Data Retention Policy
- Last updated
- Effective
How long Senitix keeps each kind of data, how we delete or anonymize it, how long backups last, and what happens when a workspace is closed.
1. About this policy
This Data Retention Policy explains how long Senitix keeps the data in and around our service, what starts each retention period, and what happens to the data when the period ends. The periods below are the settings our systems run on as of the effective date. Where a period is a default that your organization can change, we say so.
Senitix is operated by Senitix Teknoloji LTD. ŞTİ., a limited company organized in Türkiye (MERSİS no. 0478-1132-3580-0001), with its registered address at Cevizli Mah. Zuhal Cad. A Blok No:46 İç Kapı No:50, Maltepe, İstanbul, Türkiye (“Senitix,” “we,” “us” or “our”).
1.1 What this policy covers
- The Senitix application, including Senitix CRM, at app.senitix.com and crm.senitix.com (the “Service”), and the workspaces customers create in it.
- Our website, www.senitix.com.
- The records we keep to run our relationship with customers and prospects: user accounts, billing, security logs, and sales and support correspondence.
1.2 Your data and ours
Customer Data is the information your organization and its users put into a workspace or sync into it from a connected service, such as contacts, leads, deals, activities, email, files and notes. Your organization controls Customer Data and decides how long to keep it. We process it on your behalf as a service provider under our Data Processing Addendum (“DPA”). For Customer Data, the periods in this policy describe how the Service behaves and what its default settings are. You can always delete Customer Data sooner, and you can change some of the periods yourself (section 4).
For account, billing, security and website data, Senitix decides how long the data is kept, and the periods in this policy apply as written. Our Privacy Policy explains what personal information we collect, why we collect it and what rights you have.
1.3 How this policy fits with our other terms
This policy supplements our Privacy Policy, our Terms of Service and the DPA. If an order form or data processing agreement signed with your organization sets a different period or deletion commitment, that document controls for your organization.
1.4 Terms we use
- Workspace: the space in the Service that belongs to one customer organization. Some account screens call it an organization.
- Recycle bin: where most deleted records wait before they are permanently deleted. Records in the recycle bin are hidden from normal use and can be restored.
- Permanently delete: remove data from our live systems so that it can no longer be viewed or restored in the Service. Copies can remain in backups until those backups expire (section 6).
- Anonymize: overwrite the details that identify a person so that the remaining record can no longer be linked to that person.
2. How we set retention periods
- Only as long as needed. We keep data for as long as we need it to provide and secure the Service, to meet our legal obligations and to resolve disputes. After that, we permanently delete it or anonymize it.
- A defined starting point. Each period runs from a specific event, such as the day a record is deleted, the day an email is synced or the last message in a conversation.
- Automatic enforcement. Scheduled jobs in the Service remove data whose period has ended. Most of them run every day and a few run every week, so data is normally removed within seven days after its period ends.
- The same rules for every customer. Unless a period is marked as a setting you control, it applies to every workspace, whatever plan it is on.
- Narrow exceptions. A legal obligation or a legal hold can require us to keep specific data longer (section 7). Backups follow their own cycle (section 6).
3. Retention schedule
The tables below list each category of data, how long we keep it and what happens when the period ends. Periods are calendar days or years. “Default” marks a period that your workspace administrators can change (section 4).
3.1 Records and files in your workspace
| Data | How long we keep it | What happens then |
|---|---|---|
| Records in use: contacts, leads, company (account) records, deals, activities, notes, documents, products and price books, reports, custom object records and the files attached to them | For as long as they remain in your workspace | Your users decide when to delete them. Anything still in the workspace is deleted when the workspace is closed (section 8). |
| Deleted records in the recycle bin | 90 days after deletion (default; can be set from 30 days to 7 years) | Permanently deleted, together with the data that belongs to them, such as their notes, files, email addresses, phone numbers and timeline entries. They can be restored until then. A company record that still has contracts, orders or invoices linked to it stays in the recycle bin until those documents reach the end of their own period. |
| Deleted quotes, contracts, orders and invoices | 10 years after deletion | Anonymized: we remove the details that identify a person or company and keep the financial and line-item information for accounting and reporting purposes. Until then they can be restored, but they cannot be permanently deleted by hand. If the workspace is closed, they are permanently deleted, not just anonymized (section 8). |
| Deleted custom objects (the object definition and all of its records) | 15 days after deletion | Permanently erased with all of its records. |
| Deleted files held in storage trash | 90 days after deletion | Permanently deleted from storage. |
| Unfinished uploads (files uploaded but never attached to a record) | 1 day | Deleted automatically. |
| Export files you create (CSV or Excel exports and import error reports) | Up to 30 days after they are created; full-workspace export archives expire after 7 days | Deleted automatically. You can create a new export at any time. |
| Personal-data export files (a copy of one person’s data prepared for an access request) | 30 days after they are created | Deleted automatically. |
| Files you upload for an import | 24 hours after the import finishes | The uploaded file is deleted. The imported records stay in your workspace. |
| Temporary files the Service generates | Up to 180 days after they are created | Deleted automatically. |
3.2 Email, calendar and Senitix AI
Users can connect a mailbox (Gmail, Microsoft Outlook or another provider over IMAP/SMTP) and a calendar (Google Calendar or Microsoft Calendar) to Senitix. Senitix’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The Google user data section of our Privacy Policy explains what we access and why. Data received from Microsoft is kept and deleted under the same rules.
| Data | How long we keep it | What happens then |
|---|---|---|
| Email messages synced from a connected mailbox | 365 days after the message was synced into Senitix | Permanently deleted from Senitix, whatever the mailbox’s sync-depth setting. The original stays in your own mailbox. |
| Email a user moves to the trash in Senitix | 30 days after it was moved to the trash | Permanently deleted. |
| Email from a mailbox that is disconnected | Until the user disconnects the mailbox | We revoke our access to the mailbox and delete the messages synced through it at the same time. |
| Email open and link-click tracking events, where tracking is used | 180 days | Deleted. |
| Calendar events synced from a connected calendar | Stored as activity records in your workspace | Handled like the other records in section 3.1. Disconnecting a calendar stops the sync; activities already created stay until they are deleted. |
| Senitix AI conversation history (the questions asked and the assistant’s answers) | 180 days after the last message in the conversation | Permanently deleted. Senitix AI runs on AWS Bedrock in the EU, and your data is not used to train AI models. |
3.3 History, audit and security records
These records let your administrators and our security team see who did what and when. Deleting a record does not delete the history and audit entries about it. Those entries follow their own periods below, and the workspace-level entries are all deleted when the workspace is closed.
| Data | How long we keep it | What happens then |
|---|---|---|
| Field history (changes to tracked fields, with the old and new values) | 10 years | Deleted. Also deleted when the workspace is closed. |
| Workspace audit log and setup audit trail (who changed what and when, including the IP address used) | 7 years | Deleted. Also deleted when the workspace is closed. |
| Workspace security event log | 7 years | Deleted. Also deleted when the workspace is closed. |
| Approval history | 365 days (default; can be set from 30 days to 10 years) | Deleted. |
| Platform audit logs (sign-ins, account and permission changes and other events across the Senitix platform) | 7 years | Deleted. |
| Audit entries about billing and invoices | 10 years | Deleted. |
3.4 User accounts, sign-in and notifications
| Data | How long we keep it | What happens then |
|---|---|---|
| User accounts (name, email address, phone number, password hash and security settings) | For as long as the account exists | When an account is deleted, sign-in stops at once, and its personal details are anonymized 90 days later. |
| A user’s membership in a workspace, after the user is removed | 365 days after removal | Deleted. |
| Sign-ups whose email address is never verified | 30 days after sign-up, with reminders 7 days and 1 day before | The account and the workspace created with it are deleted, and the personal details are erased (section 8.4). |
| Sign-in attempts, successful and failed, including the IP address used | 30 days | Deleted. |
| Session records | Until the session expires, or 30 days after it was last active, whichever comes first | Deleted. |
| Personal preferences (saved views, saved filters, notification and email digest settings) left behind after a user is removed from a workspace | 365 days after the user is removed | Deleted. |
| In-app notifications | 90 days once read; 180 days if never read | Deleted. |
| Records of your acceptance of our terms and notices (which document, which version and when) | For as long as the account exists, and afterward for as long as we may need to show what was accepted | Deleted when no longer needed for that purpose. |
3.5 Billing and subscription records
| Data | How long we keep it | What happens then |
|---|---|---|
| Subscription, invoice and payment records (plan, amounts, currency, tax details, dates and payment references) | 10 years | Deleted or anonymized. If we must erase personal information sooner, we anonymize the personal details on these records and keep the financial entries (sections 5.3 and 7.1). |
| Payment cards | We do not store full card numbers. A saved card is held by our payment provider, iyzico, and we keep only a reference to it. | When we erase a workspace’s billing data, we also instruct iyzico to delete the stored card. iyzico keeps its own records under its legal obligations. |
3.6 Website, sales and support communications
| Data | How long we keep it | What happens then |
|---|---|---|
| Visits to www.senitix.com | Our hosting logs of requests to the site (IP address, page requested and browser details) are kept for up to 30 days. Cloudflare, our network provider, may also set a strictly necessary security cookie (see our Cookie Policy). | Deleted on a rolling basis. |
Your cookie consent choice (the sx_consent cookie) | 180 days | Deleted when it expires, or sooner if you clear your browser’s cookies. You can change your choice at any time from “Cookie settings” in the footer. |
Your language choice (the sx_lang cookie, set only if you pick a language in the language menu) | 1 year | Deleted when it expires, or sooner if you clear your browser’s cookies or pick another language. |
| Website analytics data (Google Analytics, only for a visitor who accepts the Analytics category) | 14 months from collection, in Google Analytics | Deleted by Google on that cycle. Withdrawing consent stops new analytics data from being collected; see our Cookie Policy. |
| Messages sent through the contact form on our website | The form sends your message to our team by email and keeps no copy on the website. We keep the email for as long as we need it to answer you and to follow up on any business relationship that results. | Deleted when no longer needed for those purposes. |
| Sales and support correspondence (for example, email with support@senitix.com or info@senitix.com) | For as long as needed to resolve the request and to keep a record of our relationship with your organization | Deleted when no longer needed for those purposes. |
| Marketing email preferences | If you opt in to marketing email, we keep your consent while you remain subscribed. If you unsubscribe, we keep a record of that choice for as long as we need it to honor your choice. | Deleted when no longer needed for that purpose. |
3.7 System logs and error reports
| Data | How long we keep it | What happens then |
|---|---|---|
| Application logs | 30 days (14 days for the real-time connection and status services) | Deleted automatically. |
| Load-balancer access logs (IP address and request details) | 30 days | Deleted automatically. |
| Records of failed background tasks | 30 days | Deleted automatically. |
| Internal monitoring logs of background jobs and system events | 30 days | Deleted automatically. |
| Error reports sent to our error-monitoring provider (Sentry, EU region) | For the retention period set for our account with that provider | Deleted by the provider at the end of that period. |
4. Settings you control
Your organization decides how long Customer Data stays in its workspace. The Service gives you these controls:
| Control | Who can use it | Effect on retention |
|---|---|---|
| Data Retention (days), in the workspace’s data management settings | Workspace administrators | Sets how long deleted records stay in the recycle bin. The default is 90 days, and any value from 30 days to 7 years can be chosen; a longer value is applied as 7 years. The setting is applied every day to everything already in the recycle bin, so shortening it permanently deletes records older than the new period at the next daily run. It does not change the 10-year period for quotes, contracts, orders and invoices or the 15-day period for deleted custom objects. |
| Restore from the recycle bin | Users with access to the recycle bin, within the limits of their permissions | Brings a record back, with the data that belongs to it, while it is still in the recycle bin. |
| Permanently delete from the recycle bin | Users with permission to permanently delete records, within the limits of their access | Deletes a record at once instead of at the end of its period. Not available for quotes, contracts, orders and invoices. |
| History Retention (days), in the approval settings | Workspace administrators, where approval processes are used | Sets how long approval history is kept. The default is 365 days, and any value from 30 days to 10 years can be chosen. |
| Disconnect a mailbox or calendar | The user who connected it | Revokes our access. Email synced through a disconnected mailbox is deleted at the same time. |
| Export data | Users with export permission | CSV or Excel exports, full-workspace exports and scheduled exports let you keep your own copy before you delete data or close the workspace. |
| Remove a user | Workspace administrators | Ends the user’s access to the workspace at once. The membership record is kept for 365 days. |
| Close the workspace | The workspace owner | Starts the 30-day closure timeline in section 8. The owner can cancel the closure during the grace period. |
Some periods cannot be changed from inside a workspace: the field history, audit log, setup audit trail and security event log periods, the 365-day limit for synced email, the 180-day limit for Senitix AI conversations and the backup cycle. If your organization needs a different arrangement, contact support@senitix.com. Any change must be agreed in writing.
5. How we delete and anonymize data
5.1 The recycle bin
When a user deletes a record, the Service first marks it as deleted and moves it to the recycle bin instead of erasing it. The record disappears from lists, searches and reports, but it can be restored until its period ends. Email works the same way through the email trash.
5.2 Permanent deletion
- Database records are erased from our production database, together with the data that depends on them. For a contact, for example, that includes its email addresses, phone numbers, notes, files, relationships and timeline entries.
- Files are deleted from every storage location where they may be kept. Our storage keeps the previous version of a deleted or replaced file for 30 days as a safeguard against accidental loss, and then removes it automatically.
- Copies in backups are not edited one by one. They are removed when the backup that contains them expires (section 6).
Our production systems run on Amazon Web Services (AWS) in Frankfurt, Germany (eu-central-1), with disaster-recovery copies in Ireland (eu-west-1). We do not operate our own data centers or storage hardware. AWS decommissions and destroys the physical storage media in its facilities under its own security program.
5.3 Anonymization
Some records have to stay intact after the person they describe is gone, because the law requires us to keep them or because other records depend on them. In those cases we anonymize the personal details instead of deleting the record:
- User accounts. When a deleted account reaches the end of its 90-day period, or when we carry out an erasure, we replace the name, email address, phone number and other identifying details with placeholder values. The record itself remains so that the history linked to it still makes sense.
- Billing records. When we carry out an erasure, we overwrite the personal details on billing records, such as the billing name, the cardholder’s name, IP addresses and payment method details. We keep the amounts, currency, dates and transaction references that accounting and tax records require.
- Audit records. When we carry out an erasure, the entries in our platform audit logs that identify the erased person are de-identified, so the log still shows what happened without showing who did it.
Once information has been anonymized so that it can no longer be linked to a person, it is no longer personal information, and we may keep it.
5.4 Encryption keys
Designated sensitive fields are encrypted with AES-256-GCM using encryption keys specific to each workspace. When a workspace’s data is deleted at closure, the workspace’s encryption keys are deleted as the final step, after the encrypted data itself. For more about how we protect data, see our Security page.
5.5 Copies held by our service providers
Some of our service providers hold personal information as part of the service they provide to us, for example AWS (hosting and backups), Twilio SendGrid (email delivery), Twilio (SMS verification) and iyzico (payments). Our Sub-processors page lists them. Each one keeps data under its contract with us and its own legal obligations. When we carry out an erasure of an account’s personal information, we also send deletion instructions to the providers that hold a copy and accept such requests (for example, we ask iyzico to delete stored cards), and we record any instruction that fails so that we can follow it up.
6. Backups and disaster recovery
We back up the production database and file storage so that we can restore the Service after an incident. We do not use backups to look up or work with individual records in day-to-day operations.
| Backup | When it is taken | How long it is kept |
|---|---|---|
| Daily backup of the database and file storage, in AWS Frankfurt | Every day | 35 days |
| Monthly backup of the database and file storage, in AWS Frankfurt | On the first day of each month | 365 days |
| Disaster-recovery copy of each daily and monthly backup, in AWS Ireland | With each backup | The same as the original: 35 days or 365 days |
| Database point-in-time recovery | Continuously | 7 days |
File storage is also replicated to Ireland as it changes. A deletion reaches the replica too, and previous versions of files there are removed after 30 days.
Backups are encrypted at rest and protected by a lock that stops them from being changed or deleted early, so we do not edit or remove individual items inside a backup. At the end of its period, each backup is deleted automatically and overwritten. This means data deleted from the Service can remain in backups for up to 35 days, or up to 365 days if a monthly backup captured it, before it is gone for good.
If we ever need to restore a backup, we will take reasonable steps to re-apply the deletions made since the backup was taken before the restored data is used again.
7. Legal holds and other exceptions
7.1 Records we are required to keep
Senitix is a company organized in Türkiye and keeps its own financial records under Turkish commercial and tax record-keeping rules. For that reason, and to handle payment disputes and contract claims, we keep subscription, invoice and payment records, and the audit entries about them, for 10 years. This applies even if you close your workspace or ask us to delete your personal information. During that time we use these records only for accounting, tax, audit and dispute purposes, and when we carry out an erasure we anonymize the personal details they contain (section 5.3).
Quotes, contracts, orders and invoices in your workspace are business records of your organization. The Service keeps deleted sales documents in the recycle bin for 10 years so that they cannot be lost through an accidental deletion, but closing the workspace deletes them. Your organization is responsible for keeping any records it is legally required to keep, for example by exporting them before the workspace is closed.
7.2 Legal holds
We may suspend the deletion of specific data, including data whose period has ended and data you have asked us to delete, when we need to keep it:
- because of actual or reasonably anticipated litigation, arbitration or another legal claim;
- to comply with a court order, a subpoena or a binding request from a government or regulatory authority;
- to investigate a security incident, fraud or abuse of the Service; or
- to establish, exercise or defend our legal rights.
A hold covers only the data needed for its purpose, and it overrides this policy, including your settings, only for that data. When the hold ends, the data is deleted or anonymized on the normal schedule, or right away if its period has already passed. If a hold affects Customer Data, we will tell your organization unless the law or the authority involved prohibits us from doing so.
7.3 If you need data preserved
Because your organization controls Customer Data, you can preserve it for your own legal hold: by not deleting it, by extending the recycle-bin period up to 7 years and by exporting it. If you need more than these tools provide, email legal@senitix.com before the data reaches the end of its period. Any special arrangement must be agreed in writing.
8. Canceling, closing a workspace and inactive accounts
8.1 Closing a workspace
Only the workspace owner can close a workspace, and the owner must confirm the request with their password. Any active subscription must be canceled first. Closure then follows this timeline:
| When | What happens |
|---|---|
| Day 0: the owner requests closure | The workspace becomes read-only. Users can still sign in, view data and export it. The owner can cancel the closure at any time during the grace period, and the workspace then returns to normal. |
| Days 1 to 30: grace period | Nothing is deleted. This is the time to export anything your organization wants to keep, including quotes, contracts, orders and invoices. |
| Day 30 | The closure is carried out in the next nightly run. Subscriptions and access tokens are canceled, users can no longer sign in to the workspace, and all Customer Data in the workspace is permanently deleted: records, files, email, Senitix AI conversations, field history, the workspace audit log and security event log, and the workspace’s encryption keys. |
| 90 days after closure | The user accounts of the closed workspace, deactivated at closure, have their personal details anonymized. A person’s accounts in other workspaces are not affected. |
| 365 days after closure | The workspace’s membership records are deleted, and the last monthly backup that can contain the workspace’s data expires. |
| 7 and 10 years after they were created | Platform audit logs (7 years) are deleted, and billing records (10 years) are deleted or anonymized (section 8.3). |
8.2 When a subscription ends or a workspace is suspended
Canceling a paid subscription takes effect at the end of the current billing period; see fees, renewal, cancellation and refunds in our Terms of Service. If a payment fails, we retry it, and after a grace period the workspace may be suspended.
After a cancellation takes effect, or after a suspension, the workspace stays available in read-only mode for up to 30 days so that you can export your data. If the subscription is not reactivated and the suspension is not resolved within that time, we close the workspace, and its data is then deleted as described in section 8.1.
8.3 What we keep after a workspace is closed
- Subscription, invoice and payment records and the audit entries about them, for 10 years (section 7.1).
- Platform audit logs, for 7 years.
- A minimal record that the workspace existed and was deleted, and records showing that any erasure was carried out, for as long as we may need them to demonstrate that we met our obligations.
- Copies in backups, until those backups expire (section 6).
8.4 Inactive workspaces and unfinished sign-ups
Inactive workspaces on the Free plan. If no user signs in to or uses a workspace on the Free plan for 60 days, the workspace is scheduled for closure. We send reminder emails after 30, 45 and 55 days without activity. At 60 days, the workspace’s subscription is canceled and the workspace enters the same 30-day read-only grace period described in section 8.1, during which the owner can cancel the closure. If the owner does not, the workspace’s data is deleted at the end of the grace period, about 90 days after the last activity. This rule does not apply to workspaces on paid plans.
Unfinished sign-ups. If the email address used to sign up is never verified, we send reminders 7 days and 1 day before the deadline. Thirty days after sign-up, the account and the workspace created with it are closed and deleted without a grace period, and the personal details are erased. We keep a record that the sign-up was removed and a record of any terms accepted during sign-up.
8.5 Leaving a workspace or deleting your own account
- A workspace member’s account is managed by the member’s organization. A member who wants the account or their personal data deleted can send a request from within the Service. The request goes to the organization’s administrators, who have 30 days to respond. The request itself does not delete anything.
- A workspace owner can close the workspace, and their own account, from Settings › Security. The 30-day timeline in section 8.1 applies.
- When an administrator removes a user, the user loses access to the workspace at once, and the membership record is deleted 365 days later.
9. Deletion requests
Information Senitix controls. You can ask us to delete personal information that Senitix controls, such as your user account, your billing contact details or your correspondence with us, by emailing privacy@senitix.com. We will verify your identity before we act, and we complete verified requests within 30 days. If a law requires us to keep some of the information, such as billing records, we will tell you what we are keeping and why, and we will anonymize the personal details where we can. Our Privacy Policy describes your privacy rights, including how an authorized agent can make a request for you and how to appeal our decision.
Customer Data. If your information is in a workspace that another organization controls, for example because you are a contact in the CRM of one of our customers, please send your request to that organization. If we receive such a request, we will refer it to the organization, which decides how to respond, and we will help the organization fulfill it as our agreement with it requires.
Backups. Deleted information can remain in backups until those backups expire, as described in section 6.
10. Changes to this policy
We update this policy when our systems, our service providers or our legal obligations change. We will post the updated version on this page and change the “last updated” date. If a change is material, for example if we shorten a period that applies to Customer Data or keep a category of personal information longer, we will notify workspace owners by email or in the Service at least 30 days before the change takes effect, unless the law or the security of the Service requires a shorter period.
This policy is effective as of September 12, 2026, and was last updated on September 12, 2026.
11. Contact us
- Questions about this policy and deletion requests: privacy@senitix.com
- Legal holds, preservation requests and legal notices: legal@senitix.com
- Help with settings, exports, closing a workspace or billing: support@senitix.com
- Postal address: Senitix Teknoloji LTD. ŞTİ., Cevizli Mah. Zuhal Cad. A Blok No:46 İç Kapı No:50, Maltepe, İstanbul, Türkiye
You can also reach us through our contact page. Our company information page lists our registration details.
