SECURITY
Data Retention and Deletion Policy
Effective: 5 August 2026 · v1.0 · Owner: Talonic Security
This policy describes how long Talonic retains customer data and how that data is deleted. It applies to customers who purchase Talonic through AWS Marketplace.
For the documents and data you submit to the platform, you are the data controller and Talonic is the data processor. Talonic acts as controller only for its own account, billing and website records. Our Data Processing Agreement, available at security@talonic.ai, sets out the processor terms in full.
1. What we retain
We retain:
- The documents you submit for processing
- The structured data extracted from those documents
- The field registry entries derived from them
- Operational and security records needed to run and audit the service, including access and audit logs
Your documents, extracted data and registry entries are scoped to your organisation. They are not shared with, combined with, or used to improve the service for any other customer.
2. Where it is stored
All data from AWS Marketplace subscriptions is stored on Amazon Web Services, in an AWS Region located in the European Union. Data from AWS Marketplace subscriptions is not processed on Talonic's other infrastructure and does not leave the European Union.
All data is encrypted at rest — including database storage and all file storage — and encrypted in transit using TLS, including connections between internal services and queues.
3. How long we retain it while your subscription is active
We retain your data for as long as your subscription is active and you have not asked us to delete it, and only for as long as is reasonably required to provide the service to you.
You can delete your data at any time, or ask us to delete it on your behalf. We action deletion requests within 30 days of receiving them. Copies in encrypted backups persist for a further limited period after deletion from primary systems — see section 5.
Security audit records are treated differently and are not removed by a deletion request — see section 6.
4. What happens when your subscription ends
For 45 days after your subscription terminates or expires, your data remains available in the platform so you can retrieve or delete it.
After that 45-day window, we permanently delete your documents, extracted data and registry entries within 30 days. Audit records are retained for the remainder of the 24-month period as described in section 5.
In the worst case, all copies of your data — including backups — are permanently deleted no later than 110 days after your subscription ends (45 days of availability, plus 30 days for deletion from primary systems, plus 35 days of backup rotation).
5. Backups
Encrypted backups may retain copies of your data for up to 35 days after deletion from our primary systems, after which they are deleted and overwritten on a rolling basis. Backup copies remain encrypted and access-controlled, are held in the same AWS Region as the primary data, and are used only to restore the service.
6. Security audit records
We maintain an append-only audit trail of security-relevant events. Audit records are tamper-evident: they are hash-chained per customer and the chain is anchored daily to external storage, so any modification is detectable.
We retain audit records for 24 months, after which they are deleted. This satisfies the AWS Marketplace retention requirements. Where you exercise your right to erasure, we delete your documents and extracted data and retain audit records for the remainder of the 24-month period, as permitted by GDPR Article 17(3)(e).
Audit records identify actions taken within the service. They are not used to reconstruct the content of documents that have been deleted.
7. Data we are required to keep
Where law requires us to retain certain records — for example invoicing and tax records — we retain them for the period the law requires, and only for that purpose. Any such data remains subject to the confidentiality, privacy and security terms of our agreement with you.
8. Certification of deletion
On request, we will confirm to you in writing that your data has been deleted and removed.
9. Contact
To request deletion of your data, written certification of deletion, or a copy of our Data Processing Agreement, email security@talonic.ai. We acknowledge requests within 24 business hours.*
* Business hours are 09:00 to 18:00 CET, Monday to Friday, excluding German public holidays.
Talonic GmbH · Luisenstr. 53, 10117 Berlin, Germany · security@talonic.ai