HCM Integrations & Analytics Hub logo with text around a circle conating a graphic of three people in a rising bar graph split with an right upward arrow.
Tap Innovations Logo and Paycor logo side-by-side
Data Privacy

Data Retention &
Deletion Policy

How long TAP Innovations, LLC retains Customer Data, and how data is exported, deleted, or anonymized when the customer relationship ends.

Last Updated: June 1, 2026

help@tapinnov.com

TAP Innovations, LLC — Data Retention & Deletion Policy


This policy describes how long TAP Innovations, LLC retains Customer Data, account data, and operational records, and how data is exported, deleted, or anonymized when the customer relationship ends or upon a valid deletion request.

7.1 Principles


  • Data minimization: we collect and retain only what is needed to provide and improve the Services and to comply with legal obligations.
  • Purpose limitation: data is retained for the purposes for which it was collected or as otherwise permitted by law.
  • Defined retention periods: each category of data has an associated retention period reviewed periodically.
  • Secure deletion: when retention ends, data is deleted, overwritten, or anonymized.

7.2 Retention Schedule


The following schedule governs retention. Specific periods may be adjusted by Negotiated Agreement, customer configuration, or applicable law.

Data Category Indicative Retention
Active Customer Data Retained while the subscription is active and the data is needed to deliver the Services. Customers inactive for 90+ days without renewal will receive written notice before data removal.
Post-Termination Data Retained for a transition window (typically 30 days) to allow export, then deleted from active systems.
Backups Encrypted backups age out per the backup schedule, generally within 90 days of creation.
Account and Billing Records Retained for as long as needed to manage the account and to satisfy tax, accounting, and audit requirements (typically 7 years).
Support Communications Retained for service quality, training, and dispute resolution (typically up to 3 years).
Security and Audit Logs Retained for security monitoring and forensics (typically 12 months in hot/warm storage, up to 36 months in cold/archive storage, then deleted).
Marketing Records Retained while the contact relationship is active (defined as having interacted or not opted out within the preceding 24 months), and deleted within 90 days of opt-out or verified inactivity.

7.3 Customer-Initiated Export and Deletion


During the subscription term, customers can export Customer Data through in-product tools or supported APIs. On termination, customers may request a final export during the post-termination transition window. After the window closes, Customer Data will be deleted from active systems and will age out of backups in the ordinary course.

7.4 Individual Data Subject Requests


Individuals with rights under applicable law (such as CCPA/CPRA or similar state laws) may request deletion of their personal data. Where we act as a processor on a customer’s behalf, we will route the request to the customer; where we are the controller, we will respond directly. Requests are described in Section 6.

7.5 Legal Holds and Exceptions


We may retain data beyond the schedule above where required by law, contract, regulatory request, litigation hold, or where reasonably necessary to investigate fraud or security incidents.

7.7 Secure Deletion Methods


  • Logical deletion in production systems is followed by physical overwrite or cryptographic erasure as managed by Azure storage services.
  • Media disposal in cloud data centers is governed by Microsoft’s documented secure disposal procedures.
GET IN TOUCH

Contact the TAP Legal & Security Team

Reach out for any questions about our data retention, deletion, or privacy policies.

Get in Touch

TAP Innovations | the App Place