Legal & Compliance

Data Retention & Deletion Policy

This policy describes how SuperSend handles the retention and deletion of personal and business data. SuperSend complies with GDPR Article 5(1)(e), CCPA, and other applicable data protection regulations.

Version: v2025-10
Last Updated: October 20, 2025

1. Data Retention Principles

  • Purpose Limitation
    Data is retained only as long as necessary for the provision of services or to fulfill contractual or legal obligations.
  • Minimization
    Temporary and unnecessary data is deleted or anonymized automatically according to predefined schedules.
  • Security
    All retained data is encrypted at rest (AES-256) and in transit (TLS 1.3).

2. Retention Periods

Data CategoryRetention PeriodDeletion Method
Customer account dataActive subscription + 12 monthsFull deletion upon account closure
Campaign and contact dataUntil deleted by customer or 12 months after inactivitySecure deletion via PostgreSQL purge and encrypted backup expiry
Exports and reports7 daysAutomatic removal from AWS S3
LinkedIn screenshots and debug data30 daysAutomated cleanup job
Application and audit logs12 monthsLog rotation and overwrite
Backups30-day rolling windowEncrypted deletion after expiry

3. Data Deletion Process

  • Users can delete data directly via the SuperSend interface or API. Deletion requests are processed immediately.
  • Deletion cascades through all dependent systems, including Redis caches and backups, ensuring complete removal.
  • Confirmed deletions are logged for audit purposes and are irreversible after 30 days.

4. Customer Control

Customers have full control over their stored data and can request complete deletion by contacting dpo@supersend.io. Requests are completed within 30 days.

Last Updated Oct 20 2025 — GDPR Compliance v2025-10

Ready to Scale Your Outreach?

Join thousands of teams using SuperSend to transform their cold email campaigns and drive more revenue.

Book a Demo