Data Disposal Policy
Policy governing the secure disposal and deletion of Customer Data and other information by Frontal.
Last updated 11 giugno 2026
This Data Disposal Policy describes how Frontal Labs, Inc. ("Frontal," "we," "us," or "our") securely disposes of Customer Data and other information when it is no longer needed or when deletion is requested. This policy is incorporated into the Terms of Service and supplements our Data Retention Policy. Capitalized terms not defined here have the meanings given in the Terms of Service.
1. SCOPE
This policy applies to all data processed, stored, or transmitted by Frontal in connection with the Services, including Customer Data, Account Data, Usage Data, and Frontal's own operational data.
2. DATA DISPOSAL UPON CUSTOMER REQUEST
2.1 Deletion Requests. You may request deletion of your Account and associated Customer Data through your Account settings or by contacting us at privacy@frontal.dev. Deletion requests are processed as follows:
- Self-Service Deletion: You may delete specific Customer Data (including databases, storage buckets, deployments, models, fine-tuned models, API Keys, and configurations) through the Services interface or API. Deletion takes effect immediately and is irreversible.
- Account Deletion: When you delete your Account, all Customer Data is scheduled for deletion. Active systems data is deleted within 30 days.
- Individual Data Deletion: You may request deletion of specific Personal Data in accordance with our Privacy Policy.
2.2 Deletion Timeline. Following a deletion request or Account termination, Customer Data is deleted according to the following schedule:
2.3 Customer Data Export. Before deletion, you may export your Customer Data using the export tools available in the Services. After the deletion timeline expires, we will have no obligation to maintain or provide Customer Data, and we will delete it from our production systems.
2.4 Legal Holds. Notwithstanding a deletion request, we may retain data subject to a legal hold (litigation preservation notice, regulatory investigation, or other legal requirement). We will notify you of a legal hold affecting your data unless prohibited by law.
3. SECURE DISPOSAL METHODS
Frontal employs the following data disposal methods, selected based on the storage medium and data classification level as defined in our Data Classification Policy:
3.1 Cryptographic Erasure. For cloud-based storage, our primary disposal method is cryptographic erasure: deletion of the encryption keys protecting the data, rendering the encrypted data irretrievable. This achieves the equivalent of NIST SP 800-88 media sanitization "Purge" level.
3.2 Secure Overwrite. For storage media that will be reused, we perform secure overwrite using industry-standard methods (NIST SP 800-88 Clear or Purge) before reallocation.
3.3 Physical Destruction. For storage media that is decommissioned or that held Restricted data (as defined in our Data Classification Policy), we rely on our cloud infrastructure providers' decommissioning processes, which include physical destruction of storage media in accordance with NIST SP 800-88 Destroy level or equivalent. We obtain certifications from our infrastructure providers regarding their media sanitization practices.
3.4 Database-Level Deletion. Active database records are deleted through logical deletion followed by database-level secure reclamation processes, including periodic vacuum and reindexing operations. Database systems are configured to overwrite freed storage space.
4. THIRD-PARTY SUBPROCESSOR DATA DISPOSAL
4.1 Subprocessors are contractually obligated to delete Customer Data upon termination of their engagement or upon Frontal's instruction, in accordance with the timelines and methods described in this policy and our Data Processing Agreement.
4.2 We obtain written confirmation of deletion from Subprocessors when they complete data disposal.
4.3 Subprocessors engaged as AI model providers are contractually obligated not to use Customer Data for training or improvement of their models. We implement zero-retention configurations with model providers where those configurations are available from the provider. For providers that do not offer zero-retention configurations, we: (a) contractually prohibit use of Customer Data for model training or improvement; (b) disclose this limitation in our Documentation; and (c) work with the provider toward implementing zero-retention capabilities. For current zero-retention availability by provider, refer to our Documentation.
5. DATA DISPOSAL VERIFICATION
5.1 For Restricted data, we verify deletion through a combination of automated system checks and periodic audit processes.
5.2 Upon request from enterprise Customers, we will provide written confirmation of data deletion within 30 days of the completion of the disposal process.
5.3 We maintain records of significant data disposal events for audit purposes.
6. EXCEPTIONS
Data may be retained beyond the standard deletion timeline in the following circumstances:
6.1 Legal Compliance. When retention is required by applicable law, regulation, or legal process.
6.2 Security and Abuse Prevention. Information reasonably necessary to prevent fraud, abuse, or security incidents may be retained for up to 12 months after Account deletion. This includes IP addresses associated with Terms of Service violations, fraud indicators, and security event data.
6.3 Financial Records. Billing, payment, and tax records are retained for the period required by applicable tax and financial regulations (typically 7 years, or longer where required by applicable law).
6.4 Backups. Data in backups is not immediately purged. Backups expire automatically per the retention schedule in our Data Backup and Recovery Policy. Backup data is not restored except for operational recovery purposes.
6.5 Anonymized Data. Data that has been anonymized or de-identified such that it cannot reasonably identify an individual or Customer may be retained indefinitely.
7. CUSTOMER RESPONSIBILITIES
7.1 You are responsible for deleting Customer Data from your own systems, backups, and any third-party services you use in connection with the Services.
7.2 If you have shared Customer Data with other users, third-party integrations, or publicly through the Services, deletion from Frontal's systems does not delete those copies.
7.3 You are responsible for exporting Customer Data you wish to retain before initiating deletion or Account termination.
8. CONTACT
Frontal Labs, Inc. Attn: Data Protection 131 Continental Drive, STE 305 Newark, DE 19713 United States of America Email: dpo@frontal.dev