We retain only what has a clear purpose
Retention is reviewed by record type, operational purpose, Company obligation, and any applicable legal or contractual requirement.
Account identity and sessions
The active account identity, sessions, device tokens, recovery tokens, and personal notification receipts are removed when account deletion completes. Assistant history stays in app memory for no more than six turns and is cleared on logout, Company switch, and app restart. Multazim stores no assistant transcript or provider context cache.
Company documents and records
These remain while the Company is subscribed or has a legitimate compliance purpose. When that purpose ends, they are deleted or anonymized unless law, contract, or an active dispute requires retention.
Audit record
This is kept for the minimum period needed to evidence legitimate actions and the integrity of the Company record. After account deletion, events point to a closed, non-login identity without the active name or email.
Public deletion requests
Verification links expire after 30 minutes. The encrypted email copy is removed when deletion completes. Incomplete requests are reviewed regularly and deleted or anonymized when the operational need ends.
Decision criteria
We review purpose, Company status, open cases or disputes, evidence requirements, and legal or contractual obligations. Personal data is not retained merely because it might be useful later.