Data Retention & Disposal Policy

Bizeo.AI · v1.0 · Effective September 5, 2026

Data Retention and Disposal Policy

Bizeo.AI · Version 1.0 · Effective September 5, 2026

1. Purpose and Scope

This Data Retention and Disposal Policy defines how Bizeo.AI collects, stores, retains, and securely disposes of consumer data in compliance with applicable data privacy laws, including the Gramm-Leach-Bliley Act (GLBA), the California Consumer Privacy Act (CCPA), the General Data Protection Regulation (GDPR), and Plaid's data security requirements. This policy applies to all data processed through the Bizeo.AI platform, including data accessed via Plaid Link, and to all employees, contractors, and service providers who handle consumer data.

2. Data Classification

Bizeo.AI classifies consumer data into the following categories: • Financial Account Data: Bank account numbers, routing numbers, transaction data, and balances accessed via Plaid. • Personally Identifiable Information (PII): Names, email addresses, phone numbers, and business identifiers. • Authentication Data: OAuth tokens, API credentials, and session identifiers. • Business Operational Data: Business formation documents, tax filings, and vendor records. • Usage Data: Analytics events, feature usage, and interaction logs. All data is classified according to sensitivity level and retained according to the schedules defined in Section 4.

3. Legal Basis for Data Processing

Bizeo.AI processes consumer data based on the following legal grounds: • Consumer Consent: Obtained explicitly when a user connects a financial account via Plaid Link, with clear disclosure of the data being accessed and its intended use. • Contractual Necessity: Data required to deliver the services the consumer has requested (e.g., financial reporting, business management). • Legal Obligation: Data retained to comply with tax, anti-money laundering (AML), and regulatory record-keeping requirements. • Legitimate Interest: Anonymized, aggregated data used for product improvement and fraud prevention. Consumers may withdraw consent at any time, after which data is processed only for legal retention obligations and then disposed of per Section 5.

4. Data Retention Schedule

The following retention periods apply to each data category: • Financial Account Data (via Plaid): Retained for the duration of the active service relationship plus 90 days for reconciliation, then permanently deleted. Transaction data is retained for 7 years to comply with IRS tax record-keeping requirements (IRC §6001 and Treasury Regulation 1.6001-1). • PII (Name, Email, Phone): Retained for the duration of the active account plus 30 days for account recovery, then deleted unless required for legal hold. • Authentication Data (Tokens, Credentials): Revoked immediately upon account closure or connection termination; access tokens are rotated every 90 days. • Business Operational Data (Formation, Tax, Vendor): Retained for 7 years to satisfy IRS and state regulatory retention requirements, then securely destroyed. • Usage and Analytics Data: Anonymized within 30 days of collection; raw identifiers deleted within 12 months. • Support and Communication Records: Retained for 2 years for quality assurance and dispute resolution, then deleted. • System and Security Logs: Retained for 12 months for incident investigation and audit purposes. • Backups: Encrypted backups retained for 30 days, after which they are overwritten. Backups do not extend the retention period of deleted data.

5. Data Disposal Procedures

When data reaches the end of its retention period or upon consumer request, Bizeo.AI disposes of it using the following secure methods: • Electronic Data: Securely overwritten using cryptographic erasure (AES-256 key destruction) or NIST SP 800-88 Rev.1 media sanitization standards. Deleted data is purged from all production databases, search indexes, caches, and analytics pipelines within 30 days. • Backups: Data excluded from subsequent backup cycles; existing backups overwritten per the 30-day backup retention cycle. • Physical Media: Hard drives and storage media are physically destroyed or degaussed by a certified vendor (NAID AAA-certified) before disposal. • Third-Party Data: Deletion requests are propagated to all subprocessors (Plaid, Stripe, Twilio, cloud infrastructure providers) within 30 days, with written confirmation of deletion retained. A Certificate of Destruction is generated for each disposal event and retained for 3 years.

6. Consumer Rights and Data Deletion Requests

Consumers have the right to request deletion of their data at any time. Bizeo.AI processes deletion requests as follows: • Requests are submitted via the in-app account deletion function or by emailing the privacy contact listed in our Privacy Policy. • Identity is verified before any deletion is processed to prevent unauthorized removal. • Upon verification, all consumer data is deleted within 30 days, except data required to be retained under legal or regulatory obligations (e.g., IRS tax records, AML records). • Consumers receive written confirmation once deletion is complete. • Data subject access requests (DSARs) under CCPA/GDPR are processed within 45 days of receipt. Bizeo.AI does not sell consumer data to third parties under any circumstances.

7. Policy Review and Governance

This policy is reviewed at least annually by the Bizeo.AI security team and updated whenever there is a material change in data processing activities, legal obligations, or Plaid's requirements. The review includes: • Verification that retention schedules remain compliant with current laws and regulations. • Audit of disposal records and certificates of destruction. • Assessment of subprocessor compliance with deletion requirements. • Update of data inventory and classification. The most recent review date and version number are recorded at the top of this document. All material changes are communicated to affected consumers and to Plaid where required.

8. Security Controls

All retained data is protected by the following security controls, as detailed in our Information Security Policy: • Encryption at rest (AES-256) and in transit (TLS 1.3). • Role-based access control (RBAC) with least-privilege enforcement. • Multi-factor authentication (MFA) for all administrative and data-access accounts. • Continuous monitoring and alerting for unauthorized access attempts. • Annual penetration testing and quarterly vulnerability scans. • Incident response procedures with 72-hour breach notification to affected consumers and Plaid. • SOC 2 Type II controls maintained and audited annually.

9. Contact

Questions regarding this Data Retention and Disposal Policy should be directed to the Bizeo.AI security team through the contact information provided in our Privacy Policy at https://bizeo-ai.base44.app/privacy.

Click "Download PDF" above to save this document for compliance submissions.