Marklo — Data Lifecycle & Rights Policy
Marklo
Data Lifecycle & Rights Policy
Document Owner
Chief Technology Officer (acting security & privacy lead)
Version
1.0
Effective Date
April 18, 2026
Next Review
April 18, 2027
Classification
Internal — Shareable with Customers under NDA
Purpose
This policy defines how long Marklo retains the data we process, how we delete it when retention expires, and how Marklo receives, verifies, and fulfills data-subject rights requests under applicable privacy laws (including GDPR, UK GDPR, and CCPA/CPRA).
1. Scope
This policy applies to all personal and business data processed by Marklo, including customer account data, content provided to or generated by the Marklo platform, application logs, and business records. It complements and operates consistently with the retention commitments in Marklo’s Privacy Policy.
2. Retention Principles
* Retain personal data only as long as needed for the purpose for which it was collected, or to meet a legal, contractual, or legitimate business requirement.
* Apply the shortest retention period that satisfies those requirements.
* Separate retention rules for live production data and backups.
* Document and track exceptions such as legal holds.
3. Retention Schedule
Retention periods for the principal data categories Marklo processes:
Data Category
Retention Period
Basis
Customer account and configuration data
For the duration of the active subscription plus 30 days after termination or deletion request.
Contractual — allows re-activation and export; balances minimization with customer needs.
Customer content processed through the platform (CRM, email, campaign data)
For the duration of the active subscription plus 30 days after termination.
Contractual. Processed on behalf of customers as controllers.
LLM prompts and responses (operational)
30 days, or shorter where feasible, before deletion or truncation.
Minimization — kept only as needed for product operation and debugging.
Application and security logs
90 days in hot storage; up to 12 months in archival storage.
Security monitoring and incident investigation.
Billing records and invoices
7 years after the transaction.
Tax and accounting requirements.
Marketing and prospect data
Until the data subject opts out, unsubscribes, or the data is no longer needed (reviewed annually).
Legitimate interest / consent.
Employee and contractor records
Duration of engagement plus statutory retention after termination (varies by jurisdiction).
Employment law and tax.
Backups
Rotated on a rolling window of up to 35 days; older backups are overwritten.
Recovery point objective and minimization.
4. Deletion Upon Termination or Request
When a customer terminates their subscription, or upon a verified deletion request:
1. The customer’s live account data is deleted or anonymized within 30 days of termination or the date of the verified request.
2. Data persisting in backups is overwritten through normal backup rotation, up to 35 days after the live-data deletion. Backups are not actively processed during this window.
3. A record of the deletion (date, scope, method, and requester) is retained in Marklo’s data-rights log.
5. Deletion Methods
Aspect
Standard
Deletion type
Hard deletion is used for customer account and content data at the end of the retention period. Soft deletion (record flagged as deleted, excluded from active processing) may be used during the 30-day grace period following a termination or deletion request.
Destruction method
De-identification where data retains analytic value (direct identifiers removed or hashed); de-linking where personal identifiers are separated from other data elements; permanent removal otherwise.
Automation
Account and content deletion are automated by scheduled jobs that run at the end of the grace period. Manual deletion is used only for ad-hoc or exceptional cases and is logged.
Backups
Not selectively edited. Backups containing deleted data are allowed to age out through the standard backup rotation window (up to 35 days), during which the data is not actively processed.
6. Legal Holds and Exceptions
When Marklo is required to preserve data for litigation, regulatory inquiry, or law-enforcement request, the affected data is placed on a legal hold and excluded from deletion until the hold is released. Legal holds are documented and tracked by the CTO in consultation with outside counsel where appropriate.
7. Customer-Initiated Retention Requirements
Where a customer contract imposes a shorter retention period than the defaults above, the contractual term governs. Customers can request deletion or early termination through their primary Marklo contact or by email to hello@marklo.ai; the process is documented in the Data Subject Rights sections of this Policy.
8. Responsibilities
* The CTO owns the retention schedule and reviews it at least annually.
* Engineering implements automated deletion jobs and is responsible for their correctness and monitoring.
* All personnel are responsible for respecting this policy when handling customer data.
9. Data Subject Rights
10. Rights Covered
Right
Description
Access
The right to confirm whether personal data is processed and to obtain a copy.
Rectification / Correction
The right to correct inaccurate or incomplete personal data.
Erasure / Deletion
The right to request deletion, subject to exceptions recognized under applicable law.
Restriction
The right to request that processing be temporarily restricted pending resolution of an issue.
Objection
The right to object to processing based on legitimate interests or direct marketing.
Portability
The right to receive personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Withdrawal of Consent
Where processing is based on consent, the right to withdraw consent at any time.
Non-Discrimination
The right not to receive discriminatory treatment for exercising these rights (CCPA/CPRA).
11. Intake Channels
* Email to hello@marklo.ai (primary).
* In-product account settings, for users of Marklo’s platform (account deletion and data export where supported).
* Via the customer’s primary Marklo contact, for enterprise customers.
* Postal mail to Marklo’s registered business address.
Where Marklo acts as a processor for a customer (for example, a request about an end user of the customer’s product), Marklo forwards the request to the customer acting as controller and assists the customer as required by the applicable DPA.
12. Responsibility
The CTO, as security and privacy lead, is responsible for intake, triage, and fulfillment of data subject requests. The CEO is informed of requests that involve material customer or reputational considerations.
13. Identity Verification
Before acting on a request, Marklo verifies the requester’s identity by matching request details to the information Marklo already holds (for example, account email, billing email, or other account identifiers). For sensitive requests or where identity cannot be confirmed through normal means, Marklo may request additional verification proportionate to the risk. Verification data collected for this purpose is not used for any other purpose and is retained only as long as needed to demonstrate handling of the request.
14. Response Timeline
* Acknowledgment of receipt: within 5 business days.
* Fulfillment: within 30 calendar days, or as required by applicable law. Extensions of up to a further 60 days are available under GDPR where justified by complexity; the requester is informed of the extension and the reason.
* Denials: communicated in writing with the legal basis for the denial and information about escalation or supervisory authority complaint rights.
15. Fulfillment Methods
Right
How Marklo Fulfills
Access / Portability
Marklo provides a structured export of personal data associated with the verified requester upon request.
Rectification
Marklo updates the personal data in its systems and confirms the change. For data Marklo processes on behalf of a customer, Marklo forwards the request to the customer.
Erasure
Marklo deletes or anonymizes the requester’s personal data in accordance with the Data Retention sections of this Policy (live data within 30 days; backups via the standard rotation window of up to 35 days).
Restriction / Objection
Marklo pauses the relevant processing activity. The system supports restricting processing on a per-record basis through account or administrative controls.
Withdrawal of Consent
Marklo ceases further processing based on the withdrawn consent. Marketing communications can also be unsubscribed at any time via the unsubscribe link in each email.
16. System Capabilities
* Data access: Yes. Data subjects can request data by email to hello@marklo.ai. Marklo’s platform users can also access and export data through the account settings where supported.
* Object / restrict processing: Yes, partially — Marklo can stop processing for a given data subject by disabling the record, pausing automated workflows, and excluding the record from analytics. Some processing required for legal or security purposes (for example, fraud prevention) may continue as permitted by law.
* Erasure / rectification: Yes. Rectification is performed manually for small requests and through platform features where self-service exists. Erasure is fulfilled by automated deletion jobs that run after the verified request is processed.
* Portability: Yes, via email request to hello@marklo.ai. Self-service export is available through the platform’s account settings where supported.
17. Record Keeping
Marklo records each data subject request, including the requester, nature of the request, verification steps, actions taken, date of completion, and outcome. Records are retained for a minimum of two years to demonstrate compliance.
18. Escalation and Complaints
If a requester is not satisfied with Marklo’s response, they may escalate to the CTO (hello@marklo.ai). Data subjects in the EU/UK have the additional right to lodge a complaint with their national supervisory authority. California residents have the additional rights and remedies described in the CCPA/CPRA.
19. Version History
Version
Date
Author
Summary
1.0
April 18, 2026
CTO Scott Royston
Initial issue.
1.1
July 23, 2026
CTO Scott Royston
Consolidated the Data Retention & Deletion Policy and Data Subject Rights Procedure; standardized request contact to hello@marklo.ai.
Confidential · Marklo · v1.1 · July 23, 2026Page