Data Retention Policy
Policy governing how long Frontal retains Customer Data and other categories of data.
Last updated 11. Juni 2026
This Data Retention Policy describes how long Frontal Labs, Inc. ("Frontal," "we," "us," or "our") retains Customer Data and other categories of data processed through the Services. This policy is incorporated into the Terms of Service and supplements our Data Disposal Policy. Capitalized terms not defined here have the meanings given in the Terms of Service.
1. SCOPE
This policy applies to all data processed, stored, or transmitted by Frontal in connection with the Services, including Customer Data, Account Data, Usage Data, and Frontal's operational data.
2. RETENTION PRINCIPLES
Frontal retains data based on the following principles:
- Purpose Limitation. Data is retained only as long as necessary to fulfill the purposes for which it was collected and processed.
- Legal Compliance. Data is retained to comply with applicable legal, regulatory, and contractual obligations.
- Business Necessity. Data is retained as needed to support business operations, security, and legitimate business interests.
- Data Minimization. We periodically review data holdings and minimize data where retention is no longer justified.
3. RETENTION PERIODS BY DATA CATEGORY
3.1 Customer Data
3.2 Account Data
3.3 Usage Data
3.4 Communications Data
3.5 Security Data
4. DELETION UPON REQUEST
4.1 Customers may delete specific Customer Data at any time through the Services interface or API. Upon deletion, data is removed from active systems in accordance with our Data Disposal Policy.
4.2 Upon Account termination, Customer Data is deleted according to the schedule in our Data Disposal Policy.
4.3 Backup data containing deleted Customer Data expires per the backup retention cycle and is not actively purged. Expired backups are securely deleted.
5. EXCEPTIONS TO RETENTION PERIODS
5.1 Legal Holds
Data subject to a legal hold is retained until the hold is released. Frontal preserves data subject to legal holds and does not delete it during the hold period. We will notify the Customer of a legal hold affecting its data unless prohibited by law.
5.2 Legal Obligations
Data may be retained beyond standard periods where required by applicable law, including:
- Tax, accounting, and financial reporting obligations.
- E-discovery and litigation preservation obligations.
- Regulatory investigation requirements.
- Data protection law requirements (e.g., records of consent).
5.3 Security and Abuse Prevention
The following categories of information, to the extent reasonably necessary for fraud prevention, abuse detection, and security purposes, may be retained for up to 12 months after Account termination:
- IP addresses associated with Terms of Service violations.
- Indicators of fraudulent activity.
- Security incident data.
- Blocked Account identifiers.
5.4 Anonymized Data
Data that has been anonymized or de-identified such that it cannot reasonably identify an individual or Customer may be retained indefinitely for research, analytics, and service improvement.
6. DATA EXPORT
Customers may export their data at any time during their Account term using the export tools available in the Services. Supported export formats are described in the Documentation. We recommend exporting data before initiating Account deletion.
7. CUSTOMER OBLIGATIONS
7.1 Customers are responsible for complying with their own data retention and deletion obligations under applicable law.
7.2 This policy describes Frontal's retention practices. Different retention periods may apply under an Order Form or separate written agreement with Enterprise Customers.
7.3 Customers are responsible for configuring retention settings for Services that offer configurable retention.
7.4 Customers are responsible for maintaining their own records and backups in accordance with their business and legal requirements.
8. CONTACT
Frontal Labs, Inc. Attn: Data Protection 131 Continental Drive, STE 305 Newark, DE 19713 United States of America Email: dpo@frontal.dev