Skip to content

AVENZERS CLOUD / POLICIES

Draft · not in effect

Data Deletion Policy

Current deletion controls and intended account closure process.

Draft prepared 11 October 2026No effective date assigned
Draft for review · not an effective policy

This complete draft is available so you can read how the service and its proposed commitments are described. It includes both current practices and plans that are not yet implemented. Any feature marked planned, proposed, or not operational is not available as a live commitment. This page is not an approved contract or final Privacy Policy for Google OAuth verification.

Questions or privacy requests: support@avenzers.tech

1. Important Distinctions

Deleting a file from AVENZERS Storage affects the app-managed copy and related metadata according to the application's implemented trash, restore, and permanent-deletion operations. Any retention, trash recovery, and backup-cleanup timelines must be confirmed against production behavior; this draft does not promise immediate irreversible destruction.

Deleting a file in Google Drive may invoke Google Drive's file/trash operations only where the user authorizes them and the Drive API permissions allow. Google controls its own trash and recovery behavior under its terms. Deleting a file reference or message in AVENZERS Cloud is not automatically the same as permanently deleting the original provider file.

Disconnecting Google Drive removes or invalidates the app's stored authorization when the server successfully processes the request. It should prevent new Drive access via that connection but does not automatically erase your original Google Drive files. Existing AVENZERS references to those files may no longer be accessible.

Leaving a group or workspace affects your membership and future access. It may not erase messages, files, or copies already seen by other authorized participants.

Closing an AVENZERS account is a separate process involving identity, membership, owned workspaces, personal records, content, connected-provider grants, and any legally retained information.

2. What You Can Manage Yourself

Depending on which features have been deployed and verified, you may be able to:

  • edit or remove profile details;
  • delete, trash, or restore files in managed storage;
  • remove shares or leave conversations and workspaces;
  • disconnect a connected Google Drive account;
  • revoke Google's third-party access directly at https://myaccount.google.com/permissions;
  • manage or delete original files using the relevant external storage provider.

Do not rely on a disabled or unfinished Delete Account button as confirmation of account deletion.

3. Deletion Request, Authentication and Completion

To request account deletion, data export, correction or access, contact support@avenzers.tech from your account email where feasible. Do not include passwords, recovery codes or OAuth credentials. We may perform proportionate identity and authorization checks and will follow mandatory legal request deadlines. Our ordinary privacy-request response target is 30 days or less where the law requires it.

Approved deletion workflow (not yet verified in production):

  1. Determine whether this account is sole owner of an organization. If yes, require a consenting eligible existing Admin to accept ownership before allowing personal account closure. If none is available, hold account deletion until that issue is resolved without deleting organization-owned data.
  2. When the verified personal deletion is accepted, end the account's access immediately. There is no cancellation/recovery window.
  3. Within 30 days, remove eligible active personal records, credentials and all personally owned AVENZERS Storage files, including those previously shared, except lawful retention obligations. Account closure removes access to user-owned shared managed files; participants may retain downloads made previously.
  4. Remove or revoke third-party access credentials as supported, while leaving original provider-owned files in the owner's Google Drive or other external account untouched.
  5. Preserve separately organization-owned content, channels, authorized member records and operational messages in the continuing organization's control.
  6. Keep existing conversation history for remaining participants with the deleted author's name/avatar removed and sender attribution changed to Deleted User. Message text may retain personal information and requests to remove particular content may require separate legal assessment.

Self-service account deletion is not currently available as a verified workflow. Contact AVENZERS support for account or data assistance.

4. What Happens to External Storage

Google Drive and other user-owned provider accounts have their own deletion and recovery procedures. The intended AVENZERS behavior is to remove the connection and stop using its credentials as part of a completed account closure, without silently erasing unrelated content in the user's external storage.

Files you already shared through Google-native provider permissions, external downloads, or other participants' personal copies may remain outside AVENZERS Cloud's control. You may need to review permissions or delete those copies with the relevant service or recipient.

5. Shared Files, Messages, and Organization Ownership

Personal AVENZERS-managed files: Delete the owner's managed originals and underlying AVENZERS sharing references when their account deletion completes, even if formerly shared through messages/channels. The Service cannot recall legitimately downloaded copies held by recipients.

Third-party originals: User-owned Google Drive/external-provider files remain with that provider; AVENZERS connection deletion must not erase them. Existing references and external-provider native sharing settings have separate lifecycles.

Messages: Retain collaborative conversation messages for other participants, anonymizing the sender as Deleted User and removing their name and avatar attribution after deletion. The contents of old messages may still reveal information provided in the message itself. Requests about message-body personal data require a proportionate lawful review.

Organizations: Organization-owned content is not automatically deleted when a member leaves. The sole organization owner must transfer ownership to a consenting, eligible existing Admin before deleting the personal account; otherwise that account's deletion is blocked until resolved. Organization materials and operational continuity are preserved subject to valid privileges and law.

6. Retention Targets, Backups, and Exceptions

The following are owner-approved retention decisions, not verified as live production guarantees. A backend/provider audit is mandatory before publication as operational fact.

CategoryIntended retention / treatmentImplementation check
Personal account data after confirmed closureStop access immediately; delete eligible active personal data within 30 daysPrivileged deletion job, idempotency, verification, lawful exceptions
Personally owned AVENZERS Storage filesDelete eligible objects including previously shared originals within 30 days of accepted closureR2 object removal, reference cleanup, authorization
Connected external-storage OAuth credentialsRevoke/remove on account closure; retain encrypted credentials on Free Plan downgrade while account is active, without provider API activityRevoke path vs suspend path, credential encryption, token reuse
Collaborative messagesRetain for other participants, anonymize sender as Deleted User, remove profile name/avatarCross-conversation attribution and residual PII review
Organization-owned dataRemain under continuing organization's authorized controlAdmin transfer consent and retained-resource ownership
Security and technical audit logs90 days normallyActual app/provider log lifetimes, legal hold exceptions
Recoverable or backup copies affected by deletionExpire/delete within 30 days after deletion, subject to valid legal preservation exceptionsSupabase/Vercel/R2 snapshot and backup configuration
Billing and transaction evidenceOnly as long as contract, accounting/tax, security and applicable law requireProcessor selection, statutory schedules
Inactive accountsNo deletion solely because of inactivityPrevent unannounced inactive-user purge

Legal holds, valid security investigations and mandatory retention may override ordinary periods to the extent strictly necessary. The owner-approved 30-day backup cap cannot be stated unconditionally until provider backups are proven configurable to satisfy it.

7. Deletion Confirmation and Recovery

An account cannot be recovered after a confirmed closure: there is no personal-account recovery period. Deletion acknowledgement must be sent or displayed only after the system has validly accepted the request and ended access. The service must accurately distinguish immediate access termination from the later up-to-30-day active-data deletion window and up-to-30-day backup expiry target. Clearing a browser session alone is not account deletion; orphaned personal data and revoked-access checks must be tested.

8. Contact and Updates

Operator: AVENZERS GROUP — Bangladesh-registered proprietorship, Dhaka, Bangladesh
Brand: AVENZERS Cloud
Data requests: support@avenzers.tech

Material changes follow the intended advance-notice policy in the Privacy Policy, subject to law. The public version will receive its effective date only after implementation verification and legal approval.