Skip to main content
Last updated: June, 22, 2026 Squid Academy retains personal data only for as long as it is needed for the purposes described in our Privacy Policy and to meet legal, contractual, and operational requirements. This page summarizes the main retention periods and deletion procedures referenced in Section 12 of our Privacy Policy and Section 8 of our Data Processing Addendum.

1. Key Principles

  • Purpose limitation – We keep personal data only for as long as necessary for the specific purpose it was collected.
  • Legal obligations – Some data must be retained for statutory reasons (e.g., tax, accounting, or child protection laws).
  • Customer instructions – For organization-provisioned accounts, we follow the controller’s instructions for retention and deletion under our DPA.
  • Secure deletion – When data is no longer needed, it is securely deleted or anonymized.

2. Standard Retention Periods

3. Backup Data

  • Deleted data may remain in backups until the backup cycle expires. Backups are encrypted, and access is restricted.
  • Data is deleted once the agreement ends.

4. Deletion Process

  1. Trigger – Retention period expires or a valid deletion request is received.
  2. Verification – Confirm identity of requester (public users) or confirm request with controller (org-provisioned).
  3. Deletion – Remove data from active systems.
  4. Backup purge – Data naturally removed as backup cycles expire.
  5. Confirmation – For DSR requests, confirmation sent to requester or controller.

5. Exceptions

Some data may be retained beyond standard periods:
  • To comply with legal obligations.
  • To resolve disputes or enforce agreements.
  • For ongoing investigations into misuse or violations.

6. Contact

For questions about data retention or deletion: email [email protected] or Submit a Privacy Request