BACI

DATA RETENTION AND DELETION

Version 1.0 · Effective Date: 10 September 2026 · Last Updated: 10 September 2026

This Data Retention & Deletion Policy ("Policy") establishes BACI LLC's framework for retaining, archiving, deleting, anonymising and otherwise managing information throughout its lifecycle.

BACI retains information only for periods reasonably necessary for the purposes for which it is processed, to provide and secure the Services, comply with contractual and legal obligations, protect BACI and its Customers, resolve disputes, prevent fraud and abuse, and satisfy other legitimate requirements permitted by Applicable Law.

This Policy distinguishes Customer-controlled data from information for which BACI independently determines retention purposes. It also recognises that deletion from active systems, replicas, logs and backups may occur through different technical processes and timelines.

1. SCOPE

This Policy applies to information processed by BACI in connection with the Services, including Customer Data, Customer Personal Data, Account information, Usage Data, security and audit records, support records, commercial and billing records, marketing information, website and cookie-related information, developer and API records, partner records, recruitment information, legal and compliance records, and other information maintained by BACI.

The Policy applies across BACI-controlled systems and to relevant service providers and Subprocessors to the extent required by the applicable Agreement and Applicable Law.

2. RELATIONSHIP TO THE BACI LEGAL FRAMEWORK

This Policy forms part of the BACI Legal Framework and should be read with the Terms of Service, Privacy Policy, Cookie Policy, Data Processing Addendum ("DPA"), Security Policy / Security Addendum, Subprocessor Policy & List, International Data Transfer Addendum and applicable Orders, Statements of Work and Supplemental Terms.

For Customer Personal Data processed by BACI on Customer's behalf, the DPA governs BACI's processor obligations. Where an executed Agreement, Order or mandatory law establishes a specific retention or deletion requirement for particular data, that requirement controls for the matter it expressly addresses.

This Policy does not expand BACI's rights to retain Customer Data beyond the Agreement or Applicable Law.

3. RETENTION PRINCIPLES

BACI applies the following principles:

(a) purpose limitation — information should not be retained indefinitely merely because storage is technically possible;

(b) data minimisation — retention should be proportionate to the information and purpose;

(c) contractual compliance — Customer-controlled data is retained and deleted consistently with applicable Customer instructions and agreements;

(d) legal compliance — information may be retained where law requires or permits retention;

(e) security and integrity — deletion processes must not create unreasonable security or integrity risks;

(f) defensibility — BACI may retain information reasonably necessary to establish, exercise or defend legal claims;

(g) lifecycle management — active data, archived data, logs, replicas and backups may have different deletion mechanisms;

(h) accountability — material retention rules should be documented and periodically reviewed; and

(i) irreversibility — permanent deletion may be irreversible, and Customers are responsible for exporting or preserving information they are required to retain before requesting or initiating deletion.

4. RETENTION DETERMINATION

BACI determines appropriate retention periods by considering the nature and sensitivity of information; the purposes for which it is processed; Customer instructions; contractual obligations; Service functionality; security and fraud-prevention requirements; statutory and regulatory requirements; tax, accounting and financial-record obligations; applicable limitation periods; litigation, investigation and dispute needs; technical architecture; backup and recovery requirements; and whether information can instead be anonymised or de-identified.

Where no fixed period is required, BACI applies a period reasonably related to the continuing purpose and risk.

5. CUSTOMER DATA DURING AN ACTIVE SERVICE TERM

During an active Service term, Customer Data is retained according to Customer use, Service functionality, the Agreement and applicable configuration.

Where the Services provide Customer-controlled deletion or retention functionality, Customer may use that functionality subject to applicable permissions, technical dependencies and legal restrictions.

BACI will not intentionally delete Customer Data required for the active contracted Service except pursuant to Customer instruction, configured functionality, the Agreement, security or integrity requirements, Applicable Law, or an authorised retention rule.

6. CUSTOMER-CONTROLLED RETENTION

Where BACI provides retention settings, Customers are responsible for configuring those settings consistently with their own legal, regulatory, contractual and business obligations.

Customer is responsible for determining what Customer Data it is legally required to retain and for preserving or exporting such information before deletion becomes irreversible.

The availability of a retention feature does not determine the legally appropriate retention period for Customer.

7. CUSTOMER DELETION REQUESTS

Where Customer is entitled to instruct BACI to delete Customer Data, BACI will process the instruction in accordance with the Agreement, DPA, Service functionality and Applicable Law.

Deletion may involve removal from active production systems followed by deletion from replicas, caches, archives and backups through applicable technical processes.

BACI may require appropriate authentication, authorisation or verification before executing a deletion request.

BACI is not required to follow a deletion instruction that would require BACI to violate Applicable Law or a binding legal preservation obligation.

8. TERMINATION OR EXPIRATION OF SERVICES

Upon expiration or termination of the applicable Services, Customer's access to Customer Data and the period during which Customer may retrieve it are governed by the Agreement, applicable Order and Service functionality.

After any applicable retrieval or transition period expires, BACI may delete Customer Data from active systems in accordance with the Agreement.

Customer is responsible for exporting Customer Data it wishes or is legally required to retain before the applicable retrieval period ends.

BACI has no obligation to preserve Customer Data indefinitely after the contractual retrieval period has expired.

9. RETURN OF CUSTOMER DATA

Where the DPA or Agreement requires return of Customer Personal Data or Customer Data, BACI may satisfy the requirement through available export functionality, a commercially reasonable data export, or another method agreed by the parties.

Return does not require BACI to provide BACI Technology, proprietary schemas, system secrets, internal security information, other customers' data, or information BACI is prohibited from disclosing.

10. DELETION FROM ACTIVE SYSTEMS

Deletion from active systems means that the information is removed, rendered inaccessible to ordinary Service use, or otherwise placed beyond normal production availability according to the applicable architecture.

Deletion may be asynchronous and may require processing across databases, indexes, search systems, object stores, replicas, queues, caches or derived systems.

BACI will use reasonable processes designed to propagate deletion through systems within BACI's control where the relevant data remains identifiable and deletion is required.

11. SOFT DELETION, RECYCLE AND RECOVERY STATES

Some BACI functionality may use temporary soft-deletion, recycle, quarantine or recovery states to protect against accidental deletion, support integrity, investigate abuse or permit restoration.

Information in such a state may remain technically stored while being unavailable through ordinary Customer workflows.

Where a temporary recovery state applies, permanent deletion may occur after the applicable recovery period, unless restoration, legal preservation or another authorised retention basis applies.

A soft-deleted record must not be treated as ordinarily active Customer content merely because it remains technically recoverable.

12. BACKUPS

Customer Data and other information may remain in encrypted or otherwise protected backups after deletion from active systems.

Where immediate deletion from a backup is not technically practicable, BACI may retain the information until the backup is overwritten, expires or is securely destroyed through BACI's ordinary backup-rotation process, provided the information remains protected and is not restored for ordinary business use.

If a backup containing previously deleted information must be restored for disaster recovery, BACI will use reasonable processes to reapply applicable deletion state or otherwise prevent the restored information from becoming ordinary active data where required.

Backup retention periods may vary according to system architecture, recovery requirements and contracted Service configuration.

13. REPLICAS, CACHES AND TRANSIENT COPIES

Information may exist temporarily in replicas, caches, queues, temporary files, processing buffers or other transient technical copies.

BACI may delete these copies through ordinary expiration, invalidation, rotation, overwrite or system-cleanup mechanisms where immediate record-by-record deletion is not technically practicable.

Transient technical copies must not be used to circumvent an applicable deletion obligation.

14. LOGS AND TELEMETRY

BACI may retain security, audit, operational, diagnostic, performance and Usage Data for periods reasonably necessary to secure and operate the Services, investigate incidents, prevent abuse, troubleshoot, maintain reliability, demonstrate compliance and satisfy legal obligations.

Log retention may differ from Customer content retention because logs serve separate security and operational purposes.

Where logs contain Personal Data, BACI will retain them only for a period reasonably necessary for the applicable purpose, subject to Applicable Law and legal preservation requirements.

15. SECURITY RECORDS

BACI may retain authentication records, access records, security alerts, threat indicators, forensic records, incident records and related evidence for periods reasonably necessary to protect BACI and Customers, investigate events, detect repeated attacks, support legal claims and comply with law.

Security information may be retained after related Customer content is deleted where continued retention is independently necessary and lawful.

BACI will restrict access to retained security records according to their sensitivity.

16. ACCOUNT AND IDENTITY RECORDS

BACI may retain Account, authentication, administrative, organisation-membership and access-management records while an Account or Customer relationship remains active and thereafter for periods reasonably necessary for security, fraud prevention, contractual administration, dispute resolution and legal compliance.

Credentials and secrets will be revoked, disabled, deleted or otherwise rendered unusable when they are no longer valid, subject to applicable security records and evidence preservation.

17. BILLING, PAYMENT AND COMMERCIAL RECORDS

BACI may retain invoices, payment records, transaction records, subscription records, Orders, contractual records and related commercial information for periods required or permitted by tax, accounting, financial, anti-fraud, audit, contractual and legal requirements.

BACI does not need to retain complete payment-card credentials merely to retain evidence of a transaction. Payment providers may independently retain information according to their own legal obligations and privacy terms.

18. SUPPORT AND COMMUNICATION RECORDS

BACI may retain support tickets, service communications and related diagnostic information for periods reasonably necessary to provide support, maintain service history, improve support quality, investigate incidents, resolve disputes and comply with law.

Customers should avoid including unnecessary passwords, private keys, special-category information or other sensitive information in support communications.

19. WEBSITE, MARKETING AND PROSPECT DATA

BACI retains website, enquiry, sales, marketing and prospect information according to continuing business purpose, consent or preference status, Applicable Law and the need to maintain suppression records.

Where an individual opts out of marketing, BACI may retain limited information necessary to record and honour the opt-out rather than deleting the suppression record and risking renewed marketing.

Cookie and similar-technology retention is further governed by the Cookie Policy and applicable consent settings.

20. RECRUITMENT RECORDS

BACI may retain recruitment and applicant information for the duration of a recruitment process and for a reasonable period thereafter for hiring administration, recordkeeping, equal-opportunity compliance, dispute management, future opportunities where permitted, and other lawful purposes.

Longer retention may apply where the individual consents to future consideration or Applicable Law requires it.

21. PARTNER, DEVELOPER AND AFFILIATE RECORDS

BACI may retain records concerning developers, agencies, advisers, technology partners, affiliates, licensees and other commercial relationships for the duration of the relationship and thereafter for contractual, accounting, security, fraud-prevention, compliance and dispute-resolution purposes.

API and developer security records may be retained separately from ordinary relationship data where required to investigate misuse or compromise.

22. AI INPUTS AND OUTPUTS

Private Inputs and private Outputs are retained according to the applicable Service, Customer configuration, Agreement and lawful operational requirements.

Retention does not change BACI's no-general-model-training-by-default commitment. Unless Customer expressly agrees in writing or affirmatively opts into a clearly identified programme, BACI will not use Customer Confidential Information, Customer Personal Data, private Inputs or private Outputs to train or fine-tune general-purpose or shared AI models for the benefit of other customers.

Deletion of an Input or Output does not require deletion of a general model where the relevant information was never used to train that model.

23. CUSTOMER-SPECIFIC AI TRAINING OR FINE-TUNING

Where Customer expressly requests Customer-specific private training, fine-tuning, retrieval or similar functionality, retention of the relevant datasets, configurations, model artefacts or derived materials will be governed by the applicable Order, DPA and Supplemental Terms.

BACI will not convert Customer-specific private training material into general shared training material without Customer's applicable affirmative authorisation.

24. DERIVED, AGGREGATED AND DE-IDENTIFIED INFORMATION

Subject to the Agreement and Applicable Law, BACI may retain aggregated or de-identified information where the resulting information no longer reasonably identifies an individual, Customer or Customer Confidential Information.

Where Applicable Law requires de-identified information to remain de-identified, BACI will maintain it in de-identified form and will not attempt to re-identify it except where legally permitted for security, testing, validation or compliance.

A deletion obligation applicable to identifiable Customer Personal Data does not necessarily require deletion of lawfully created information that is no longer Personal Data.

25. DERIVED DATA AND DATA LINEAGE

Where Customer Data is transformed, indexed, analysed or incorporated into Customer-specific derived datasets, BACI will use reasonable processes designed to address deletion obligations across identifiable derived copies where required by the Agreement or Applicable Law.

The technical method may depend on data lineage, architecture and whether the derived information remains attributable to the source data.

BACI will not intentionally preserve an identifiable derivative solely to defeat an applicable deletion obligation.

26. SEARCH INDEXES, EMBEDDINGS AND RETRIEVAL SYSTEMS

Customer Data may be represented in search indexes, vector indexes, embeddings, retrieval stores or other technical structures used to provide Customer-requested functionality.

Where deletion is required, BACI will use reasonable technical processes to remove, invalidate, rebuild or otherwise make the relevant Customer-specific representation unavailable through ordinary Service use where it remains identifiable and within BACI's control.

The exact method may vary by architecture and may occur asynchronously.

27. ANALYTICS AND SERVICE IMPROVEMENT DATA

BACI may retain Usage Data and aggregated or de-identified analytics for security, capacity planning, performance, reliability, product analytics and lawful Service improvement.

BACI will not use this provision to retain identifiable Customer Personal Data indefinitely where the relevant purpose can reasonably be achieved with de-identified or aggregated information.

28. LEGAL HOLDS AND PRESERVATION

BACI may suspend ordinary deletion where information is subject to a valid legal hold, litigation preservation duty, regulatory requirement, investigation, subpoena, court order or other binding legal obligation.

A legal hold applies only for as long as reasonably necessary for the relevant obligation.

Information preserved under legal hold will remain subject to applicable confidentiality and security requirements and will not be used for unrelated purposes merely because deletion is suspended.

When the preservation requirement ends, the information will return to the applicable retention and deletion process unless another lawful retention basis applies.

29. FRAUD, ABUSE AND DISPUTE PRESERVATION

BACI may retain limited information reasonably necessary to detect or prevent fraud, enforce the Agreement, investigate abuse, prevent repeated evasion, resolve billing or contractual disputes, establish or defend legal claims, and protect BACI, Customers or third parties.

This exception must not be used as a basis for indefinite retention unrelated to the identified risk or dispute.

30. GOVERNMENT AND LAW-ENFORCEMENT REQUESTS

Receipt of a governmental or law-enforcement request does not automatically create indefinite retention.

BACI may preserve information where required by valid legal process or Applicable Law and will handle government requests under the Terms, Privacy Policy, DPA and applicable legal requirements.

Where legally permitted and reasonably practicable, BACI may seek clarification, narrowing or legal review of a request reasonably believed to be unlawful, defective or materially overbroad.

31. DATA SUBJECT DELETION REQUESTS — BACI AS CONTROLLER

Where BACI acts as Controller and receives a valid deletion request, BACI will evaluate and process the request in accordance with Applicable Data Protection Law and the Privacy Policy.

Deletion rights are not absolute. BACI may retain information where a lawful exception applies, including legal compliance, security, fraud prevention, freedom of expression where applicable, public-interest requirements, contractual necessity where permitted, or establishment, exercise or defence of legal claims.

Where BACI denies or limits a request, BACI will provide information required by Applicable Law.

32. DATA SUBJECT REQUESTS — BACI AS PROCESSOR

Where BACI processes Customer Personal Data solely on Customer's behalf, Customer is responsible for determining and responding to the Data Subject's request.

BACI will provide reasonable assistance as required by the DPA and Applicable Data Protection Law.

BACI will not independently alter or delete Customer Personal Data contrary to Customer's lawful instructions merely because BACI has technical access to the information.

33. DELETION VERIFICATION

BACI may use system records, job status, deletion logs, administrative records or other reasonable mechanisms to verify that a deletion process has been initiated or completed.

A deletion confirmation relates to BACI's applicable systems and does not certify deletion from systems controlled independently by Customer or unrelated third parties.

BACI may retain limited evidence that a deletion request was received and fulfilled where necessary for accountability and compliance.

34. SECURE DELETION METHODS

BACI may use deletion, cryptographic erasure, key destruction, secure overwrite, provider-supported sanitisation, resource destruction, logical deletion followed by lifecycle expiry, or other methods appropriate to the storage technology and risk.

The appropriate method depends on whether information resides in databases, object storage, managed cloud services, ephemeral storage, backups, encrypted volumes or other media.

BACI will not claim use of a specific physical destruction or sanitisation standard unless that method is actually applicable to the relevant environment.

35. STORAGE MEDIA AND INFRASTRUCTURE RETIREMENT

For infrastructure operated by third-party cloud or hosting providers, BACI may rely on provider controls for media sanitisation, destruction, reallocation and lifecycle management.

BACI will select and manage relevant providers through its security and Subprocessor framework.

A provider's certification or destruction standard will not be represented as BACI's own certification unless BACI is expressly within its scope.

36. SUBPROCESSOR RETENTION AND DELETION

BACI will require Subprocessors that process Customer Personal Data on BACI's behalf to protect and delete or return such data consistently with applicable contractual and legal requirements.

Subprocessors may maintain their own technical deletion cycles, including backup rotation, provided those cycles are consistent with BACI's obligations.

When a Subprocessor relationship ends, BACI will require appropriate return or deletion of Customer Personal Data subject to lawful retention exceptions.

37. THIRD-PARTY SERVICES CONTROLLED BY CUSTOMER

Where Customer connects BACI to a third-party service controlled by Customer, deletion from BACI does not necessarily delete information previously transmitted to or retained by that third-party service.

Customer is responsible for managing retention and deletion within Customer-controlled third-party systems.

BACI will not represent that it can delete information from an independent system where BACI lacks the technical or legal authority to do so.

38. DATA RESIDENCY AND RETENTION

Retention and deletion obligations apply regardless of data location, but technical processes may differ by region, provider and architecture.

A data-residency commitment does not itself establish a particular retention period.

Where an Order establishes a specific residency or retention requirement, BACI will apply it according to the applicable contractual terms.

39. REGULATED AND RESTRICTED DATA

Customer must not submit classified, specially regulated or restricted information to an ordinary BACI environment where BACI has not expressly authorised that environment for the relevant category.

Where BACI expressly agrees to support a regulated data category, additional retention, deletion, archival or legal-hold requirements may be established through an Order or Supplemental Terms.

40. PUBLIC-SECTOR RECORDS

Government and public-sector Customers may have statutory records-retention, public-records, archival, evidentiary or deletion obligations.

Such Customers are responsible for identifying requirements applicable to their records unless BACI expressly assumes a specified obligation in the Government & Public Sector Schedule or applicable Order.

BACI will not delete government Customer Data contrary to a binding contractual retention requirement or valid legal preservation instruction.

41. RETENTION SCHEDULES

BACI may maintain internal or published retention schedules assigning periods or retention criteria to categories of information.

A retention schedule may use a fixed period, event-based period, Customer-configured period, legal requirement, contractual period or purpose-based criterion.

Where a published schedule and an executed Customer agreement conflict, the applicable order of precedence determines the controlling requirement.

BACI may revise retention schedules as Services, laws, risks and operational requirements evolve, subject to existing contractual commitments.

42. NO INVENTED UNIVERSAL PERIODS

BACI will not publish arbitrary universal retention periods merely to create the appearance of precision.

Where BACI has established and operationalised a fixed retention period for a defined category, that period may be published in an applicable retention schedule, product documentation, Order or Supplemental Terms.

Where retention depends on Customer configuration, legal obligation, Service architecture or another variable, BACI will describe the applicable criterion rather than falsely state a fixed period.

43. CUSTOMER EXPORT BEFORE DELETION

Before terminating Services, closing an Account or initiating irreversible deletion, Customer should export information it needs for legal, regulatory, operational or archival purposes.

BACI is not responsible for Customer's failure to preserve information after BACI has provided the retrieval rights required by the Agreement.

Where deletion is irreversible, BACI may not be able to restore the information after the applicable recovery and backup periods have expired.

44. ACCOUNT CLOSURE

Closing an Account may trigger termination, access restriction, retention or deletion processes depending on the Account type, applicable subscription and Agreement.

Account closure does not automatically require immediate deletion of all information where BACI must retain commercial, security, legal, suppression or compliance records.

Customer Data associated with a paid organisational Service is governed by the applicable Customer Agreement rather than solely by an individual user's request to close an Account.

45. SUSPENDED OR ABANDONED ACCOUNTS

BACI may retain data associated with suspended or abandoned Accounts for a reasonable period necessary to permit lawful restoration, resolve payment or security issues, investigate abuse, comply with the Agreement or satisfy legal requirements.

Retention of a suspended Account does not entitle BACI to use Customer Data for unrelated purposes.

Where the Account will not be restored and no retention basis remains, the applicable deletion process will apply.

46. TRIALS, TEST ENVIRONMENTS AND SANDBOXES

Data placed in trials, demonstrations, test environments or sandboxes may be subject to shorter retention, reset or deletion cycles than production Services.

Customers should not place production-sensitive or legally required records into a trial or test environment unless the applicable terms expressly support that use.

Product-specific retention rules may apply to sandbox and development environments.

47. API CREDENTIALS AND SECURITY TOKENS

Revoked or expired API credentials, tokens and similar secrets may be deleted, cryptographically invalidated or retained only in non-usable form where necessary for security, audit or fraud-prevention records.

BACI may retain credential identifiers, prefixes, revocation timestamps, last-used information and related security metadata where reasonably necessary to investigate misuse or demonstrate revocation.

BACI will not intentionally retain a usable secret merely because related audit metadata must be preserved.

48. DELETION AND AUTONOMOUS ACTIONS

Autonomous functionality must not override a Customer's configured retention, deletion, legal-hold or approval controls unless Customer has expressly authorised that capability.

Where an Autonomous Action can delete or materially alter Customer Data, BACI may support authority boundaries, permissions or approval controls appropriate to the functionality.

Customer remains responsible for configuring Autonomous deletion authority proportionate to the consequence of the action.

Autonomy does not remove governance.

49. DATA PORTABILITY AND MIGRATION

Where Customer migrates from BACI or moves data between BACI environments, temporary duplicate copies may exist during the migration process.

BACI may retain such copies only for the period reasonably necessary to complete, verify and secure the migration, subject to backup and legal-retention requirements.

Successful migration does not automatically delete the source environment unless the applicable process or Customer instruction provides for deletion.

50. MERGERS, ACQUISITIONS AND CORPORATE TRANSACTIONS

Information may be transferred or retained in connection with a merger, acquisition, financing, reorganisation, sale of assets or similar corporate transaction where permitted by Applicable Law and the Agreement.

Any successor that receives Customer Data remains subject to applicable contractual and legal obligations.

Corporate transaction records may be retained for legal, tax, accounting and evidentiary purposes.

51. ANONYMISATION AS AN ALTERNATIVE TO DELETION

Where permitted by Applicable Law, BACI may permanently anonymise information instead of deleting it if the resulting information no longer constitutes Personal Data and no longer reasonably identifies the Customer or Customer Confidential Information.

Pseudonymisation alone is not equivalent to anonymisation where re-identification remains reasonably possible.

BACI will not describe information as anonymous merely because direct identifiers have been removed.

52. RETENTION GOVERNANCE

BACI will assign appropriate responsibility for retention and deletion governance.

Governance may include retention schedules, legal-hold procedures, deletion workflows, technical lifecycle controls, privacy review, security review, Customer instruction handling, Subprocessor oversight and periodic assessment.

BACI may prioritise automation where reliable automation reduces the risk of unnecessary retention or incomplete deletion.

53. PERIODIC REVIEW

BACI will periodically review material retention practices to determine whether information remains necessary, whether retention periods remain appropriate, whether legal requirements have changed and whether technical deletion processes remain effective.

Where BACI identifies unnecessary retention, BACI will take reasonable steps to correct the relevant rule or process.

54. RECORDS OF RETENTION AND DELETION

BACI may maintain records documenting retention rules, deletion jobs, legal holds, Customer instructions, Data Subject requests, system lifecycle events and other information reasonably necessary for accountability.

Such records may themselves be retained after the underlying information is deleted where necessary to demonstrate compliance, provided they contain no more information than reasonably necessary for that purpose.

55. SECURITY DURING RETENTION

Information remains subject to applicable security and confidentiality protections throughout its retention period.

Archived, legally preserved, backup or otherwise inactive information does not cease to require protection merely because it is not used in ordinary Service operations.

Access to retained information should be restricted according to purpose and sensitivity.

56. DELETION FAILURES AND EXCEPTIONS

If a deletion process fails or cannot complete as expected, BACI will use reasonable processes to identify and remediate material failures where deletion is contractually or legally required.

Temporary technical inability to delete a copy does not authorise unrelated Processing of that copy.

Where permanent technical constraints prevent immediate deletion, BACI may isolate or restrict the information until deletion becomes practicable, where permitted by Applicable Law.

57. RESTORATION OF DELETED DATA

BACI may restore data from a recovery state or backup only where authorised and technically available.

Once information has passed applicable recovery and backup cycles and has been permanently deleted, restoration may be impossible.

BACI does not guarantee recovery of information that Customer has deleted unless an applicable Service feature or Agreement expressly provides a recovery commitment.

58. DELETION OF BACI CONTROLLER DATA

For Personal Data BACI processes as Controller, BACI will delete or anonymise information when it no longer has an ongoing legitimate purpose or legal basis for retention, subject to lawful exceptions.

The Privacy Policy describes BACI's controller purposes and Data Subject rights.

BACI may retain limited records necessary to document consent withdrawal, opt-outs, previous transactions, legal compliance or request fulfilment.

59. RETENTION AFTER CONSENT WITHDRAWAL

Withdrawal of consent ends Processing that depends solely on that consent prospectively.

It does not require BACI to erase information where another lawful retention basis applies, nor does it invalidate Processing lawfully performed before withdrawal.

Where no other lawful basis or retention requirement applies, BACI will delete or anonymise the affected information according to applicable processes.

60. RETENTION AFTER MARKETING OPT-OUT

BACI may retain a minimal suppression record after a marketing opt-out to ensure the preference continues to be honoured.

Suppression information will not be used to resume the marketing activity the individual opted out of unless the individual later lawfully changes the preference.

61. CONFLICTING RETENTION REQUIREMENTS

Where deletion and preservation obligations conflict, BACI will apply the requirement that legally controls the relevant information and context.

BACI may restrict access or Processing while a conflict is resolved.

Customer should promptly inform BACI of Customer-specific preservation requirements that BACI has contractually agreed to follow.

62. CHANGES TO THIS POLICY

BACI may update this Policy to reflect changes in Services, architecture, retention functionality, Applicable Law, regulatory guidance, security requirements, Subprocessors or the BACI Legal Framework.

Each version will identify its effective date and last-updated date.

BACI will not use a unilateral policy change to override a higher-precedence contractual retention commitment.

63. INTERPRETATION

References to deletion include permanent deletion, secure destruction, cryptographic erasure, irreversible anonymisation or another legally sufficient method where appropriate to the context.

"Immediate deletion" does not mean that every technical copy disappears synchronously where backups, caches, replicas or distributed systems require secure lifecycle processing, unless Applicable Law or an express contractual commitment requires a specific result within a specific period.

Nothing in this Policy authorises BACI to retain information longer than permitted by Applicable Law or the applicable Agreement.

Mandatory law controls to the extent of any inconsistency.

64. CONTACT

Privacy and retention enquiries may be directed to:

BACI Privacy BACI LLC privacy@bacihq.com

Security matters may be directed to:

security@bacihq.com

ANNEX I — RETENTION CATEGORY FRAMEWORK

BACI uses the following category framework when assigning or reviewing retention requirements:

1. Customer Content and Customer Data — Customer-controlled or contract-controlled retention, subject to Service functionality, termination retrieval rights, legal preservation and backup lifecycle.

2. Customer Personal Data Processed on Behalf of Customer — governed by Customer instructions, the DPA, Applicable Data Protection Law and lawful retention exceptions.

3. Account and Identity Data — active relationship plus security, fraud, contractual and legal requirements after closure.

4. Usage, Operational and Diagnostic Data — retained according to operational, reliability, capacity, support and lawful analytics needs.

5. Security and Audit Data — retained according to threat detection, incident investigation, audit, evidentiary and compliance needs.

6. Billing and Commercial Records — retained according to tax, accounting, financial, contractual, fraud and legal requirements.

7. Support Records — retained according to support history, troubleshooting, security, dispute and legal requirements.

8. Marketing and Prospect Data — retained according to legitimate business need, consent, Applicable Law and suppression requirements.

9. Cookie and Similar-Technology Data — retained according to the Cookie Policy, consent state, technical purpose and applicable law.

10. Recruitment Data — retained according to recruitment purpose, legal requirements, dispute periods and lawful future-opportunity purposes.

11. Partner, Developer and Affiliate Records — retained according to relationship, security, accounting, contractual and legal requirements.

12. Legal and Compliance Records — retained according to legal holds, statutory obligations, limitation periods, regulatory requirements and defence of claims.

13. Backups and Technical Copies — retained through applicable recovery, rotation, expiration and secure destruction processes.

This framework defines the basis for retention decisions and does not invent fixed periods where BACI has not operationally established them.

ANNEX II — DELETION LIFECYCLE

A BACI deletion process may include the following stages depending on the relevant system:

1. Request or Trigger — Customer instruction, Account closure, expiration, retention rule, Data Subject request, administrator action or other authorised event.

2. Validation — verification of authority, scope, dependencies, legal holds and applicable contractual requirements.

3. Active-System Removal — deletion, disabling, tombstoning or removal from ordinary production availability.

4. Derived-System Propagation — removal or invalidation from indexes, retrieval systems, derived datasets or Customer-specific representations where required.

5. Replica and Cache Expiry — propagation through replicas, caches, queues and transient systems.

6. Backup Rotation — expiration, overwrite, cryptographic erasure or destruction according to applicable recovery lifecycle.

7. Subprocessor Completion — deletion or return through applicable third-party lifecycle where relevant.

8. Verification — system records or other reasonable evidence that the applicable deletion process has completed.

9. Residual Compliance Record — retention of minimal evidence of the deletion action where reasonably necessary for accountability.

Not every deletion requires every stage, and technical sequencing may differ by architecture.

ANNEX III — LEGAL HOLD PRINCIPLES

Where BACI must preserve information notwithstanding an ordinary deletion rule:

1. the hold should identify the relevant legal, regulatory, investigative or dispute basis;

2. preservation should be limited to information reasonably within scope;

3. access should remain restricted;

4. the preserved information should not be used for unrelated purposes merely because it is retained;

5. the hold should be reviewed when appropriate;

6. the hold should be released when the preservation obligation ends; and

7. released information should return to its ordinary retention or deletion lifecycle unless another lawful basis applies.

Nothing in this Annex requires BACI to disclose privileged legal-hold analysis to Customer or another party.

BACI DATA RETENTION & DELETION POLICY — VERSION 1.0 Effective 10 September 2026

We're listening.