Data Retention and Disposal Policy
Key points:
- NextiaTax keeps personal and business information only as long as needed for the purposes it was collected, or as required by law.
- Retention periods are defined per data category and enforced through the product, our cloud configuration, and operational procedures.
- When data is deleted it is removed from active systems and then ages out of encrypted backups on a rolling cycle.
- Bank-connection data obtained through Plaid is retained only while a connection is active and is purged after disconnection.
- This policy is reviewed at least annually and whenever our practices, providers, or legal obligations change.
1. Purpose
This Data Retention and Disposal Policy states how Nextia AI (“Nextia,” “NextiaTax,” “we,” “us,” or “our”) retains, and securely disposes of, the personal and business information it processes in operating the NextiaTax service. It is a defined, enforced policy intended to comply with applicable Canadian data-protection law, including the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and substantially similar provincial laws in Alberta, British Columbia, and Quebec.
2. Scope
This policy applies to all data NextiaTax controls or processes across the web and mobile applications, supporting databases, file storage, message queues, logs, and backups, and to the service providers listed on our Sub-processors page that process data on our behalf. It covers customer account and identity data, business and bookkeeping records, document and AI-processing data, billing data, bank-connection data, support communications, and technical and security logs.
3. Retention principles
- Purpose limitation. We retain information only as long as reasonably necessary for the purpose it was collected, to provide the service, or to meet a legal, tax, audit, security, or dispute-resolution obligation.
- Data minimization. We avoid keeping information longer than needed and prefer deletion or de-identification once a retention period ends.
- Enforceability. Retention rules are enforced through application logic, cloud-platform lifecycle configuration, and documented operational procedures rather than left to individual discretion.
- Accountability. The privacy lead is responsible for this policy and for confirming that retention and disposal are carried out as described.
4. Retention schedule
The periods below are default retention targets. Specific records may be kept longer where a legal hold, active dispute, fraud investigation, or statutory obligation applies, or shorter where a customer validly requests deletion and no obligation requires retention.
| Data category | Retention | Disposal trigger |
|---|---|---|
| Account & identity data (name, email, roles, workspace membership) | Life of the account, then up to 90 days after closure | Account closure or verified deletion request |
| Business & bookkeeping records (receipts, invoices, transactions, categories, notes) | Life of the account; individual items removed on deletion | Item deletion, account closure, or verified deletion request |
| Document & AI-processing data (uploaded files, extracted text and fields, assistant questions and answers) | Tied to the underlying record; removed when the record is deleted | Record deletion or account closure |
| Billing & tax records (invoices, subscription and payment metadata) | Up to 6 years, consistent with Canadian tax record-keeping requirements | Expiry of the statutory record-keeping period |
| Bank-connection data (institution and account identifiers, transactions, encrypted access token) | Only while the connection is active; purged after disconnection | Connection removed, account closure, or consent withdrawn |
| Support & communication records | Up to 24 months after the interaction | Expiry of the retention window |
| Technical, audit & security logs | Up to 24 months | Expiry of the retention window |
| Encrypted backups | Rolling cycle of up to 90 days | Automatic expiry as the backup ages out |
5. Deletion and disposal
Deleting an item in the product first marks it as deleted and then permanently removes it from active systems. Because business records may be shared with other members of a workspace, account-deletion requests are reviewed so that another member’s data, or information we must retain for audit, tax, or legal reasons, is preserved or de-identified rather than exposed or improperly destroyed.
We use disposal methods appropriate to the storage medium, including logical deletion from databases and object storage, cryptographic erasure for encrypted stores where supported, and revocation of third-party credentials. When a bank connection is removed, the encrypted provider access token is invalidated and the associated data is purged. Data held in encrypted backups is not individually editable; it is rendered unrecoverable as those backups expire on their rolling retention cycle.
Our cloud provider (Microsoft Azure) performs secure media sanitization and decommissioning for the underlying storage hardware in accordance with its published practices.
6. Legal holds
Where litigation, a regulatory request, a lawful order, or an active investigation requires it, we may suspend routine disposal and preserve specific information for as long as necessary. Once the hold is lifted, the affected data returns to its normal retention schedule.
7. Third parties and sub-processors
Service providers that process data on our behalf are engaged under contracts that require appropriate safeguards and deletion or return of data at the end of the engagement. Providers such as Microsoft Entra (identity), Stripe (payments), and Plaid (bank connections) maintain their own retention practices for the data they hold as part of their service; our current providers are listed on the Sub-processors page.
8. Customer rights
Subject to applicable law and identity verification, customers may request access to, correction of, export of, or deletion of personal information, and may withdraw consent for optional processing, as described in our Privacy Policy. Some requests may be limited by another person’s privacy, shared-workspace rights, technical feasibility, or a retention obligation described above.
9. Review
This policy is reviewed and, where necessary, updated at least once a year, and also whenever there is a material change to our systems, service providers, or legal obligations. The date above reflects the most recent review.
10. Contact
Questions about data retention or disposal, or requests relating to your information, can be sent to [email protected].