Disposal methods
Disposal is performed by the method appropriate to the medium, and Restricted data is disposed of only by these methods:
- Managed cloud stores — deletion through the provider's deletion operations; sanitisation and destruction of the underlying physical media are inherited from Microsoft Azure's published controls.
- Application-host working files — per-conversation working directories and uploaded files are deleted as part of the engagement-data schedule.
- Work devices — devices must be full-disk encrypted under the Physical Security Policy and must be wiped (cryptographic erase or full factory reset, issued through the MDM where it supports remote wipe) before reuse, transfer, or disposal.
- Removable media — not used for customer data under the Physical Security Policy; any exceptionally approved media is physically destroyed at end of use.
- Credentials and keys — disposed of by revocation and rotation with the issuing system, and removal from the credential stores; deletion of a stored copy alone is not disposal.
- Paper — the company operates remote-first and substantially paperless; any printed material classified Confidential or above is cross-cut shredded.
3.8 Disposal records
End-of-engagement deletions and customer-requested deletions are recorded — what was deleted, when, on whose instruction, and who verified it — and the record is retained as audit evidence. Routine schedule-driven disposal of logs and telemetry does not require individual records.
4. Responsibilities
The Security Owner owns the retention schedule, approves legal holds with the Founder, and is accountable for verified deletion. The Engineering owner implements retention and executes and verifies deletions. The Data Protection lead handles deletion requests that concern personal data and the related customer communication. Every member of staff disposes of data in their care by the methods in this policy. Detailed assignments are set out in the Security Roles and Responsibilities document.
5. Exceptions
Any exception to this policy must be requested in writing, assessed for risk, limited in time, recorded, and approved by the Founder. No exception may extend the retention of customer data beyond the customer's contractual terms without the customer's agreement.
6. Review
This policy is reviewed at least annually and whenever there is a significant change to the business, the data the company holds, applicable law, or customer commitments. The document owner maintains its version history.
Approval and adoption
This policy has been reviewed and approved for adoption by Lever AI. It takes effect from the effective date shown in the document control table above and remains in force until it is reviewed or superseded.
Kshitij Arora
Founder, Lever AI