Tovi

Retention policy

Data retention and disposal policy

Effective 19 August 2026 · Version 1.0

Policy owner: Data Protection Officer

Organization: GenesisX Group LLC, operator of Tovi

Review frequency: At least annually and upon material changes to Tovi's systems, products, data processing activities, or legal obligations.

1. Purpose

This Data Retention and Disposal Policy establishes requirements for the retention, deletion, and secure disposal of personal, financial, and operational information collected or processed by Tovi.

Tovi seeks to retain personal data only for as long as reasonably necessary to fulfill the purposes for which it was collected, meet legitimate business or legal requirements, resolve disputes, prevent fraud, and protect the security of its services.

When information is no longer required, Tovi deletes, destroys, anonymizes, or otherwise renders it inaccessible using methods appropriate to the nature and sensitivity of the information.

2. Scope

This policy applies to information under Tovi's control, including information stored or processed through:

This policy applies to employees, contractors, officers, administrators, and other personnel authorized to access Tovi information.

3. General Retention Principles

Tovi follows the following principles when retaining information:

4. Retention Schedule

Tovi applies the following standard retention periods.

Eligibility Assessment Information

Eligibility assessment responses, including identity, contact, employment, income, financing, and borrowing information:

Retention period: 24 months from submission.

The information may be deleted earlier following a valid deletion request unless continued retention is necessary for legal, fraud-prevention, security, or dispute-resolution purposes.

Uploaded Financial Documents

Bank statements and other financial documents uploaded for income verification:

Retention period: 12 months from upload.

Documents may be deleted earlier upon a valid request or when Tovi determines that they are no longer necessary for the applicable assessment.

Financial Data Received Through Plaid

Financial information received through a Plaid connection, which may include balances, transactions, income information, deposit information, account information, and account ownership information:

Retention period: up to 12 months from collection.

Tovi may delete this information earlier when:

Tovi does not retain Plaid-derived financial information solely because it may be useful for an unspecified future purpose.

Plaid Connection Credentials and Tokens

Plaid access tokens, connection identifiers, and similar technical credentials are retained only for as long as reasonably necessary to maintain an authorized financial account connection or provide the requested service.

When a connection is permanently terminated or the associated data is required to be deleted, Tovi will disable, revoke, or delete applicable connection credentials where technically supported and appropriate.

Incomplete Document Uploads

Files or records associated with incomplete document upload processes:

Retention period: 7 days.

After this period, incomplete uploads are deleted unless the user subsequently completes the submission.

Abuse Prevention Information

One-way hashes of IP addresses used for rate limiting and abuse prevention:

Retention period: 24 hours.

The original IP address is not retained by Tovi for this purpose.

Application and Security Logs

Application, authentication, error, and security logs are retained only for as long as reasonably necessary for security monitoring, troubleshooting, fraud prevention, and system administration.

Where Tovi controls the applicable retention configuration, logs containing personal data should generally be retained for no longer than 12 months, unless a shorter or longer period is reasonably necessary for an active security investigation or legal obligation.

Marketing Attribution Information

Campaign identifiers, referral information, and related advertising attribution information are retained only for as long as reasonably necessary to evaluate campaign performance and maintain applicable business records.

Sensitive financial information received through Plaid or uploaded financial documents must not be intentionally included in advertising or marketing attribution records.

Data Subject Requests

Records necessary to document privacy requests and Tovi's response may be retained for a reasonable period after the request is resolved to demonstrate compliance, prevent repeated unauthorized requests, and resolve disputes.

Tovi will minimize the personal information retained for this purpose.

Anonymized and Aggregated Information

Information that has been irreversibly anonymized or aggregated so that it can no longer reasonably be associated with an identifiable individual may be retained indefinitely for statistical, analytical, product development, or research purposes.

5. Account Disconnection and Plaid Data

If a consumer disconnects or revokes access to a financial account, Tovi will stop requesting new data through that connection as soon as reasonably practicable.

Tovi will review information previously obtained through the connection and delete information that is no longer reasonably necessary for the service requested by the consumer, subject to applicable legal, regulatory, security, fraud prevention, and dispute-related retention requirements.

Where technically supported and appropriate, associated Plaid access credentials will also be revoked, disabled, or deleted.

6. Data Subject Deletion Requests

Consumers may request deletion of their personal data by contacting Tovi's Data Protection Officer at max@genesisglobal.group.

Upon receiving a valid request, Tovi will:

  1. 1.Verify the identity of the requester where reasonably necessary.
  2. 2.Identify personal data associated with the individual.
  3. 3.Determine whether any information must be retained for a lawful or legitimate reason.
  4. 4.Delete or anonymize information that is no longer required.
  5. 5.Take reasonable steps to address applicable copies held by processors acting on Tovi's behalf.
  6. 6.Document completion of the request.

Information that must be retained for legal, regulatory, fraud-prevention, security, contractual, or dispute-related purposes will be isolated or restricted where appropriate and deleted when the applicable reason for retention ends.

7. Secure Disposal

Personal and financial information must be disposed of using methods designed to prevent unauthorized recovery or reconstruction.

Depending on the system and type of information, disposal may include:

Sensitive information must not be disposed of through insecure methods that would leave it reasonably accessible to unauthorized persons.

8. Backups

Tovi primarily relies on cloud service providers for infrastructure, storage, redundancy, and backup capabilities.

Deletion from active production systems may not immediately remove information from encrypted backup systems where individual records cannot reasonably be removed without affecting the integrity of the backup.

Where this occurs:

9. Third Party Service Providers

Tovi uses third party service providers to process or store information, including providers such as Plaid, Supabase, and Cloudflare.

Tovi seeks to use providers that maintain appropriate security, retention, and disposal practices for the nature of the information processed.

Where Tovi instructs a processor to delete information, the processor may retain limited copies in backups, security logs, or other systems according to its contractual terms, documented retention cycles, or legal obligations.

Tovi remains responsible for managing personal data under its control and for selecting service providers appropriate to the sensitivity of the information involved.

10. Legal Holds and Retention Exceptions

Ordinary retention periods may be suspended when information is reasonably necessary for:

Information retained under an exception must not be kept indefinitely merely because an exception once existed.

When the reason for the exception ends, the information will return to its ordinary retention and disposal schedule.

11. Responsibility

The Data Protection Officer is responsible for oversight of this policy.

Personnel with access to personal or financial information are responsible for following applicable retention and disposal requirements and must not retain unauthorized personal copies of consumer information.

Tovi's technical and administrative personnel are responsible for configuring retention and deletion mechanisms in systems under their control where reasonably practicable.

12. Periodic Review

Tovi will review:

at least annually and when material changes occur to Tovi's products, systems, vendors, or processing activities.

Retention periods that are no longer justified by a legitimate purpose will be shortened or removed.

13. Policy Compliance

Material exceptions to this policy must be documented and approved by the Data Protection Officer or company leadership.

Failure by personnel to comply with this policy may result in suspension or removal of access to Tovi systems.

14. Policy Review and Approval

This policy will be reviewed at least annually and updated as necessary.

See also our privacy notice, which explains what personal data Tovi collects and your rights under the Data Privacy Act of 2012, and our information security policy.