Data retention and disposal policy
Effective 19 August 2026 · Version 1.0
Policy owner: Data Protection Officer
Organization: GenesisX Group LLC, operator of Tovi
Review frequency: At least annually and upon material changes to Tovi's systems, products, data processing activities, or legal obligations.
1. Purpose
This Data Retention and Disposal Policy establishes requirements for the retention, deletion, and secure disposal of personal, financial, and operational information collected or processed by Tovi.
Tovi seeks to retain personal data only for as long as reasonably necessary to fulfill the purposes for which it was collected, meet legitimate business or legal requirements, resolve disputes, prevent fraud, and protect the security of its services.
When information is no longer required, Tovi deletes, destroys, anonymizes, or otherwise renders it inaccessible using methods appropriate to the nature and sensitivity of the information.
2. Scope
This policy applies to information under Tovi's control, including information stored or processed through:
- Tovi's website and application
- Eligibility assessments
- Financial account connections
- Plaid
- Supabase
- Document and file storage systems
- Administrative systems
- Cloud infrastructure
- Application logs
- Devices used by authorized personnel
- Third party service providers processing information on Tovi's behalf
This policy applies to employees, contractors, officers, administrators, and other personnel authorized to access Tovi information.
3. General Retention Principles
Tovi follows the following principles when retaining information:
- Personal data must not be retained longer than reasonably necessary for the purpose for which it was collected.
- Retention periods should reflect the sensitivity of the information and the purpose for which it is processed.
- Access to retained information must remain restricted to authorized personnel and systems.
- Information subject to a valid deletion request should be deleted unless Tovi has a lawful or legitimate reason to retain it.
- Information subject to a legal, regulatory, fraud, security, or dispute-related preservation requirement may be retained beyond the ordinary retention period.
- Data that has been irreversibly anonymized so that an individual can no longer reasonably be identified may be retained for analytical or statistical purposes.
4. Retention Schedule
Tovi applies the following standard retention periods.
Eligibility Assessment Information
Eligibility assessment responses, including identity, contact, employment, income, financing, and borrowing information:
Retention period: 24 months from submission.
The information may be deleted earlier following a valid deletion request unless continued retention is necessary for legal, fraud-prevention, security, or dispute-resolution purposes.
Uploaded Financial Documents
Bank statements and other financial documents uploaded for income verification:
Retention period: 12 months from upload.
Documents may be deleted earlier upon a valid request or when Tovi determines that they are no longer necessary for the applicable assessment.
Financial Data Received Through Plaid
Financial information received through a Plaid connection, which may include balances, transactions, income information, deposit information, account information, and account ownership information:
Retention period: up to 12 months from collection.
Tovi may delete this information earlier when:
- It is no longer necessary for the assessment or service requested by the consumer
- The consumer submits a valid deletion request
- The financial account connection is terminated and retention is no longer reasonably necessary
- Applicable requirements require earlier deletion
Tovi does not retain Plaid-derived financial information solely because it may be useful for an unspecified future purpose.
Plaid Connection Credentials and Tokens
Plaid access tokens, connection identifiers, and similar technical credentials are retained only for as long as reasonably necessary to maintain an authorized financial account connection or provide the requested service.
When a connection is permanently terminated or the associated data is required to be deleted, Tovi will disable, revoke, or delete applicable connection credentials where technically supported and appropriate.
Incomplete Document Uploads
Files or records associated with incomplete document upload processes:
Retention period: 7 days.
After this period, incomplete uploads are deleted unless the user subsequently completes the submission.
Abuse Prevention Information
One-way hashes of IP addresses used for rate limiting and abuse prevention:
Retention period: 24 hours.
The original IP address is not retained by Tovi for this purpose.
Application and Security Logs
Application, authentication, error, and security logs are retained only for as long as reasonably necessary for security monitoring, troubleshooting, fraud prevention, and system administration.
Where Tovi controls the applicable retention configuration, logs containing personal data should generally be retained for no longer than 12 months, unless a shorter or longer period is reasonably necessary for an active security investigation or legal obligation.
Marketing Attribution Information
Campaign identifiers, referral information, and related advertising attribution information are retained only for as long as reasonably necessary to evaluate campaign performance and maintain applicable business records.
Sensitive financial information received through Plaid or uploaded financial documents must not be intentionally included in advertising or marketing attribution records.
Data Subject Requests
Records necessary to document privacy requests and Tovi's response may be retained for a reasonable period after the request is resolved to demonstrate compliance, prevent repeated unauthorized requests, and resolve disputes.
Tovi will minimize the personal information retained for this purpose.
Anonymized and Aggregated Information
Information that has been irreversibly anonymized or aggregated so that it can no longer reasonably be associated with an identifiable individual may be retained indefinitely for statistical, analytical, product development, or research purposes.
5. Account Disconnection and Plaid Data
If a consumer disconnects or revokes access to a financial account, Tovi will stop requesting new data through that connection as soon as reasonably practicable.
Tovi will review information previously obtained through the connection and delete information that is no longer reasonably necessary for the service requested by the consumer, subject to applicable legal, regulatory, security, fraud prevention, and dispute-related retention requirements.
Where technically supported and appropriate, associated Plaid access credentials will also be revoked, disabled, or deleted.
6. Data Subject Deletion Requests
Consumers may request deletion of their personal data by contacting Tovi's Data Protection Officer at max@genesisglobal.group.
Upon receiving a valid request, Tovi will:
- 1.Verify the identity of the requester where reasonably necessary.
- 2.Identify personal data associated with the individual.
- 3.Determine whether any information must be retained for a lawful or legitimate reason.
- 4.Delete or anonymize information that is no longer required.
- 5.Take reasonable steps to address applicable copies held by processors acting on Tovi's behalf.
- 6.Document completion of the request.
Information that must be retained for legal, regulatory, fraud-prevention, security, contractual, or dispute-related purposes will be isolated or restricted where appropriate and deleted when the applicable reason for retention ends.
7. Secure Disposal
Personal and financial information must be disposed of using methods designed to prevent unauthorized recovery or reconstruction.
Depending on the system and type of information, disposal may include:
- Permanent deletion of database records
- Permanent deletion of files from private object storage
- Revocation or deletion of access credentials and tokens
- Cryptographic deletion where supported
- Secure deletion through cloud provider functionality
- Removal of information from authorized personnel devices where applicable
- Physical destruction of storage media where physical media containing sensitive information is retired
- Irreversible anonymization where retention of statistical information is appropriate
Sensitive information must not be disposed of through insecure methods that would leave it reasonably accessible to unauthorized persons.
8. Backups
Tovi primarily relies on cloud service providers for infrastructure, storage, redundancy, and backup capabilities.
Deletion from active production systems may not immediately remove information from encrypted backup systems where individual records cannot reasonably be removed without affecting the integrity of the backup.
Where this occurs:
- Backup information remains protected by applicable access and security controls.
- Backup copies are retained only according to the service provider's normal backup lifecycle.
- Deleted information is not intentionally restored to active processing except where required for legitimate disaster recovery.
- If a backup containing previously deleted information must be restored, Tovi will take reasonable steps to reapply applicable deletion requests and retention rules.
9. Third Party Service Providers
Tovi uses third party service providers to process or store information, including providers such as Plaid, Supabase, and Cloudflare.
Tovi seeks to use providers that maintain appropriate security, retention, and disposal practices for the nature of the information processed.
Where Tovi instructs a processor to delete information, the processor may retain limited copies in backups, security logs, or other systems according to its contractual terms, documented retention cycles, or legal obligations.
Tovi remains responsible for managing personal data under its control and for selecting service providers appropriate to the sensitivity of the information involved.
10. Legal Holds and Retention Exceptions
Ordinary retention periods may be suspended when information is reasonably necessary for:
- Compliance with applicable law or regulation
- A court order or governmental request
- Pending or reasonably anticipated litigation
- Investigation of suspected fraud
- Investigation of a security incident
- Enforcement of contractual rights
- Establishment, exercise, or defense of legal claims
Information retained under an exception must not be kept indefinitely merely because an exception once existed.
When the reason for the exception ends, the information will return to its ordinary retention and disposal schedule.
11. Responsibility
The Data Protection Officer is responsible for oversight of this policy.
Personnel with access to personal or financial information are responsible for following applicable retention and disposal requirements and must not retain unauthorized personal copies of consumer information.
Tovi's technical and administrative personnel are responsible for configuring retention and deletion mechanisms in systems under their control where reasonably practicable.
12. Periodic Review
Tovi will review:
- The categories of personal data it maintains
- The purposes for retaining that data
- Applicable retention periods
- Service provider retention practices
- Technical deletion procedures
- Legal and regulatory requirements
at least annually and when material changes occur to Tovi's products, systems, vendors, or processing activities.
Retention periods that are no longer justified by a legitimate purpose will be shortened or removed.
13. Policy Compliance
Material exceptions to this policy must be documented and approved by the Data Protection Officer or company leadership.
Failure by personnel to comply with this policy may result in suspension or removal of access to Tovi systems.
14. Policy Review and Approval
This policy will be reviewed at least annually and updated as necessary.
See also our privacy notice, which explains what personal data Tovi collects and your rights under the Data Privacy Act of 2012, and our information security policy.