iSyph is designed around a simple idea: the less data that lingers, the safer everyone is. This policy explains how we minimise and retain personal data.
1. Minimisation by design
We collect and process only the data necessary to operate your communication space and our relationship with you. Files shared within a space are designed to clear themselves once received or after a defined period.
2. Categories & retention periods
- Account & access data (who is in which space, roles) — retained for the duration of your engagement, then deleted within 15 days of termination.
- Conversation content — retention is configured by your company per space; you set what persists and for how long, including an ephemeral (zero-retention) mode where nothing is kept. Default: 30 days. Expired content is cleared by an automated sweep that runs approximately hourly, not instantly at the moment of expiry.
- Shared files — cleared once received, or after the period your company configures for that space, whichever applies. An automated sweep removes expired files approximately hourly.
- Website enquiry data (quote requests) — retained for 24-48 hrs. to respond to and manage your enquiry.
- Operational logs — retained for 30 days for security and reliability, then rotated out.
- The engagement record (your plan, features, and retention terms, and any later amendments) — retained permanently as a business record of what was configured and when. This is not conversation content and is not subject to the retention window above; it is never edited or deleted, only superseded by a later version if terms change, so there is always an accurate account of what was agreed at each point in time.
3. Deletion & return
On termination of an engagement, iSyph will, at your election, return or delete the personal data we process on your behalf, except where retention is required by law. Your environment is then decommissioned.
Where deletion applies to files or conversation content, it is an actual removal from storage — not a hidden flag or a soft delete that leaves data recoverable. Once erasure is carried out, iSyph does not retain a separate copy.
4. Your control
As the Data Fiduciary, your company sets retention parameters for conversation content within the bounds the platform supports. iSyph does not extend retention beyond your configuration.
Specific periods marked above must be confirmed by iSyph and reviewed by legal counsel before publication.