Data Deletion Policy

Last updated: January 26, 2026

1. Introduction & Scope

This Data Deletion Policy describes how Converge handles the deletion of data when accounts are canceled, terminated, or when users request data removal. This policy applies to all data processed through the Converge platform.

This policy should be read alongside our Privacy Policy and Terms of Service. Definitions used in this policy:

  • Service Data: All data you create or upload to Converge, including customer conversations, employee accounts, integrations, and files.
  • Account Data: Information about your company account, including billing details and subscription status.
  • End-User Data: Data about customers who interact with your business through Converge-connected messaging platforms.

2. Self-Service Deletion for Companies

As a Converge workspace owner or administrator, you have several self-service options for data deletion:

Delete Individual Customers

You can delete individual customer records and their entire conversation history at any time through the Converge dashboard. This deletion is immediate and permanent.

Export Data Before Deletion

Before deleting any data, we recommend exporting your data through Settings > Data Export. Exports include all customers, conversations, and associated metadata.

Clear All Visitors

You can bulk-delete all visitor records (users who browsed but haven't started a conversation) through Settings > Visitor Management.

Disconnect Integrations

Disconnecting a platform integration stops new data collection from that platform. Existing data remains until manually deleted.

3. Account Cancellation & Termination

When your Converge subscription expires or is canceled:

Grace Period

Your data is retained for 30 days after your subscription expires. During this period, you can reactivate your subscription and retain all data.

Automatic Deletion

After the 30-day grace period, automatic deletion begins. Data is permanently deleted according to the following timeline:

| Data TypeDeletion Timeline |
| Customers & Messages40 days |
| Employees & Sessions40 days |
| Files & Attachments40 days |
| Integrations & Settings40 days |
| Analytics Events7 days (automatic cleanup) |
| Database Backups90 days |
| Audit Logs365 days |

Once deletion begins, this process cannot be reversed.

4. Requesting Full Company Deletion

To request immediate and complete deletion of your company account and all associated data:

  • Email: [email protected]
  • Subject: Data Deletion Request - [Your Company Name]
  • Include: Registered email address, company name, and reason for deletion

We will verify your identity and process your request within 30 days. You will receive confirmation once deletion is complete.

5. Data Deletion for End Users

If you are an end user (a customer who has communicated with a business through Converge), here's what we store about you and how to request deletion:

What We Store

  • Messages you sent through connected platforms (Telegram, WhatsApp, Messenger, etc.)
  • Profile information from your messaging platform (name, avatar)
  • Metadata (timestamps, platform, conversation status)
  • IP-based enrichment data (country, city, timezone) - unless you enabled Do Not Track
  • How to Request Deletion

    1. Contact the business directly: The company you messaged controls your data. Request deletion through their customer service channels.

    2. Company action: The company can delete your customer record and all associated messages through their Converge dashboard.

    3. Escalation: If the company is unresponsive for more than 14 days, email [email protected] with details of your request.

    Automatic Deletion

  • Widget visitors who haven't started a conversation are automatically deleted after 1-30 days (configured by each company)
  • Visitor session data expires according to company-configured retention settings

6. Technical Details

Encryption

All personally identifiable information (email, phone, name) is encrypted at rest using per-company encryption keys. Integration credentials are encrypted with rotating Data Encryption Keys (DEKs).

Cascade Deletion

When a company account is deleted, ALL related data is automatically and permanently removed:

  • All employees and their active sessions
  • All customers, messages, and conversation history
  • All file attachments and uploaded assets
  • All integration configurations and platform connections
  • All analytics events and widget tracking data
  • All tags, notes, and customer metadata

Secure Deletion

Data is deleted from primary databases immediately. Replicas and backups are purged according to the timelines specified above.

7. What Is NOT Deleted

Certain data is retained even after account deletion:

  • Aggregated Statistics: Anonymized, non-identifiable usage metrics used to improve our service
  • System Logs: Infrastructure logs retained for up to 365 days for security and debugging (these contain no personally identifiable information)
  • Billing Records: Transaction and invoice data retained as required by tax and financial regulations
  • Legal Hold Data: Data subject to active legal proceedings or investigations

8. Legal Holds & Exceptions

We may retain data beyond the standard deletion timelines in the following circumstances:

  • Legal Requirements: When required by applicable law, regulation, or legal process
  • Fraud Prevention: During active investigations of suspected fraud or abuse
  • Dispute Resolution: While legal disputes involving the data are pending
  • Law Enforcement: In response to valid legal requests from authorities

In such cases, we will retain only the minimum data necessary and delete it promptly once the hold is lifted.

9. Changes to This Policy

We may update this Data Deletion Policy from time to time. Material changes will be communicated via email to account owners and posted on this page. Your continued use of Converge after changes constitutes acceptance of the updated policy.

10. Contact Information

For questions about this Data Deletion Policy or to submit a deletion request:

If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.