Reso Data Retention Policy

    Last updated: 8 September 2026 | Version 1.0

    This policy sets out how long Reso Group Limited ("Reso", "we", "us") retains customer data, why we retain it, and how it is deleted. It applies to all data collected through our platform and website, and should be read alongside our Privacy Policy, Data Deletion Notification Policy, and Terms and Conditions.

    Our guiding principle is that we keep data only as long as it is needed to provide our services, meet our legal obligations, or protect our legitimate business interests, and no longer. Your content is never used to train any AI model. While Reso is not yet ISO 27001 certified, our retention practices are designed to align with ISO 27001 standards, and we are working toward certification.

    1. Retention periods by data category

    The periods below are our standard retention periods. Teams and Enterprise customers may agree a different retention period for dispute case data as part of their subscription terms, between a minimum of 30 days and a maximum of ten years. Where an agreed period applies it is recorded in that customer's agreement and set on their organisation record, and every change to it is written to the account activity log. An agreed period governs case data only. It does not shorten any period we are legally required to keep, and it does not affect billing records, user accounts or the activity log.

    Data categoryWhat it includesRetention periodWhy
    Account dataName, email, phone, organisation, roleLife of account + 7 years after closureNZ tax and company record-keeping obligations (Tax Administration Act 1994, Companies Act 1993)
    Billing and transaction recordsInvoices, payment history, subscriptions, billing contacts7 years from the relevant transaction, regardless of any deletion request or agreed retention periodTax Administration Act 1994 requires business records be kept for 7 years
    Dispute case dataClaim, response, uploaded documents, extracted text, search index entries, chronology, every report version, settlement recordsSeven years from the last activity on the matter, unless a different period is agreedKept so you can return to past matters, then deleted automatically
    Working record of AI processingCopies of the questions we send our AI providers and the answers received, containing case content30 days, or immediately on deletion of the matter, whichever is soonerQuality assurance and fault investigation on the analysis we produce
    Data export filesThe file we build when you export your data, and the link we email you7 days from creationThe link expires on its own timetable and is not affected by later deletion of a matter
    Account notice recordsRecords that we sent you a closure, deletion or export notice: the address, subject, date and whether it was delivered. No case content7 years from the date the notice was sentEvidence that we told you your deletion dates, kept for as long as that could be disputed and aligned with the billing records it sits beside
    Usage and technical dataLog-ins, feature usage, IP addresses, device data12 months in identifiable formSecurity monitoring and fault investigation
    Cost and usage figuresRecords of platform and AI processing costs incurred on a matterRetained after the matter is deleted, with the link to the matter irreversibly severed so no case content is reachable through themBilling accuracy, cost analysis and capacity planning
    Invited party accountsWhere an invited party chooses to create an account: name, email, passwordSuspended after 12 months without an active dispute; permanently erased 90 days after suspensionAccounts that are no longer used should not persist
    Security and access logsProduction system access logs18 months in identifiable formRetained longer than general usage data because intrusions are often detected well after the event; supports retrospective incident investigation
    Account activity logSee section 8Life of the serviceSee section 8

    2. Early deletion at your request

    You may request deletion of your case data (or your whole account) at any time by contacting support@getreso.co.nz. We will:

    • confirm the request and verify your identity
    • delete the relevant data from production systems within 10 working days
    • confirm completion in writing, per our Data Deletion Notification Policy.

    Deleting a matter destroys the matter and its contents: the claim, the response, uploaded documents and the text taken from them, search index entries, every report version, the chronology, and the working record of AI processing for that matter. It is not a hidden or archived state and it cannot be reversed. Every deletion records what was removed and what, if anything, failed, and a nightly check catches anything left behind.

    By default anyone in your organisation with the appropriate role can delete a matter. If you would rather deletion sat with us instead, ask and we will set that for your organisation.

    Four things are not covered by a deletion, and we would rather state them here than have you discover them later.

    • Billing records. We cannot delete records we are legally required to keep. Billing and transaction records remain for their 7 year statutory period. We will tell you what has been retained and why.
    • The account activity log. Entries recording that a matter existed remain after the matter is deleted. See section 8 for exactly what those entries contain.
    • Background processing. A small number of copies are made by processes that run on a schedule rather than on a matter, and are not linked to a matter, so a deletion request cannot locate them. They are deleted within 30 days.
    • Data export files. If you have exported your data, the export file we built already contains a copy. It expires 7 days after it was created and is not brought forward by a later deletion.

    A deletion request takes effect on the timetable above and is not delayed by the retention period on the matter or by the timetable at section 3.

    3. What happens when your account closes

    • We confirm in writing the date your access ends and the date your matters will be deleted. Deletion is automatic and takes place on the dates given.
    • You have until the date given to export your case files and reports.
    • We send a deletion notice at least 14 days before deletion, per the Data Deletion Notification Policy.
    • Account and billing data moves into restricted archive storage for the remainder of its legal retention period, accessible only for compliance purposes.

    Closing your account brings deletion of your matters forward. It does not extend any retention period.

    4. Backups

    We hold encrypted backups in two places: on our production server for 14 days, and in Amazon Web Services' Sydney region, Australia, for 90 days. Backups older than those periods are purged automatically on the nightly rotation.

    This means data you have deleted may persist in an encrypted backup for up to 90 days. Backups are encrypted, access-restricted, and used only for disaster recovery. Deleted data is not restored to production except where unavoidable in a full system recovery, in which case the deletion is promptly re-applied.

    Because backups are complete copies, the masking described at section 7 does not apply to them. Case content in a backup is held in the same form it takes in the live system.

    5. Legal holds

    If data is relevant to actual or reasonably anticipated legal proceedings, a regulatory investigation, or a law enforcement request, we may suspend deletion of that data until the matter is resolved. Legal holds are approved by a director of Reso Group Ltd., documented, and reviewed every 6 months. Where lawful, we will tell you if your data is subject to a hold.

    6. How deletion works

    Production systems: data is deleted or irreversibly de-identified so it can no longer be linked to you, except for the account activity log described at section 8 and the exceptions listed at section 2.

    Backups: purged on rotation as described above.

    Subprocessors: our service providers are contractually required to delete customer data on our instruction, and deletion requests are passed through to them. One exception: OpenAI keeps a copy of content sent through its API for up to 30 days for abuse monitoring before deleting it, and that copy is held under its terms rather than on our instruction. See section 7.

    Anonymisation: we do not currently hold an anonymised or aggregated dataset. Where we introduce one, it will be aggregated or stripped of identifiers so that individuals cannot reasonably be re-identified, and this policy will be updated.

    7. AI processing, masking and overseas transfer

    Two providers are involved in producing your analysis: one writes it, the other independently checks it. Both receive the same material. Both operate in the United States, so case content is processed outside New Zealand. Our backups are held in Australia, as described at section 4.

    What the providers keep. OpenAI keeps a copy for up to 30 days for abuse monitoring and then deletes it. Anthropic does not keep one, unless its safety systems flag a request, in which case it may be held for up to two years. Neither uses your material to train their models, and your content is never used to train any AI model.

    What we mask. Before your written account is sent, we replace the names of the people involved, along with email addresses, phone numbers and account numbers, with placeholders, and put them back in the finished report. Photographs and scanned documents are sent as images and cannot be masked this way.

    The limits of masking. It is not a general de-identification. We replace the names of the parties recorded on the matter, and patterns we can detect: email addresses, phone numbers, IRD numbers and bank account numbers. We do not detect names in general, so a person mentioned only inside your written account, who is not a party to the matter, is not replaced. We do not detect street addresses, dates of birth, or licence, passport or NHI numbers.

    Our own record. We keep a working record of what was sent and what came back, on the terms set out in the table at section 1.

    8. The account activity log

    We keep a permanent record of activity on the platform. It records that a matter existed, its reference and dispute type, the names of files uploaded, and who did what. It holds no case content: no narratives, no documents, no analysis. Where a member of our staff writes a note on a report review, the note itself stays with the report and is deleted with the matter; the log records only that a note was written.

    One piece of free text is held here deliberately. If you give a reason when closing your account, we keep it in your words. It is about your account rather than about a dispute, and it is the only record of why an account closed.

    Our systems cannot change or delete an entry in this log. Removing that protection requires direct database administration, and doing so is itself a recorded change.

    Entries about a matter remain after the matter itself is deleted. We keep it this way because a security record that can be altered or erased is not a security record, and because it allows us to investigate something discovered long after the event.

    9. How your content is stored

    Case content is encrypted at rest in our production database, and the working record of AI processing is encrypted and reachable only by staff with system administrator rights.

    One exception, which we disclose because it is a deliberate design choice rather than an oversight: the search index that makes your documents searchable holds document text unencrypted. It is subject to the same access controls and the same retention period as the rest of your case file, and it is deleted when the matter is deleted. It means that a copy of our database would yield readable document text.

    10. The other party in a dispute

    Where you invite another party to respond to a dispute, this section explains what happens to what they provide.

    Where their material is held. Everything the invited party contributes is stored inside your case file rather than as a separate record: their name and email address, their response and any counterclaim, the documents they attach and the text taken from them, any saved draft, when they were invited and when they accepted our terms, and the invitation and reminder emails we sent.

    How long it is kept. It is deleted when the matter is deleted, on the same retention period as the rest of your case file.

    If they never respond. The invitation link stops working after 30 days. Nothing is deleted at that point: their name and email address remain on the matter for as long as the matter exists, because they form part of the record of who the dispute was with.

    Their access to the report. Access ends at the earlier of 60 days after the dispute concludes, or the point at which you stop keeping the matter. Their access can never outlive your case file. When they open or download the report, that is recorded in the activity log, so who has seen a report can be answered for both sides.

    Their rights. An invited party may ask us what we hold about them and ask us to correct it, and we will respond within the timeframes set by the Privacy Act 2020. They may also ask us to delete their material by emailing support@getreso.co.nz. Because their material sits inside your case file, we handle these requests by hand and we will speak to you before altering your file.

    What we tell them. Before an invited party writes anything, we tell them on screen that their material goes to our AI providers in the United States, what we mask and what we cannot, that neither provider trains on it, how long it is kept and who decides that, that they keep access to the report for 60 days after the dispute ends, and how to ask us what we hold, correct it, or delete it.

    Their own account. Most invited parties never create one. Where they do, it is suspended after 12 months without an active dispute and permanently erased 90 days later unless they return or a dispute of theirs becomes active. Erasure removes their name, email address and password, leaving only a record that somebody was invited to a matter, with nothing identifying them.

    11. Responsibilities and review

    Policy owner: Gina Wollerman, gina@getreso.co.nz

    Retention schedules are implemented in our systems by the technical team and checked annually, including all organisations on a non-standard retention period.

    This policy is reviewed annually, and additionally whenever our legal obligations, systems, or subprocessors change materially, consistent with the review disciplines of ISO 27001 (toward which we are working).

    Exceptions to this policy, including agreed variations to the retention periods in section 1, must be approved by a director of Reso Group Ltd. and documented.

    12. Questions

    Contact us at support@getreso.co.nz with any questions about this policy or to make a deletion request.