Data Retention & Protection Policy
Effective as of August 24, 2026
1. Introduction
This Policy provides for the systematic review, retention and destruction of documents received or created by Day AI in connection with the transaction of its business. This Policy covers all records and documents, regardless of physical form (including electronic documents), contains guidelines for how long certain documents should be kept and how records should be destroyed. The Policy is designed to ensure compliance with federal and state laws and regulations, to eliminate accidental or innocent destruction of records and to facilitate Day AI’s operations by promoting efficiency and freeing up valuable storage space. This Policy covers all data processed or in Day AI’s custody or control in whatever medium such data is contained in, including cloud hosted databases and static file storage.
2. Definitions
A. “Anonymisation” is the process of turning Data into a form which does not identify individuals. It is a type of information sanitization whose intent is privacy protection.
B. “Archiving” is the process of moving Data that is no longer actively used to a separate storage device or location for retention.
C. “Data” is Record and Document.
D. “Destruction” is defined as physical or technical destruction sufficient to render the information contained in the Document irretrievable by ordinary commercially available means.
E. “Document” as used in this Policy, is any medium which holds Information used to support an effective and efficient organizational operation.
F. “Litigation Hold Order” means a “hold order” issued by the Office of the General Counsel to IT and any relevant division to preserve all information relative to threatened or pending litigation, regulatory action or government order.
G. “Personal Data” (also “Personally Identifiable Information”) is any information relating to an identified or identifiable natural person (the “Data Subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
H. “Record” is any medium which holds information or evidence about a past event.
3. Data Classification
Data shall be classified as follows:A. Public: This information is public information, and can be openly shared on our website, discussed in public and with anyone. Public information as the name implies, is public, and does not require any additional controls when used.
B. Internal: Internal information is company-wide and should be protected with limited controls. Internal information may include the Employee Handbook, various policies and company-wide memos. If disclosed, Internal information has a minimal impact to the business.
C. Confidential: Confidential information is team-wide and its use should be contained within the business. This information may include pricing, marketing materials, or contact information. If disclosed, Confidential information could negatively affect the business and the brand.
D. Restricted: Restricted information is highly sensitive and its use should be limited on a need-to-know basis. Restricted information includes trade secrets and personally identifiable information (PII). If disclosed, there would be a significant financial or legal impact to the business.
4. Data Retention Periods
Data shall be retained for as long as required by the purpose they have been collected for. Therefore:
A. Personal information collected for purposes related to the performance of a contract between you and Day AI shall be retained until such contract has been fully performed.
B. Personal information collected for the purposes of Day AI’s legitimate interests shall be retained as long as needed to fulfill such purposes.
C. Day AI may be allowed to retain personal information for a longer period whenever you have given consent to such processing, as long as such consent is not withdrawn.
D. We may retain the data for a longer period if required for compliance with a legal obligation according to applicable law (e.g., to meet tax or commercial law retention obligations) or to the extent required for establishment, exercise, or defense of legal claims.
E. Once the retention period expires, the applicable personal information shall be deleted. Therefore, the right of access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
F. The retention periods that apply to each category of customer and personal data processed through the Services — including CRM and platform data, meeting recordings and transcriptions, AI-generated summaries, voiceprints where voice identification is enabled, account data, website visitor data and data received from Google APIs — are published in the Storage period section of Day AI’s Privacy Policy, and are incorporated into this Policy by reference. In the event of any inconsistency between this Policy and the Privacy Policy as to a published retention period, the Privacy Policy controls.
G. When data reaches the end of its retention period, or on a customer’s request for deletion, Day AI deletes it within the periods published in the Storage period section of the Privacy Policy, which set out the periods applicable to each category of data and which Day AI may adjust as the Services change. Day AI will not materially extend a published period in a manner adverse to a customer during that customer’s subscription term without at least thirty (30) days’ prior notice. Until deletion from backups is complete, the data remains encrypted, is not processed for any purpose other than secure storage and restoration, and remains subject to this Policy. Day AI retains data beyond these periods only where required by applicable law or under a Litigation Hold Order issued in accordance with section 10.
5. Data Storage and Security
A. Storage Methods
Cloud-Based Storage: All Data is stored in secure and encrypted cloud-hosted databases and static cloud file storage to ensure reliable and scalable storage solutions. Third-party providers are selected against documented evaluation criteria, are assessed for security and data protection before they process any customer data, and are reassessed periodically thereafter. Day AI publishes the subprocessors that store or otherwise process customer data — including its cloud hosting and storage providers — together with the processing each performs and the countries in which it is performed, at day.ai/trust/subprocessors. Customers may subscribe at that page to receive notice of changes to the list, and Day AI gives at least thirty (30) days’ notice before a new subprocessor begins processing customer data. Where a subprocessor must be engaged or replaced on an emergency basis to preserve the security, availability or lawfulness of the Services, Day AI may do so before that period expires and gives notice as soon as reasonably practicable.
B. Access Controls
Employee Access: Access to stored Data is tightly controlled. Employees are granted only the access and permissions necessary to perform their specific job functions. Permissions are periodically reviewed and revoked if no longer needed.
Runtime Processes: All runtime processes are granted permissions using Identity and Access Management (IAM), ensuring that each process only has the minimal necessary permissions to perform its specific tasks.
C. Security Measures
Encryption: All restricted Data is encrypted at rest using industry-standard encryption algorithms. Encryption keys and application secrets are held in a managed secrets store, are not exposed to personnel in plaintext, and are accessible only to the runtime processes that require them.
Access Authentication: IT assets are protected by robust authentication mechanisms, including password protection and biometric security where feasible.
Regular Scanning: IT assets are regularly scanned for viruses and malware and encrypted to enhance protection against unauthorized access.
Monitoring and Logging: Continuous monitoring and logging are implemented to detect any unauthorized access or anomalous activities related to Data storage.
D. Data Handling
Data at Rest: All Data is encrypted at rest using industry-standard algorithms, and encryption keys are managed so that stored Data is not readable in the underlying storage layer. Access to Data in decrypted form through the Services is limited to authorized personnel who require it to provide, secure, support or troubleshoot the Services, or where required by law, and every such access is subject to role-based access controls, logging and confidentiality obligations. Additional restrictions apply to data received from Google APIs, as described in Day AI’s Privacy Policy.
Data in Transit: Secure protocols are utilized for Data transmission, ensuring that Data remains encrypted and protected during transit.
Data Lifecycle Management: Policies are in place to manage the lifecycle of Data, including secure deletion protocols for Data no longer needed.
E. Use Limitations
No Model Training: Day AI does not, and will not, use customer data to train, fine-tune, calibrate, develop or otherwise improve any artificial intelligence or machine learning model. This applies to customer data in every form, including identifiable, pseudonymized, de-identified, anonymized, aggregated and derived forms, and to any output or insight derived from customer data. It applies equally to data received through integrations, including all data received from Google APIs. Day AI contractually requires each third-party AI provider that processes customer data to be bound by the same prohibition, and configures those services so that customer data is not retained or used by the provider for model training.
No Sale or Advertising Use: Day AI does not sell customer data, does not disclose it for cross-context behavioral or targeted advertising, and does not use it for its own marketing.
Purpose Limitation: Customer data is processed only to provide, secure, support and operate the Services, on the customer’s documented instructions, and as required by applicable law. Day AI also creates and uses aggregated and de-identified data for service operation, security, support, analytics and benchmarking, as permitted by its Terms of Use; that data is never used for model training.
F. Security Incident Response and Breach Notification
Incident Response Plan: Day AI maintains a documented incident response plan that assigns roles and responsibilities, defines severity levels and escalation paths, and is reviewed and tested no less than annually.
Customer Notification: Day AI will notify an affected customer of a Security Incident involving that customer’s data without undue delay and in any event no later than seventy-two (72) hours after Day AI becomes aware of the incident. For this purpose, a "Security Incident" is a breach of Day AI’s security leading to the unauthorized acquisition of, access to, use of, or disclosure of customer data on systems controlled by Day AI or by a subprocessor processing customer data on Day AI’s behalf; unsuccessful attempts and activities that do not compromise the security of customer data — such as pings, port scans, denial-of-service attempts and failed log-in attempts — are not Security Incidents.
Contents of Notice: The notice will describe, to the extent then known, the nature of the incident, the data affected, the likely consequences, the measures taken or proposed to address it, and a point of contact for further information. Where that information is not all available within seventy-two (72) hours, Day AI will provide what is available within that period and the remainder in phases as it becomes available, without further undue delay. Day AI will not delay notice on the ground that its investigation is incomplete. Day AI’s notification of, or response to, a Security Incident is not an acknowledgement of fault or liability.
Regulatory Notification and Cooperation: Day AI will notify supervisory authorities and data subjects where required by applicable law, and will cooperate with affected customers in their own investigation, mitigation, remediation and notification obligations. Where personal data subject to the GDPR is involved, the notification obligations in Day AI’s Data Processing Addendum also apply.
Records: Day AI documents each Security Incident, including the facts relating to it, its effects and the remedial action taken.
G. Independent Assurance
Day AI maintains a SOC 2 Type II examination (or an equivalent independent third-party audit) covering the Services and makes its then-current report available to customers on request, subject to confidentiality obligations. Day AI conducts periodic penetration testing and vulnerability assessments and will not materially decrease the overall security of the Services during a customer’s subscription term.
6. Data Archiving
A. All archived Data must be encrypted or locked and continuously safeguarded to avoid data breaches.
B. Electronic Records shall be archived for access controls and in a format which is appropriate to secure the confidentiality, integrity and accessibility of such records. After the archival period has expired, records shall be destroyed in accordance with section 7.
C. If archival is outsourced, the vendor must first be assessed to ensure they comply with the standards set forth in the Day AI Security Policy and appropriate contracts with data protection and information security clauses must be implemented.
D. The possibility that data media used for archiving will wear out shall be considered. If electronic storage media are chosen, any procedures and systems ensuring that the information can be accessed during the retention period (both with respect to the information carrier and the readability of formats) shall also be stored in order to safeguard the information against loss as a result of future technological changes. The responsibility for the storage falls to the IT Manager or equivalent in charge of the storage function.
7. Data Deletion and Disposal
A. Personal Data or confidential or restricted information must be disposed of as confidential waste and be subject to secure electronic deletion or Anonymisation.
B. Some expired or superseded contracts may only warrant in-house shredding.
C. Paper Documents shall be shredded using secure, locked consoles designated in each office from which waste shall be periodically picked up by security screened personnel for disposal.
D. IT shall maintain and enforce a detailed list of approved destruction methods appropriate for each type of information archived whether in physical storage media such as CD-ROMs, DVDs, backup tapes, hard drives, mobile devices, portable drives or in database records or backup files.
E. IT shall fully document and approve the destruction process. The applicable statutory requirements for the destruction of information, particularly requirements under applicable data protection laws, shall be fully observed.
F. The specific deletion or destruction process may be carried out either by an employee or by an internal or external service provider that IT subcontracts for this purpose. All external service providers must be thoroughly vetted and reviewed to ensure their full compliance with data protection requirements, and all data disposal is subject to applicable provisions under relevant data protection laws and the Day AI Security Policy.
G. IT shall verify that deletion/disposal has been carried out correctly.
8. Roles and Responsibilities
A. Each Supervisor is responsible for the Data its department creates, uses, stores, processes and destroys. Each Supervisor shall be responsible for implementing procedures for the retention, Archiving and Destruction of Data in accordance with this Policy, communicating the terms of this Policy to the relevant employees and enforcing compliance. Each Supervisor shall be responsible for submitting exception requests to the process, including consulting and receiving legal advice if necessary to justify making an exception request under section 10.
B. The Office of the General Counsel may audit compliance with this Policy from time to time and provide recommendations to be reviewed by the President of the Company and by the other relevant senior management. The Office of the General Counsel shall provide guidance with regard to this Policy.
C. Each employee shall be responsible for returning Records and Documents in their possession or control to Day AI upon separation or retirement. Final disposition of such Records and Documents shall be determined by the immediate Supervisor in accordance with this Policy.
9. Legal and Regulatory Compliance
Breaches of this Policy may have serious legal and reputation repercussions and could cause material damage to Day AI. Consequently, breaches can potentially lead to disciplinary action that could include summary dismissal and to legal sanctions, including criminal penalties.
All employees are expected to promptly and fully report any breaches of the Policy. A report may be made to the employee’s Supervisor or the General Counsel. Reports made in good faith by someone who has not breached this Policy will not reflect badly on that person or their career at Day AI. Reports may be made using the following e-mail address: privacy@day.ai.
10. Exceptions and Special Cases
A. Exception requests may be made on account of a client requirement, business requirement, legal requirement or vital historical purpose. Exception Request Forms shall be reviewed and approved by the Office of the General Counsel and routed to IT to enforce.
B. Documents for which the Office of the General Counsel has issued a Litigation Hold Order shall be archived, retained and only destroyed as specified by the Office of the General Counsel. A Litigation Hold Order shall appoint a custodian of records and specify a location for storage and review of documentation.
11. Monitoring and Auditing
Documented procedures and evidence of practice should be in place for this operational Policy. Examples of effective organizational management, audit controls, and employee practices include: (i) documented record retention schedules and archival information; (ii) documented encryption and decryption strategies that allow for retrieval of archival electronic records; (iii) regular employee procedures and anecdotal documentation of record management and archival processes; and (iv) direct observation of archival records organization and storage. Ongoing monitoring and periodic auditing processes shall be designed to ensure compliance with this Policy.
12. Training and Awareness
Training and communication plans shall be routinely undertaken in accordance with best practices to ensure understanding and compliance across the organization.
13. Review and Update
Regular review and updating of the Policy shall be undertaken in accordance with best practices to reflect changes in laws, technologies, or business practices.