Policy

Data Retention Policy

Version 1.0 · Last updated: May 20, 2026

Owner: Security Lead and Privacy Lead · Reviewed annually

Purpose and scope

This policy describes how long Nexma retains data processed through the platform, how data is deleted when retention ends, and how customers can request deletion under applicable privacy law.

It applies to all customer data stored in Nexma production systems, including the Codex, conversation history, audit logs, and operational metadata.

Customer data categories

Different categories of data serve different purposes and are retained for different periods:

  • Project and Codex dataSpatial datasets, schemas, project files, and uploads. The product Codex is the system of record for these assets.
  • Codex historyVersioned snapshots and branches of Codex files used for time-travel and recovery.
  • Conversation historyJax chat history within a project — prompts, model responses, and tool invocations.
  • Audit logsRecords of security-relevant events: authentication, administrative changes, privileged access, and data export.
  • Support recordsInbound support correspondence and the metadata needed to handle and follow up on support requests.
  • Marketing and contact dataContact-form submissions, sales inquiries, and newsletter subscriptions.

Default retention periods

Unless a customer agreement specifies otherwise, the following default retention periods apply:

CategoryDefault retention
Project and Codex dataLifetime of the customer relationship plus 90 days after termination, then deleted.
Codex history (snapshots, branches)Bound to the parent project — deleted with the project after the 90-day post-termination window.
Conversation history1 year from creation, then deleted. Customers can request earlier deletion.
Audit logs7 years from creation — required for security investigation and contractual obligations.
Support records3 years from last activity on the ticket.
Marketing and contact data2 years from last engagement, then deleted or anonymized.
BackupsEncrypted backups retained for up to 30 days, then automatically purged on a rolling schedule.

Deletion process

When a retention period ends, data is deleted from active systems through automated jobs that run on a defined cadence. Deletion is logged so that the deletion itself is auditable.

Deleted data is removed from production storage and remains in backups only until the backup retention window expires.

Soft and hard deletion

Some data — primarily projects — is soft-deleted first, allowing recovery during the 90-day post-termination window. After that window, hard deletion removes the data from active systems entirely. Hard deletion is the default for shorter-retention categories such as conversation history.

Customer-initiated deletion

Customers can delete projects, Codex files, and conversations from within the Nexma product at any time. These actions trigger the standard deletion process described above.

Where applicable privacy law grants a right to erasure (for example, GDPR Article 17), data subjects may request deletion of their personal data. Where Nexma acts as a processor, requests are routed through the customer (controller); where Nexma acts as a controller, requests are handled directly.

Requests can be sent to legal@nexma.ai.

Backup retention

Backups exist for disaster recovery and are encrypted at rest. Backup retention windows are short and bounded; once an item is deleted from active systems, it is purged from backups on the rolling backup schedule.

Nexma does not restore individual deleted items from backups except as part of a documented disaster-recovery event.

Contact

Questions about data retention, or requests to delete personal data, can be sent to the privacy team.

Email: legal@nexma.ai