Legal
Data Retention Policy
Last updated: 13 August 2026
This policy explains how Bach.ai — operated by Wittelsbach Private Limited (“Wittelsbach”, “we”, “our”, “us”) — stores, retains and deletes your data. It should be read together with our Privacy Policy and our Data Deletion Instructions.
1. Our principles
We hold your data to four rules: it is stored only for legitimate business purposes, kept for the minimum time required, deleted permanently when no longer needed, and handled in line with global privacy standards.
2. What we retain
| Data category | Examples |
|---|---|
| Account data | Name, email, login credentials, company details |
| Platform data | Audit results, revenue-leak findings, funnel and conversion metrics |
| Connected-account data | Meta and Google Ads performance data; Shopify, WooCommerce, Magento or Wix store data |
| Communication data | Support tickets, chat records, emails |
| Billing data | Invoices, payment status, subscription history |
| Technical logs | IP address, device info, access logs |
3. How long we keep it
| Data type | Retention period |
|---|---|
| Account information | While the account is active |
| Platform & analytics data | Up to 24 months after last activity |
| Connected ad & store data | Deleted when your account is deleted or terminated, on a verified request, or through the inactive-account process (section 4) |
| Support communications | Up to 18 months |
| Billing & financial records | 7 years, as required by law |
| System logs | Up to 12 months |
4. Inactive accounts
An account is inactive after 12 consecutive months with no login. We send a reminder email first; if there is no response, the account and its associated data are permanently deleted within 30 days.
5. Deleting your data on request
You can request full account deletion at any time by emailing info@wittelsbach.ai. Once we verify the request, your account and all personal and connected-account data are permanently deleted from our active systems immediately — except records we are legally required to keep (see section 7). Residual copies in encrypted backups expire on the normal backup cycle (see section 6).
6. Backups
Encrypted backups are kept for disaster recovery for up to 35 days. Deleted data may persist in a backup until it expires on this cycle, after which it is gone.
7. Legally required retention
Some data must be kept longer to meet tax, accounting, fraud-prevention or regulatory obligations, or to resolve disputes. Such data is isolated, access-restricted, and never used for product analytics or marketing.
8. Security and destruction
Retained data is protected by encrypted storage, role-based access control, activity logging and regular security audits. When data reaches end of life, digital records are permanently erased using industry-standard methods, and any physical records are securely destroyed.
9. Changes to this policy
We may revise this policy as our technology, regulations or operations change. The latest version is always available on this page with a new “Last updated” date.
10. Contact
Questions about data retention? Contact:
Wittelsbach Private Limited
Banjara Hills, Road No. 12, Hyderabad – 500034, Telangana, India
Email: info@wittelsbach.ai
Website: https://www.wittelsbach.ai