DATA RETENTION & CUSTOMER EXIT POLICY
This Data Retention & Customer Exit Policy (“Policy”) forms part of the Master Service Agreement (“MSA”) between XploroTech Solutions Private Limited (“XploroTech”, “Company”, “we”, “us”, or “our”) and the Customer.
This Policy applies to VENTA Xploro POS, VENTA Admin, VENTA Insights, VENTA Captain, Xploro AI, related applications, APIs, integrations, support services, and future VENTA-branded services.
This Policy should be read together with the Data Processing Addendum, Privacy Notice, Xploro AI Addendum, Refund & Cancellation Policy, and Subprocessors & AI Data Use Notice.
1. Purpose
This Policy explains:
a. how long XploroTech generally retains Customer Data;
b. how Customers may export or retrieve eligible data;
c. what happens when a subscription expires, is cancelled, suspended, or terminated;
d. how backups, logs, support records, billing records, and AI data may be retained; and
e. the Customer’s responsibilities for statutory, tax, accounting, audit, and business record preservation.
2. Customer Responsibility for Records
2.1 The Customer remains responsible for preserving all records required for its business, tax, GST, accounting, statutory, audit, regulatory, employment, consumer, contractual, and legal obligations.
2.2 VENTA is a software platform and is not a permanent data-archiving, statutory-record preservation, tax-record retention, or regulatory-compliance service unless expressly agreed in an applicable Order Form.
2.3 The Customer must maintain its own independent records, exports, backups, and archives as appropriate for its business and legal obligations.
2.4 Before cancellation, non-renewal, account closure, or expiry of the applicable export period, the Customer must export or obtain copies of the Customer Data it needs to preserve.
2.5 XploroTech is not responsible for losses arising because the Customer failed to download, export, archive, preserve, or retain its required records before the applicable deletion or exit deadline.
3. Types of Data Covered
This Policy may apply to:
a. invoices, orders, payments, refunds, discounts, voids, cancellations, reservations, memberships, loyalty records, inventory records, purchase records, production records, reports, and operational data;
b. customer, guest, employee, supplier, vendor, outlet, user, and contact information;
c. account, subscription, billing, payment-reference, tax, support, and communication records;
d. login logs, access logs, audit logs, device data, diagnostic data, error logs, security records, and API records;
e. support tickets, emails, chats, screenshots, attachments, implementation records, and training records;
f. AI prompts, AI Outputs, AI usage records, routing records, diagnostics, code fragments, schemas, report requests, and AI audit logs; and
g. backups, archives, de-identified data, and aggregated service information.
4. Retention During an Active Subscription
4.1 During an active paid subscription, Customer Data is generally retained for as long as necessary to provide the subscribed Services.
4.2 The Customer may access and export eligible Customer Data using available VENTA functionality, subject to:
a. the Customer’s subscription plan;
b. authorised user permissions;
c. applicable product functionality;
d. technical limitations;
e. storage limits;
f. data integrity and security requirements; and
g. applicable law.
4.3 XploroTech may retain logs, audit records, support records, security records, billing records, and technical records for periods that may extend beyond the active subscription period where reasonably necessary for security, support, fraud prevention, legal compliance, tax, audit, dispute resolution, and enforcement of agreements.
5. Subscription Expiry, Cancellation and Non-Renewal
5.1 If a subscription expires, is cancelled, is not renewed, or is terminated, the Customer’s access to the relevant Services may end on the effective termination date, subject to the MSA and applicable Order Form.
5.2 Unless a different period is stated in an applicable Order Form, the Customer may request export of eligible Customer Data for up to [90] calendar days after the effective termination or expiry date (“Customer Exit Period”).
5.3 During the Customer Exit Period, XploroTech may:
a. restrict ordinary user access;
b. provide limited administrator or export access;
c. require payment of overdue amounts before providing export assistance;
d. charge reasonable fees for non-standard exports, migration assistance, data conversion, restoration, custom reports, or professional services; and
e. require verification of the requester’s authority.
5.4 The Customer is responsible for ensuring that its authorised administrator submits any export request before the end of the Customer Exit Period.
5.5 After the Customer Exit Period, XploroTech may delete, anonymise, archive, or otherwise remove Customer Data from active production systems, subject to Clause 8.
6. Suspension
6.1 If Services are suspended due to non-payment, suspected fraud, misuse, security risk, unlawful activity, or breach of the MSA or Acceptable Use Policy, the Customer may lose access to some or all Services.
6.2 Suspension does not remove the Customer’s obligation to pay outstanding fees or comply with the MSA.
6.3 Where legally and operationally appropriate, XploroTech may permit data export during a suspension after:
a. verifying the Customer’s identity and authority;
b. resolving applicable security concerns;
c. receiving payment of overdue amounts; and
d. confirming that export will not create a legal, fraud, security, privacy, or operational risk.
6.4 XploroTech may refuse, delay, restrict, or condition export where required by law or reasonably necessary to protect the Services, XploroTech, the Customer, other users, or third parties.
7. Data Export
7.1 The Customer may request export of eligible Customer Data through available self-service functionality, the Customer administrator, or the designated VENTA support channel.
7.2 Available export formats may include CSV, Excel-compatible files, PDF, database extract, report files, media files, or other formats supported by the relevant VENTA module.
7.3 XploroTech does not guarantee that all Customer Data can be exported in every format, with every relationship, attachment, historical version, audit trail, third-party integration reference, proprietary configuration, system metadata, or AI context preserved.
7.4 Exports may exclude:
a. XploroTech proprietary software, source code, system prompts, models, internal security controls, algorithms, product configurations, or internal Documentation;
b. data belonging to another Customer or third party;
c. information XploroTech is prohibited from disclosing by law, contract, security requirement, or lawful authority request;
d. information that may compromise security, confidentiality, fraud controls, audit integrity, or another person’s rights; and
e. aggregated, de-identified, anonymised, or internal operational information not reasonably capable of being linked to the Customer.
7.5 The Customer is responsible for reviewing exported data for completeness, compatibility, statutory suitability, and fitness for its intended purpose.
7.6 Any migration to another software provider, data transformation, mapping, cleansing, reconstruction, import support, custom extraction, or reconciliation may be chargeable professional services.
8. Deletion, Archiving and Exceptions
8.1 Following the end of the Customer Exit Period, XploroTech may delete or anonymise Customer Data from active production systems within [30] calendar days, unless a longer period is required or permitted under this Policy.
8.2 XploroTech may retain Customer Data, Personal Data, logs, audit records, support records, billing records, security records, AI records, or other information for longer periods where necessary for:
a. applicable law, tax, accounting, statutory, audit, regulatory, insurance, or legal obligations;
b. court orders, regulatory requests, lawful authority requests, or legal holds;
c. security, fraud prevention, abuse prevention, incident response, forensic investigation, or system integrity;
d. dispute resolution, claim management, debt recovery, contract enforcement, or preservation of evidence;
e. backup, restoration, disaster recovery, business continuity, or technical recovery;
f. maintaining transaction, audit, and activity integrity; or
g. de-identification, anonymisation, aggregation, analytics, benchmarking, research, product improvement, and security improvement.
8.3 Information retained under Clause 8.2 may be restricted from routine access and used only for the relevant retention purpose.
8.4 XploroTech may retain billing, tax, payment, invoice, contractual, account, and legal records for the period required by applicable law or reasonably necessary for business administration, audit, dispute resolution, and legal compliance.
9. Backups and Disaster Recovery
9.1 Customer Data may remain in encrypted or otherwise protected backups after deletion from active production systems.
9.2 Backups are retained according to XploroTech’s standard backup and disaster-recovery schedule, which may be up to [30] calendar days after deletion from active production systems.
9.3 Backup data is generally not available for ordinary customer access, selective deletion, routine restoration, or individual export.
9.4 If backup data is restored for disaster recovery or operational reasons, XploroTech will apply reasonable measures to ensure that previously deleted Customer Data is deleted again in the ordinary course, where technically practicable.
9.5 XploroTech may retain backups for longer where required for legal compliance, security, fraud prevention, disaster recovery, or other lawful purposes.
10. Audit Logs, Security Logs and Technical Records
10.1 XploroTech may retain login logs, access logs, audit trails, transaction records, device records, API logs, diagnostic information, error logs, security logs, and related technical records for at least [180] calendar days or such longer period as XploroTech reasonably determines is necessary.
10.2 Such records may be retained to:
a. investigate fraud, misuse, data loss, unauthorised access, security incidents, and policy violations;
b. support troubleshooting, service management, billing verification, and dispute resolution;
c. maintain system integrity, auditability, and security;
d. comply with legal, regulatory, contractual, or lawful-authority requirements; and
e. protect the rights, property, and safety of XploroTech, Customers, users, and third parties.
10.3 Audit and security logs may not be available for routine customer export where disclosure could compromise security, privacy, audit integrity, or the rights of others.
11. Support, Communication and Training Records
11.1 XploroTech may retain support tickets, emails, chats, call records, screenshots, attachments, training records, implementation notes, project records, issue-resolution history, and related communications for [3] years after the relevant interaction, account closure, or project completion, unless a longer period is required or reasonably necessary.
11.2 Support and communication records may be retained for quality assurance, training, legal compliance, service history, fraud prevention, dispute resolution, and operational continuity.
11.3 The Customer should not submit passwords, OTPs, PINs, full payment-card details, CVV, API secrets, private keys, or other sensitive authentication information in support tickets or communications.
12. AI Data Retention
12.1 Where Xploro AI is enabled, XploroTech may retain AI Inputs, AI Outputs, AI usage records, model-routing records, system logs, safety records, support records, diagnostic records, code fragments, schema details, report requests, and AI audit records for [90] calendar days after the relevant interaction, unless a longer period is required or reasonably necessary.
12.2 AI data may be retained for:
a. providing the requested AI Service;
b. maintaining authorised conversation or task context;
c. quality assurance, safety monitoring, abuse prevention, and fraud prevention;
d. troubleshooting, technical support, debugging, bug analysis, and incident response;
e. auditability, security, legal compliance, and dispute resolution; and
f. improving the reliability, performance, safety, and functionality of Xploro AI.
12.3 XploroTech will not use Customer Data, AI Inputs, AI Outputs, source code, schemas, support logs, or other Customer-specific information to train a general-purpose AI model unless the Customer separately opts in through a written agreement or expressly enabled product setting.
12.4 AI data may also be processed or retained by approved AI Providers in accordance with the AI Subprocessors & Data Use Notice, applicable provider terms, XploroTech’s account configuration, and applicable law.
12.5 The Customer should avoid submitting unnecessary Personal Data, confidential information, credentials, secrets, payment data, or restricted information through AI Services.
13. De-Identified and Aggregated Information
13.1 XploroTech may retain aggregated, anonymised, or de-identified information that does not reasonably identify the Customer or an individual.
13.2 XploroTech may use such information for analytics, benchmarking, reporting, capacity planning, service reliability, security, fraud prevention, product improvement, and research.
13.3 Aggregated, anonymised, or de-identified information may be retained for as long as reasonably necessary for the relevant lawful purpose.
14. Legal Holds and Exceptional Retention
14.1 XploroTech may suspend deletion or destruction of relevant information where it is subject to:
a. a legal hold;
b. actual or anticipated litigation;
c. a regulatory, government, court, tax, audit, insurance, or law-enforcement request;
d. a fraud, misuse, security, or incident investigation; or
e. another legal, contractual, or legitimate business requirement.
14.2 Retained information will be handled in accordance with applicable law, the MSA, the Data Processing Addendum, and XploroTech’s security and confidentiality obligations.
15. Changes to This Policy
15.1 XploroTech may update this Policy from time to time to reflect changes in law, regulations, security practices, backup systems, hosting arrangements, AI Services, product architecture, business operations, or retention requirements.
15.2 XploroTech will publish the updated version in the VENTA Legal Centre and update the document version and effective date.
15.3 For material changes, XploroTech may provide notice through the Services, dashboard, email, website, app notification, or another reasonable electronic method.
16. Contact
For customer-data export, retention, deletion, account closure, or related questions, contact:
Data Export / Account Closure Requests: xplorocare@xplorotech.com
Privacy / Grievance Contact: xploro@xplorotech.com
Security Incident Reporting: xploro@xplorotech.com
Billing / Subscription Requests: xploro@xplorotech.com
Legal Notices: xploro@xplorotech.com
VENTA Legal Centre: https://www.venta-pos.com/





