This page explains how to request deletion of your data from Ontio, what happens after you do, and how deletion works differently depending on how your Ontio instance is deployed. It supplements our Privacy Policy and Terms of Service.
1. What This Covers
Two categories of data are handled differently:
- Account and Site Data: your name, work email, login credentials, billing information, and support communications with Ontio.
- Customer Data: the operational data ingested into your organization's knowledge graph through the Ontio platform, including any personal data it contains.
2. Deletion by Deployment Model
How deletion works depends on which deployment model your organization uses:
| Deployment Model | Who Controls Deletion of Customer Data |
|---|---|
| Cloud | Ontio deletes Customer Data from Ontio-managed infrastructure upon your verified request or per your contracted retention schedule. |
| Hybrid | You control deletion within your own environment; Ontio deletes Customer Data held in the Ontio-managed components upon request. |
| On-Premises | You control deletion entirely: the knowledge graph and all pipeline data reside on your own infrastructure. Ontio holds no copy to delete. |
| Air-Gapped | You control deletion entirely, with no Ontio access at any point. |
If your organization is on an On-Premises or Air-Gapped deployment, this page primarily concerns your Account and Site Data (e.g., admin console logins, billing contacts) rather than Customer Data, since Ontio never receives the latter.
3. How to Request Deletion
Individual account holders: You can delete non-essential profile information directly from account settings. To close your account and delete associated Account Data, email privacy@ontio.ai from your registered address with the subject line "Account Deletion Request."
Customer Data (Cloud/Hybrid deployments): An authorized administrator on your account should submit a deletion request through the admin console or by emailing privacy@ontio.ai. Because Customer Data is customer-owned, we act on the instruction of your organization's designated administrator(s) rather than individual end users, consistent with our processor role described in the Privacy Policy.
Data subject requests (e.g., an individual asking about their personal data within a customer's graph): Please contact the organization that operates the relevant Ontio instance directly. Ontio will assist that organization in fulfilling verified requests as required under our DPA.
4. Verification
We take reasonable steps to verify the identity and authority of the requester before acting on a deletion request, which may include confirming the request comes from a registered administrator or account email, and, for Customer Data, confirming authorization consistent with your organization's designated contacts under the applicable agreement.
5. Timelines
We aim to complete verified deletion requests for Account and Site Data within 30 days, and for Customer Data on Cloud/Hybrid deployments within the timeframe specified in your DPA (typically 30 to 90 days, depending on plan). Deletion from active systems occurs first; residual copies in backups are purged per Section 6.
6. Backups and Residual Copies
Deleted data may persist temporarily in encrypted backup systems for disaster-recovery purposes. Backup copies are overwritten or purged on a rolling cycle (typically within 30 to 90 days of deletion from production systems) and are not accessed except for restoration purposes.
7. Third-Party AI Model Subprocessors (OpenAI, Anthropic)
Where your configuration routes data through OpenAI or Anthropic (for example, during LLM-augmented steps in the ontology pipeline or natural-language query interpretation), the following describes what actually happens to that data once it reaches their systems:
- Default retention. Under each provider's standard commercial/API terms, inputs and outputs are automatically deleted from their systems within 30 days of processing, retained that long solely for abuse monitoring. Neither provider uses this data to train their models under standard commercial terms.
- No early deletion on request, under standard terms. Neither provider offers a self-serve mechanism to force deletion of already-submitted data before that 30-day window closes. If you request deletion of Customer Data that was processed through one of these providers within the preceding 30 days, the practical outcome is that it will expire from the provider's systems on its own schedule; Ontio cannot accelerate this under default terms.
- Retention exceptions. Both providers may retain data longer than 30 days where legally required, or where content is flagged under their usage/safety policies (Anthropic, for example, may retain flagged content for up to 2 years and related safety-classification metadata for up to 7 years).
- Zero Data Retention (ZDR). Both providers offer Zero Data Retention arrangements under which inputs and outputs are not stored at all beyond in-flight processing. ZDR is a negotiated enterprise agreement applied to specific eligible API endpoints; it is not automatic and not a self-serve setting. [Confirm current status: Ontio has / has not yet established ZDR agreements with OpenAI and Anthropic for the endpoints used in Cloud and Hybrid deployments.] Customers with strict data-erasure requirements (e.g., regulated industries) should confirm current ZDR status with their account team rather than assume rapid deletion applies to AI-processed data.
- Reducing exposure independent of retention. Where Microsoft Presidio is configured to redact personal data before a request reaches an external LLM provider, that data never reaches OpenAI's or Anthropic's systems at all. This is the most reliable way to keep a given field out of scope for this section entirely, and is independent of either provider's retention terms.
For current policy details, see OpenAI's API data usage documentation and Anthropic's commercial data retention policy, or contact privacy@ontio.ai.
8. Exceptions
We may retain limited data where required to:
- Comply with a legal obligation, court order, or regulatory requirement
- Resolve disputes or enforce our agreements
- Maintain security, fraud-prevention, or audit logs for a limited period consistent with our records-retention practices
We will tell you if an exception applies to your specific request and, where possible, the retention period involved.
9. Contact Us
For any deletion request or question about this policy: Ontio Holdings, privacy@ontio.ai