Retention and Deletion Policy
This page is provided for convenience and may be updated over time.
Retention and Deletion Policy
Effective date: Aug 10, 2026
This policy describes the retention approach for personal data processed by Lingonberry Island Ltd. in connection with the business-to-business Service. The Privacy Notice explains the applicable purposes, legal bases, and data-subject rights.
1. Customer Content in a Workspace
- While a subscription is active, Customer Content is retained as needed to provide the Service and follow Customer's instructions.
- After access ends, Customer has 30 days to request or complete an available export.
- Unless Customer gives another lawful instruction, deletion begins after the export window and is completed from active systems within 90 days after termination.
- A legal duty, legal hold, active dispute, security investigation, or agreed instruction may require a different period.
- Deleted data may remain in access-restricted backups until the applicable backup expires or is overwritten. If a backup is restored, the deletion rule is reapplied.
This section applies to Customer Proprietary Data, Customer Modifications, and Tool Outputs. It does not apply to Company Database data for which Company acts as an independent controller.
2. Public-source Company Database
Public URLs submitted in a Public URL Run and the resulting public-source and Company-generated baseline data may be retained in the Company Database after the requesting Customer's subscription ends.
Company Database data is retained and refreshed while relevant to the Service's B2B intelligence, source-traceability, quality, and database-protection purposes. Data is corrected, restricted, invalidated, or removed when it is no longer necessary, source rights require it, or a valid data-protection request requires it.
The Company Database excludes Customer Proprietary Data, Customer Modifications, Tool Outputs, the requesting Customer's identity, and Customer-specific request context.
3. Business accounts and rejected Consumer Users
Account, membership, invitation, and access-review data is retained for the customer relationship and then only as needed for closure, security, legal claims, and compliance.
If a person is rejected or removed because the Service is not available to Consumer Users, associated provisional Customer Content is deleted under the same 30-day export and 90-day active-system deletion limits where an export is appropriate and lawful. We may delete safely removable provisional data sooner after notice. Legal and security records may be retained where required.
4. Company-analysis access intakes
- Unapproved intake records are retained for no more than 30 days after submission, unless a legal hold applies.
- A denied or expired intake loses safely removable private provisional resources, including an intake-owned Workspace, tenant mapping, subscriber placeholder, and prepared suggestion session.
- A pending requester receives no membership or tenant claim and cannot access provisional data.
- After approval, the intake and prepared view become part of the approved account and Workspace records.
- Identity-free public domains separately promoted to Company Database review are no longer part of the identity-linked intake. Their retention follows Section 2.
5. Billing and accounting records
Billing and accounting material is retained for the periods required by Finnish law. The applicable category determines the period. In general:
- vouchers, invoices, transaction correspondence, and related accounting material are retained for at least six years calculated as required by law; and
- financial statements, ledgers, charts of accounts, and specified accounting records are retained for at least ten years from the end of the financial year.
We do not apply a blanket ten-year period to all customer communications or all Workspace content.
6. Logs, audit records, and support
- Security and operational logs are retained for the shortest period reasonably required for security, troubleshooting, reliability, capacity, and claims, taking account of log type, severity, and configured storage capacity.
- Audit records may be kept longer when necessary to investigate misuse, demonstrate authorization, or meet a legal requirement.
- Support and sales communications are retained while needed to handle the matter and then for reasonable relationship, dispute, and legal-record purposes.
- An active incident, legal hold, or authority request may extend a period.
7. AI provider processing
Text and metadata sent to OpenAI is subject to Company's OpenAI account controls and OpenAI's applicable DPA. Under default API controls, certain prompts, responses, and metadata may be retained by OpenAI for up to 30 days unless law requires longer retention. Approved modified-abuse-monitoring or zero-data- retention controls, if configured, may reduce that processing.
Service results selected for persistence are stored in the applicable Company Database or Workspace category; the transient provider copy does not determine the Service's own retention period.
8. Legal holds and deletion verification
Where law or a preserved claim requires retention beyond a normal period, access is restricted to the lawful purpose and the data is deleted when the hold ends.
Customers may contact info@lingonberryisland.com to request reasonable confirmation that required Workspace deletion has been completed. Some retained records may be withheld or described only generally where disclosure would compromise security, another person's rights, or a legal obligation.
9. Customer responsibilities
Customer is responsible for using available export tools within the 30-day window, applying appropriate Workspace retention choices, and deleting data it no longer needs. After final deletion and backup expiration, data cannot be recovered.
10. Viewer trials and accepted Order Forms
A Viewer trial permits analysis starts for 30 days and then retains linked results read-only for 90 days. Without an unresolved accepted Order Form, access then terminates, the export window lasts 30 days, and active-system Customer Content deletion completes within 90 days after termination. During that export window, the existing Viewer identity may access only the closure notice, dedicated export, commercial conversion, session, and logout; it has no ordinary product or result-view capability. The identity is deactivated when the export window ends.
An Order Form in accepted_pending_activation is a cleanup hold. The workspace and results required for validation and activation are not closed or deleted until staff explicitly activates, rejects, or cancels the order. After rejection or cancellation, termination is the later of the original read-only deadline and the resolution timestamp.
The minimal company trial registry may remain after Customer Content deletion to prevent repeated company-funded trials. It contains a normalized company domain and lifecycle timestamps but no UID, email, allowance, or result content. Its final retention period remains a privacy/legal release gate. Accepted-order, accounting, audit, security, and legal-hold evidence follows its applicable separate period; retaining it does not permit continued product access.