Data Retention and Deletion
- Contracting entity
- Omni Data Tech Inc., an Ontario corporation, 3601 Highway 7 East, Suite 1006, Markham, Ontario, L3R 0M3, Canada
- Effective
- 2026-08-30
- Version
- 1.1
- Last updated
- 2026-08-30
- Posted at
- https://fieldzeus.com/legal
- Privacy requests
- [email protected]
- Legal notices
- [email protected]
This Data Retention and Deletion Policy (this "Policy") is a published notice describing Zeus's data retention and deletion practices. It is referenced by the Zeus Privacy Policy and the Zeus Terms of Service (the "Terms"); the retention, deletion and post-termination data rules stated here take contractual effect through the Terms, which incorporate this Policy's subject matter. This Policy applies to every Customer, Workspace, Account, Authorized User and Link Recipient and to all data processed through the Services. Capitalized terms not defined here have the meanings given in the Terms and the Defined Terms Register. This Policy sits at precedence tier 5: where it conflicts with the Terms, a Supplement, the DPA or an enterprise agreement, those documents control. Jurisdictional privacy supplements modify this Policy only to the extent mandatory law requires.
1. Purpose, Scope and Zeus's Retention Rights
1.1 Scope of this Policy
This Policy states: the general standard by which Zeus retains data; the published Retention Schedule; how deletion requests and the in-app account-deletion feature operate; how backups and backup rotation interact with deletion; which records survive account purge by design; what happens to Customer Data after Termination; the retention and downgrade model for photos and media; the allocation of responsibility for Offline Data on the Customer's own devices; and the survival of Aggregated Data. This Policy does not grant any access, export or retention right not expressly stated in the Terms, and nothing in this Policy enlarges any Zeus obligation stated in the Terms, the Privacy Policy or the DPA.
1.2 General retention standard
Zeus retains Customer Content, Customer Data, End-Customer Data, Account Data, Personal Information, Usage Data and Telemetry for as long as reasonably required to fulfil the purposes for which the data was collected — including providing, securing, maintaining and improving the Services — unless a longer retention period is required or permitted by applicable law. Zeus may retain any category of data for a period of time consistent with the original purpose of its collection; retention is keyed to purpose, not to fixed calendar limits, except where the Retention Schedule in Section 2 publishes a specific parameter.
1.3 Zeus sets and may change retention periods and storage limits
Zeus may establish — and may change at any time — general practices and limits concerning use and storage within the Services, including the maximum period of time that data or other content will be retained by the Services and the maximum storage allocated to a Workspace, plan or feature.
1.4 Retention beyond account closure
Following closure, termination or deactivation of an Account or Workspace, Zeus may retain Customer Data and Personal Information for the purposes set out in this Policy and the Privacy Policy, including backup, archival, account recovery, fraud and abuse prevention, security, dispute resolution, enforcement of the Terms and Zeus's other agreements, analysis of aggregated, non-personally identifiable data, and compliance with legal and regulatory obligations, or as otherwise permitted by law. Retention for these purposes may continue for as long as a valid business reason exists — which may be indefinitely — including where information is retained indefinitely in connection with legal claims or fraud prevention. Zeus may retain any data for a longer period in the event of a complaint or where Zeus reasonably believes there is a prospect of litigation in respect of its relationship with the Customer or any individual.
2. Retention Schedule
2.1 The published schedule
Every parameter below that is stated as a number of hours or days is enforced by a scheduled, monitored job running on Zeus's production infrastructure. Where no such job runs, this Policy states the general standard in Section 1.2 rather than a period: Zeus does not publish a retention period it does not operate.
| Data tier | Current parameter |
|---|---|
| Product analytics events — raw | 30 days |
| Mobile synchronization telemetry — raw per-attempt records | 30 days |
| Mobile synchronization telemetry — daily aggregated rollups | 365 days |
| Crash reports, error stacks, session records, and aggregated analytics other than the synchronization rollups above | Retained for as long as necessary for the purposes described in this Policy; removed on account purge (Section 3) |
| Server diagnostic logs | 30 days |
| Resolved synchronization conflict records | 180 days |
| Field-level before-images (the record of what a field held before an edit) | 180 days |
| Push notification registration tokens, after removal | 30 days |
| Sign-in abuse and rate-limiting counters | 7 days |
| In-progress signature sessions, before a document is signed | 6 hours |
| Internal background-job records | 7 days once completed; 90 days once failed and abandoned |
| Workspaces abandoned before signup is completed | 24 hours |
| Photos — full-resolution media after a retention downgrade triggers | 60-day grace period, at or after the end of which the full-resolution file is downgraded to a thumbnail (Section 7) |
| Photos — thumbnails | Retained for the life of the Workspace; removed only on account purge (Section 7) |
| Business logos, user signature images and avatars | Retained until user deletion or account purge; never thumbnailed by retention |
| Invoices, payments, signing records, communication timelines and other Workspace records | Retained for the life of the Workspace; removed on account purge (Sections 3 and 5) |
| Zeus's own customer, billing and tax records | Statutory periods, typically 6–7 years, jurisdiction-set (Sections 2.2 and 5) |
| Account and Workspace data after a verified deletion request | Deactivated immediately; a daily sweep purges records and stored objects deactivated more than 30 days earlier, subject to Sections 3.2 and 3.3 |
| Audit trails and the tenant-deletion ledger | Append-only; survive account purge by design (Section 5) |
| Backup copies | Purged as backup copies rotate out of Zeus's backup retention (Section 4) |
| Every other category | Retained for as long as necessary for the purposes described in this Policy (Section 1.2) |
2.1A Access links expire; expiry is not deletion
As a product fact: links the Services issue to a Link Recipient — including a client hub link and a link to view a quote, invoice or other document — carry an expiry, and may also be revoked at any time by the Customer that issued them. When a link expires or is revoked, access through that link ends. Expiry is not deletion: the underlying records remain in the Workspace and are retained under this Policy until the Workspace's records are removed under Section 3 or Section 5.
2.2 Statutory financial and tax retention
Zeus is required by law to keep basic information about its customers — including contact, identity, financial and transaction data — for extended statutory periods after they cease being customers, for tax, audit and compliance purposes. For example, invoice and financial-transaction information is kept for the tax-law period applicable in the relevant jurisdiction — typically six (6) to seven (7) years — and deletion requests cannot override these statutory periods. These statutory obligations attach to Zeus's records of its own business relationship with the Customer. They do not except invoices, payments or other records held inside a Workspace from an account purge: those records are removed on purge as described in Section 5.1. Where a statutory obligation requires Zeus to retain a specific record notwithstanding a deletion request, Zeus retains that record on the grounds stated in Section 3.3.
2.3 Status of the schedule; changes
The Retention Schedule states Zeus's practices as at the Effective Date; it is a point-in-time disclosure, not a contractual commitment to any minimum or maximum retention period, and Zeus may change any parameter in it at any time under Section 1.3, with the posted version of this Policy stating the then-current parameters. A period appears in the Retention Schedule only where a scheduled job enforces it. Where a deletion routine exists but is not scheduled, or where no period has been set, the Retention Schedule states the general standard in Section 1.2 instead of a number, and the data concerned is retained for as long as necessary for the purposes described in this Policy.
3. Deletion Requests; Two-Phase Deletion; No Promised Purge Timing
3.1 How to request deletion; routing and verification
Deletion may be requested (a) in-app, through the account-deletion feature available in the profile settings of the mobile application, or (b) by writing to [email protected]. Requests are processed under the Privacy Policy's rights procedures, which govern identity verification, authorized agents, refusal and charging grounds, response windows, and the routing rule for End-Customer Data: where a request concerns End-Customer Data or Worker Data that a Customer causes Zeus to process, Zeus redirects the request to that Customer and provides assistance to the Customer only, as described in the Privacy Policy and, for enterprise customers, the DPA. This Section 3 describes only what deletion operationally does once a request is accepted.
3.2 Two-phase deletion; no committed purge timing
Account deletion is two-phase: on acceptance of a verified request, the Account and Workspace are immediately deactivated and all active sessions are revoked, ending access to the Services; the underlying records and stored objects are then purged in a second phase. The second-phase purge runs as soon as reasonably practicable, unless applicable law or regulation requires otherwise; the purge process may include internal processing and rollback stages, and Zeus does not commit to any fixed automatic purge timeline. As at the Effective Date, and as a current practice published under Section 2.3 rather than a commitment, the second phase is performed by a sweep that runs daily and collects Accounts and Workspaces deactivated more than thirty (30) days earlier. That is a description of how the sweep currently runs, not a promise that any particular record will be gone on any particular day, and it is subject to Section 3.3.
A request to delete Personal Information forfeits the Account: once deletion is requested the requester will no longer have access to the existing Account or Workspace and will not be able to use the Services through it.
3.3 Grounds on which deletion is refused or data is retained
Zeus may deny a deletion request, or delete only part of the data concerned, where retaining the information is necessary for Zeus or its service providers to: complete a transaction or perform an agreement with the Customer; detect or prevent fraud, abuse or security incidents; troubleshoot problems; assist with investigations; enforce the Terms or other legal terms; exercise or defend legal claims; or comply with applicable legal requirements. Even after a request that an account or information be permanently deleted, Zeus may retain and use the information as necessary to comply with its legal obligations, resolve disputes and enforce its agreements.
3.4 Residual copies; complete erasure may be impossible
It is not technologically possible to remove each and every record of the information provided to Zeus from Zeus's systems, and the Customer acknowledges that complete erasure of all copies may be impossible. After information is deleted from the Services, residual copies may persist on active systems for a period before removal, and copies in backup systems are removed only on the backup schedule described in Section 4, in accordance with applicable law.
3.5 Uninstalling the application deletes nothing server-side
Uninstalling the Zeus mobile application through the device's procedures for uninstalling downloaded applications removes only the application from that device: Zeus may retain all data already collected or synchronized to Zeus's systems after the uninstallation, and uninstallation is not a deletion request.
3.6 No general duty to edit or delete submitted content
Except as expressly stated in this Policy or required by applicable law, Zeus is under no obligation to edit, delete or otherwise modify Customer Content once it has been submitted to the Services.
4. Backups and Backup Rotation
4.1 Backups are excluded from targeted deletion; purge on scheduled rotation
Deletion — whether by in-app feature, verified request or Termination — does not extend to Customer Data stored on backups, which is destroyed in accordance with Zeus's standard destruction practices for backup data as backup copies rotate out of Zeus's backup retention, due to the cost and technical difficulty of deleting individual records from backups. Zeus does not publish the rotation interval in this Policy; it is a security and continuity parameter Zeus may change at any time under Section 1.3. Until a backup copy is destroyed on rotation, it remains protected under the Terms and this Policy, and Zeus has no obligation to restore, maintain or provide any Customer Data from backups.
4.2 Isolation until deletion is possible; extended backup retention grounds
Where deletion of Personal Information is not immediately possible — for example because it has been stored in backup archives — Zeus will securely store the information and isolate it from any further processing until deletion is possible. Zeus may retain information for longer periods as permitted or required by law, including to maintain suppression lists, to prevent abuse, or where required in connection with a legal claim or proceeding.
5. Append-Only Records; What Survives Account Purge, and What Does Not
5.1 Two different things are called "append-only"; only one of them survives purge
Many record types in the Services are append-only: while the Workspace exists they cannot be edited or deleted, and a correction is made by writing a reversing entry rather than by altering or removing the original. This is a data-integrity property. It is not, by itself, an exemption from deletion, and this Policy distinguishes the two.
Records that survive account purge. The following are retained after account purge, Termination and the termination of any DPA, as evidence of the orderly and accurate processing of data in the Services and for the statutory retention purposes described in Section 2.2:
- the Workspace audit log — the record of what was done in the Services and by whom;
- Zeus's internal administrative and operator audit log; and
- the tenant-deletion ledger — the record that an erasure was requested and performed, which must outlive the Workspace it records, because a ledger a purge could erase would be no record at all.
Records that are append-only but do NOT survive account purge. Invoices, payments, payment applications, refunds and receivable adjustments, other financial and commercial entries, signature and signing-evidence records, document records, the client communication timeline, and security and abuse events are append-only for the life of the Workspace — no user and no ordinary Zeus process can edit or delete them, and corrections are reversing entries — but they are erased with the rest of the Workspace's records on account purge, under Section 3.
Accordingly, a deletion request or account purge removes the Customer-facing records and stored objects described in Section 3, including the financial and signing records named above, and does not remove the audit logs and deletion ledger retained under this Section. Section 3.3 states the separate grounds on which Zeus may decline to delete a specific record, and Section 3.4 states why residual and backup copies may persist for a period after that.
5.2 Signing Events and Evidence Packages
As a product fact: Signing Events and their Evidence Packages (signer details, signature image, IP address, device summary, optional GPS-at-signing, content hashes, consent records and server timestamps) are recorded in an append-only trail. That trail cannot be edited or deleted for the life of the Workspace, and it is erased with the Workspace on account purge under Section 5.1; the audit log's record that the signing occurred survives.
Because the Evidence Package does not survive account purge, retaining executed copies is the responsibility of the parties to the signed document. Zeus does not promise post-termination delivery of executed copies to signers or to any other party, and a party that will need the evidence of execution later should download and keep it while the Workspace is live.
6. Customer Data After Termination; Discretionary Retrieval Window
6.1 Export before Termination is solely the Customer's responsibility
The Customer is solely responsible for downloading and backing up its Customer Content and Customer Data before Termination, using the live self-serve export available in the Services during the term. In-term export assistance beyond the self-serve export, if Zeus elects to provide it, may be subject to fees at the Customer's cost.
6.2 Effect of Termination on data; no export warranty; no migration duty
From Termination, access ends: the Customer's Content and all other data will no longer be accessible through the Account or Workspace. Except as required by law, Zeus has no obligation to maintain, retain or provide the Customer with copies of Customer Content or Customer Data after Termination, and Zeus makes no warranty as to the availability of, or the capability to transfer, use or export, any data after Termination. Zeus is not obligated to provide migration, transition, export or support services after Termination unless expressly required by law or agreed in writing; any hand-over assistance to the Customer or a successor provider is at Zeus's sole discretion and, if provided, is chargeable at Zeus's then-current rates.
6.3 Discretionary retrieval window — up to 30 days; none for the Free Plan
As a discretionary courtesy only, Zeus MAY keep Customer Data retrievable for up to thirty (30) days following Termination of a paid Subscription; commencing on day 31 following Termination, Zeus has no obligation of any kind to maintain or provide Customer Data and reserves the right to permanently delete it. If retrieval is provided, Zeus determines in its sole discretion the format, method and manner in which any Customer Data is made available, retrieval may be subject to applicable fees, and Zeus's efforts are limited to commercially reasonable efforts. Zeus makes no representation as to the integrity, completeness or timeliness of any data made available or exported under this Section. For Free Plan Workspaces, Zeus provides no access to Customer Data after Termination or expiration: the retrieval window under this Section is zero.
6.4 After the window: deletion, archiving, retention or anonymization at Zeus's sole discretion; no liability
After any retrieval window (and immediately on Termination for Free Plan Workspaces), Zeus may deactivate the applicable Account(s) and permanently delete, archive, retain or anonymize Customer Data, in Zeus's sole discretion, in accordance with its policies and applicable law. Where any data is left in a closed or terminated Workspace, Zeus may continue to retain it under this Policy but may also delete it at any time at its discretion. Termination or restriction of access may include removal of, or access restrictions on, some or all materials, records and data in the Account, and Zeus is not liable to the Customer or any third party for termination of access to the Services, or for deletion, loss, corruption, export failure, or inability to access Customer Data after termination, suspension, downgrade, nonpayment, or expiration.
6.5 Third-party and legal-process requests; litigation holds
Third parties seeking Customer Data — including under litigation holds, subpoenas or other legal process, and whether before or after Termination — must follow Zeus's procedures for such requests; Zeus retains sole discretion over the disposition of Customer Data under Section 6.4 except to the extent a legal obligation binding on Zeus requires otherwise.
6.6 Enterprise DPA carve-out
For enterprise customers with an executed DPA, the DPA alone carries a return-or-delete-on-written-request duty, subject to the DPA's legal-hold, backup-isolation and anonymization-equivalence carve-outs. Nothing in this Policy creates any return or deletion duty for any other customer, and where the DPA applies its terms control over this Policy for personal-data-processing subject matter.
7. Photo and Media Retention; Downgrade Grace; Thumbnails
7.1 The photo retention and downgrade model
As a product fact: photo bytes are stored in Zeus's region-pinned object storage with EXIF metadata (including GPS) stripped from the stored image server-side; capture time and optional GPS metadata are retained as database records and made available to the Account Owner. When a retention downgrade triggers for a Workspace (for example, on plan limits or downgrade), affected full-resolution media enters a sixty (60) day grace period; at or after the end of the grace period the full-resolution media is downgraded to a thumbnail, and the full-resolution file is not retained after that downgrade. Thumbnails are retained for the life of the Workspace and are not hard-deleted by the retention process; they are removed on account purge under Section 3. Business logos, user signature images and avatars are never thumbnailed by retention and are stored until user deletion or account purge.
7.2 No liability for access loss on downgrade
Zeus is not liable for deletion, loss, corruption, export failure, or inability to access full-resolution media or any other Customer Data after termination, suspension, downgrade, nonpayment, or expiration, including where full-resolution media has been downgraded to a thumbnail under Section 7.1.
8. On-Device (Offline) Data
8.1 Offline Data is on the Customer's devices and under the Customer's control
As a product fact: the Zeus mobile application maintains Offline Data — an on-device working copy of Workspace data (local database, unsynchronized outbox and parked conflicts), which can include End-Customer Data and Worker Data — on each device where the application is installed. Offline Data resides under the Customer's and its Authorized Users' physical control, outside Zeus's systems. Server-side deletion, account purge, Suspension and Termination do not — and technically cannot — erase Offline Data on the Customer's devices, and device-level retention and erasure are user-controlled and not centrally enforceable by Zeus. Securing, retaining and erasing Offline Data (including on lost, sold, recycled or decommissioned devices, and after Termination) is the Customer's responsibility, as further allocated in the Terms and the Customer Security Responsibilities Addendum.
8.2 Export files are provided as-is
Any export files generated by the Services (including the self-serve export) are provided as-is, and Zeus is not responsible for any errors or omissions in an export file or for any corruption of the Customer Content that may occur.
9. Aggregated and De-Identified Data Survive Deletion
9.1 Survival, ownership and savings
Notwithstanding anything to the contrary in this Policy, deletion requests, consent withdrawal, account closure, account purge and Termination do not affect Aggregated Data or De-Identified Data: Zeus owns all such data outright and may continue to create, retain and use it during and after the Term, including after account deletion. Aggregated Data and De-Identified Data are not Personal Information, and this Policy's retention and deletion rules do not apply to them. This survival is always subject to the savings pack stated in the Terms and Privacy Policy: such data must never identify the Customer, its clients or any individual; one account's underlying data is never exposed to another account; and Zeus will not attempt to re-identify de-identified information except where necessary to satisfy requirements under applicable law.
10. Mandatory-Law Savings; Jurisdiction-Required Content; Relationship to Other Documents
10.1 Mandatory-law savings
Nothing in this Policy limits any right an individual or the Customer has under mandatory applicable law, and Zeus applies the retention and deletion practices in this Policy as required or permitted by applicable law. Where the law of a jurisdiction requires different treatment, the applicable jurisdictional privacy supplement modifies this Policy for that jurisdiction only and only to the extent mandatory law requires; the global positions in this Policy otherwise remain in full force, and any statutory right to a free copy of Personal Information is honoured through the channels in the Privacy Policy notwithstanding the fee provisions of Section 6.
10.2 Jurisdiction-required disclosure content
The retention and destruction obligations of Canadian, New Zealand and Australian law apply to this Policy of their own force, and the relevant jurisdictional supplement states them.
10.3 Relationship to other documents; survival
This Policy is read together with: the Terms (retention-limits right, uninstall clause, effect-of-termination data clause); the Privacy Policy (rights procedures and retention disclosures) and its jurisdictional supplements (21–24); the Mobile Application EULA (uninstall ≠ delete); the Subscription, Billing, Cancellation and Refund Policy (data on cancellation); the Security and Trust Statement and Enterprise Security Exhibit (backup rotation and isolation facts); the DPA (enterprise deletion/return with carve-outs); and the Customer Security Responsibilities Addendum (device and Offline Data duties). The rules of this Policy concerning retained records, backups, Aggregated Data and post-Termination data survive Termination and account purge to the extent they concern data or records that survive those events.