Data Retention and Account Deletion Policy

Effective Date: September 2, 2026

This policy outlines our approach to data retention and deletion for user accounts, in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR), Czech Act No. 110/2019 Coll. on personal data processing, and other applicable European data protection laws. As required by GDPR Article 5(1)(e) (storage limitation principle), personal data is kept only as long as necessary for the purposes for which it was collected.

1. Account Deletion Request

Upon a user's request to delete their account, we will deactivate the account and remove it from the live environment. This ensures that the account data is no longer visible or accessible on our platform.

2. Data Retention Period

- Retention Duration: User account data will be retained for six (6) months following the initial deletion request.

- Purpose of Retention: The retention period allows users the opportunity to restore their accounts and helps us address any legal, regulatory, or operational requirements that may arise.

3. Data Storage and Security

During the retention period, user data will be securely stored and protected with encryption and access control mechanisms. Access to retained data is limited to authorized personnel only, and data will be used solely for compliance, audit, and legal purposes.

4. Permanent Deletion

At the end of the six-month retention period, personal data that is not subject to a statutory retention duty, legal hold, unresolved claim, fraud-prevention need, or another lawful exception will be permanently deleted or irreversibly anonymized. Backup copies are removed through the normal backup-expiration cycle and are not restored except for disaster recovery.

5. Tax, VAT, Accounting, and Affiliate Payout Records

Affiliate tax profiles, VAT-validation evidence, accepted self-billing agreements, issued tax documents, accounting entries, crypto settlement records, wallet addresses, and transaction hashes are retained for the applicable statutory period. Czech VAT tax documents are normally retained for ten (10) years from the end of the tax period in which the supply took place; related accounting or tax records may be kept for a different or longer period where another law, audit, correction period, dispute, or legal hold requires it. Access is restricted to personnel and advisers who need it for payout, tax, accounting, audit, or legal compliance.

These records are not deleted merely because the affiliate closes their aiAllure account. Where feasible, non-required account data is removed or de-linked while the legally required financial record is preserved.

6. Law Enforcement Preservation & Legal Hold

Notwithstanding the retention periods and deletion procedures described above, we may preserve and retain user data beyond the standard retention period when required for:

  • Active criminal investigations: Upon receipt of a valid preservation request, court order, or other legal process from a competent law enforcement authority (including Czech Police, Europol, INTERPOL, or other national authorities), we will preserve all relevant account data, content, metadata, and access logs for the duration specified in the request or as required by law.
  • Mandatory CSAM reporting: Where we detect or receive a report of suspected Child Sexual Abuse Material (CSAM), we are required under Directive 2011/93/EU and Czech law to preserve all associated evidence and report to NCMEC, Europol, INHOPE, and/or Czech Police. This data will be preserved until law enforcement confirms it is no longer needed.
  • Non-consensual intimate imagery (NCII / deepfake offenses): Where content is flagged under Czech Criminal Code §193b or equivalent laws, associated user data, uploaded reference images, generated outputs, and access logs are preserved for potential law enforcement use.
  • Pending litigation or regulatory proceedings: Where we are aware of pending or reasonably anticipated litigation, arbitration, or regulatory investigation, a legal hold will be placed on all potentially relevant data.
  • DSA compliance: Under the EU Digital Services Act (Regulation 2022/2065, Art. 18), we may be required to preserve data pursuant to orders from Member State authorities.

Scope of preservation: A legal hold may cover account data, chat logs, generated content, uploaded images, IP addresses, device identifiers, payment records, and moderation/compliance audit trails. Users subject to a legal hold will not be informed of the hold where doing so would jeopardize an investigation or where prohibited by the applicable legal process.

Data preserved under a legal hold is stored securely with restricted access, used only for the stated legal purpose, and deleted when the legal obligation expires or law enforcement confirms the data is no longer required.

7. User Rights (GDPR Articles 15-22)

Under GDPR Article 17 (Right to Erasure), users may request deletion of their personal data. We respond within the period required by GDPR Article 12(3). The right is subject to lawful exceptions, including processing needed to comply with tax, VAT, accounting, legal-claim, or other statutory obligations; data covered by an exception is restricted and retained only for the applicable purpose and period.

You also have the right to lodge a complaint with the Czech Data Protection Authority (Úřad pro ochranu osobních údajů, ÚOOÚ) at www.uoou.cz, or with the supervisory authority of your EU/EEA member state of residence.

8. Compliance and Auditing

aiAllure will regularly review and audit its data deletion processes to ensure compliance with GDPR and other applicable laws. This policy will be updated as necessary to reflect regulatory changes or improvements in our data management practices.

Contact Information

For any questions or concerns regarding this policy, please contact us at:

Novera Group s.r.o.
Rybná 716/24
CZ-110 00 Praha 1
hello@aiallure.com