Data Retention & Deletion Policy
Last updated: June 19, 2026 • Effective date: June 19, 2026
This policy explains, in plain language, how long Aevon LLC (“Aevon,” “we,” “us”) keeps a Client’s data and exactly what happens to it when a Client leaves. It is part of, and should be read with, our Privacy Policy; for healthcare Clients, the applicable Business Associate Agreement (BAA) controls over this policy for anything involving patient health information (PHI).
What we hold, and for how long
By design, the Portal keeps very little. We do not store call content or PHI — call audio and transcripts live with Retell, our voice-AI provider, not in the Portal database. What we keep about a Client is:
| Data | How long we keep it |
|---|---|
| Client account & settings (business name, contact, login email, scrambled password, business hours, report preferences) | While the account is active; deleted on departure (see below) |
| The Client’s Retell access key (encrypted while stored) | While the account is active; destroyed with the account on departure |
| Billing record (Stripe customer ID, plan, billing status) | While the account is active; deleted with the account, except records we must keep for tax/accounting |
| Security & audit logs of sensitive actions (who changed or accessed what, and when) | Retained after departure as our accountability record (see “Records we keep”) |
| Call data held in Retell (audio/transcripts, where the Client has enabled it) | Per the Client’s instructions, the applicable BAA, and Retell’s terms |
What happens when a Client leaves
When a Client cancels or is offboarded, we follow these steps:
- Delete the Portal account immediately. Deleting the account removes the Client’s login and access, destroys the stored (encrypted) Retell key, and removes the account’s settings, sessions, and passkeys. As part of the same step, the Portal also clears any of that account’s unused password-reset or email-change links and any queued emails addressed to it, so nothing client-identifiable is left waiting in the system.
- Retire the voice agent. In Retell, we turn off and retire the Client’s AI agent and release its phone number if it will not be reused.
- Cancel billing. We cancel the Client’s subscription with Stripe, our payment processor (normally at the end of the paid period unless the Client asks otherwise).
- Clear incidental copies after a 30-day grace period. Routine system backups and any incidental copies (for example, client-specific files) age out and are cleared within 30 days. This short window is a safety net so an accidental cancellation or a billing dispute does not destroy something we still legitimately need.
Call data held by Retell
Call recordings and transcripts are held inside Retell, not the Portal. They are retained or deleted according to the Client’s instructions, the applicable BAA, and Retell’s own retention terms. Deleting the Portal account does not by itself delete call data in Retell; retiring the Retell agent and any Retell-side deletion follow Retell’s rules and the Client’s instructions.
Records we keep
A few records intentionally outlive the account, because we are required or accountable to keep them:
- Security & audit logs — a record of sensitive actions (for example, when a Retell key was set, accessed, or a client was deleted). These store only the action, the actor, and the time — never a secret’s value.
- Billing and tax records — kept as long as tax and accounting law requires.
- Security-incident records — where an incident occurs, we keep the related records for at least six years, as required for HIPAA matters.
Your choices
Before an account is deleted, a Client may request an export of their account and configuration data by emailing support@aevon.io; we will provide it in a commonly used electronic format within a commercially reasonable time. A Client may also ask us to delete their account sooner. Patients and callers should direct any requests about their own data to the Client (the healthcare provider), who decides how that data is used.
Changes
We may update this policy; material changes will be posted here with a new effective date, and we will email account administrators.
Contact
Aevon LLC · support@aevon.io