Orbelyra

Legal

Data Deletion

Version 1.0 - Effective [Effective date not configured]

Data Deletion Policy

Effective Date: [Effective date not configured] Version: 1.0 Company: AJTech LLC Privacy Contact: privacy@example.com Support: support@example.com

This Data Deletion Policy is a production legal draft intended for review by qualified counsel before launch.

1. How to Delete the Application Account

Users with access to their account may request deletion from Settings, Account, Delete Account. The application may require recent authentication, current password verification, active session verification, CSRF validation, and a typed confirmation phrase before accepting the request. Account deletion may disable login, revoke active sessions, remove eligible profile data, and start deletion workflows for connected resources.

2. How to Delete a Workspace Where Allowed

Workspace deletion may be available only to the Customer User or other person legally authorized to act for the Customer. Workspace deletion may require subscription review, ownership verification, confirmation of connected social account disconnects, review of scheduled posts, and confirmation that legally required records may be retained. Platform staff cannot delete customer workspaces unless expressly delegated and audited.

3. How to Disconnect Meta

Customer Users can disconnect Meta, Facebook, or Instagram accounts from the Connections page where available. The Service identifies the exact connected account, attempts provider revocation where supported, invalidates local encrypted credentials, marks the account disconnected, and prevents future publishing jobs that require that connection.

4. How to Disconnect TikTok

Customer Users can disconnect TikTok accounts from the Connections page where available. The Service invalidates or deletes local OAuth credentials, marks the connection disconnected, prevents future TikTok publishing with that account, and retains only safe historical records needed for audit, troubleshooting, or legal obligations.

5. How to Disconnect Google and YouTube

Customer Users can disconnect Google/YouTube accounts from the Connections page where available. Users may also revoke authorization from their Google account security or third-party access settings. Local encrypted credentials are invalidated or deleted after disconnect, and future publishing jobs requiring that YouTube channel are cancelled where safe or moved to manual action required.

6. How to Request Deletion if Unable to Log In

If a user cannot log in, the user may contact privacy support at privacy@example.com. We may require information sufficient to verify identity, account ownership, workspace authority, and the requester's legal right to act. We will not delete an account, workspace, or social integration solely because an unauthenticated person enters an email address.

7. Verification Required Before Deletion

Deletion requests may require verification of account access, email ownership, workspace ownership, subscription authority, business authority, social account authority, or other reasonable checks. Verification protects customers from unauthorized deletion, malicious account takeover, or accidental loss of business records.

8. What Data Is Deleted

Depending on the request, applicable law, and contractual obligations, we may delete or anonymize eligible account profile data, inactive sessions, notification endpoints, eligible uploaded media, eligible proxy previews, eligible media derivatives, unused OAuth credentials, disconnected social account metadata, and data no longer needed to provide the Service.

9. What Data May Be Retained

We may retain limited records needed for security, fraud prevention, billing, tax, legal compliance, dispute resolution, platform policy compliance, audit logs, immutable approval history, publication history, backup integrity, and enforcement of the Terms of Service. Retained records should be limited to what is reasonably necessary for those purposes.

10. Retention for Billing, Legal, Security, and Audit Reasons

Billing records, Stripe webhook records, subscription entitlement history, security logs, audit logs, approval records, staff assignment history, and publication attempts may be retained after account or workspace deletion where required or reasonably necessary. These records should not contain plaintext passwords, OAuth tokens, KMS plaintext keys, SMTP credentials, or full sensitive provider secrets.

11. Timeline and Processing Expectations

Deletion requests are processed within a reasonable period after successful verification. Some deletion may take longer because of backup cycles, billing records, legal holds, platform API availability, provider revocation timing, or operational safeguards. We do not promise immediate deletion where retention is required or where deletion would compromise security, audit, billing, or legal obligations.

12. How OAuth Credentials Are Revoked or Deleted

For connected social accounts, the Service attempts provider revocation where supported and then invalidates or deletes locally stored encrypted access and refresh credentials. The Service preserves safe connection and publishing history only as needed for audit, troubleshooting, legal compliance, or customer records.

13. What Happens to Scheduled Posts

When an account, workspace, or social connection is deleted or disconnected, future scheduled posts requiring that account may be cancelled, paused, or moved to manual action required. Posts already published to third-party platforms may remain on those platforms unless the Customer removes them directly or uses provider tools. The Service may retain safe publication records for audit and reconciliation.

14. What Happens to Uploaded Media

Eligible uploaded media, proxy previews, thumbnails, and derivatives may be deleted from configured storage according to the deletion request and retention policy. Immutable version and approval records may be retained in limited form where needed for legal, security, billing, or audit obligations. Published media may remain on connected platforms according to those platform policies.

15. What Happens to Comments and Messages

Workflow comments, chat messages, change requests, publishing instructions, and system messages may be deleted, anonymized, or retained depending on workspace deletion status, audit needs, legal obligations, and operational requirements. Staff confidentiality obligations continue after deletion or termination.

16. Contact Privacy Email

Privacy and deletion requests should be sent to privacy@example.com. General support requests may be sent to support@example.com. Include enough information for us to understand the request, but do not send passwords, OAuth tokens, payment card numbers, or social platform secrets.