Document ID: GT-AI-RETENTION-2026-10-07-v1
Version: 1.0
Effective date: October 7, 2026
Policy authority: Angel Godd-Santana, Company Owner.
Approval: Adopted by the Company Owner on October 7, 2026.
1. Purpose, scope and controlling instruments
Godd Technologies, LLC (the Company) establishes this policy for records of typed or spoken conversations with its designated website AI assistants on goddtechnologies.com, samgov.goddtechnologies.com and angelgoddsantana.me. Coverage of the assistant workflow on the professional personal site does not characterize every activity on that site as a Company service.
The policy applies only to the three designated website agents and their verified Company records. Telephone calls, voicemail, other agents, unidentified sources and legacy records are outside this initial operating scope. Exclusion from this workflow does not remove privacy rights or the Company's obligations under its existing Privacy Policy, an applicable contract or law.
This policy supplements the Company's published Privacy Policy and Terms of Use and Service for this specific workflow. It does not amend purchase terms, expand purchasing authority, create an Accepted Order, or vary a controlling Government Order. Applicable mandatory requirements and the controlling instrument remain applicable. A conflict must be identified and resolved before affected records enter disposition; website use or an assistant response does not resolve it.
2. Covered record categories and purpose
Covered records comprise, to the extent provided or generated:
- Conversation content: visitor messages, assistant responses, transcripts and voice recordings where voice recording is enabled and a recording exists.
- Inquiry and opportunity records: confirmed contact details, organization, reason for contact and relevant follow-up details. These may include ordinary procurement references or professional opportunity requirements given by the visitor.
- Conversation administration records: summaries, source and provider conversation identifiers, verified start time, processing and delivery status, and associated usage or cost metadata.
- Disposition control records: documented Keep decisions, scope and age provenance, verification outcomes and the limited metadata needed to record disposition and prevent a later duplicate delivery from recreating disposed content.
Conversation and inquiry content is used to conduct the requested interaction and permit personal follow-up by Company staff or Angel, as appropriate to the inquiry. This policy does not authorize unrelated data uses or new record collection.
3. Visitor notice and service-provider processing
Before a visitor starts an interaction, the visitor-facing notice must identify the AI assistant, recording and transcription practices, purpose, relevant service providers, retention and disposition limits, and the alternative contact method. Affirmative authorization must occur before initiating the provider connection. Choosing voice must precede any microphone request.
The workflow uses Microsoft Azure for Company infrastructure, ElevenLabs for AI conversations and associated processing, and Notion for the Company inbox record. The visitor disclosures must also verify and disclose the applicable language-model, fallback, analysis, speech and notification provider roles or categories; naming the orchestration platform alone must not imply that no other provider processes data. This policy makes no assertion about provider training use, geographic restrictions or deletion of provider backups that has not been verified.
The policy is for ordinary inquiries. The information-handling restrictions in the existing corporate Privacy Policy and government legal and procurement reference continue to govern. A public AI assistant is not an approved channel for protected government information, credentials, full payment-card information or other restricted material. An assistant cannot establish an agency authorization, certification or compliance status.
4. Default period and retention start
The default disposition-eligibility time is the actual conversation start time, authenticated from the provider and bound to the exact conversation and designated agent, plus 90 elapsed days of 24 hours each in UTC. Eligibility begins when that time is reached, subject to a documented Keep exception and the verified disposition prerequisites.
The start of the period must not be substituted with webhook receipt time, a storage timestamp, a Notion creation date, an import date or an inferred date. Editing, archiving, restoring, receiving a duplicate delivery or transferring a record does not reset that start.
Ninety days is the default eligibility period for the covered workflow; it is not a representation that every recoverable or separately held copy is permanently erased at that instant. Verified disposition, its completion time and unresolved limits must be recorded accurately.
5. Documented Keep exceptions
Only an explicit Company Owner decision may establish a Keep exception. The decision must identify the affected records, the business or controlling recordkeeping reason, the approving authority and decision date, and a stated review date. An Accepted Order, continuing engagement or other actual business purpose may support the stated reason; an inquiry, an assistant's promise, an inbox status or an assumed future relationship does not establish an exception automatically.
At review, the Owner must record a decision to release the exception or to continue it with a supported reason and a new review date. A review date alone neither authorizes deletion of a kept record nor grants a blanket extension. An overdue review must be identified as outstanding; it is not a claim of authorized indefinite retention.
Ending Keep does not restart the 90-day period. A released record already beyond its original eligibility time may proceed only through the verified disposition process. Missing or conflicting age, identity or Keep evidence blocks automated disposition pending recorded reconciliation; that safety block is neither a new Keep approval nor a substitute retention policy.
6. Disposition and remaining records
Disposition requires verification of record identity, age, exception status, known copies and settled processing, followed by separately approved execution for the exact records. Policy approval alone is insufficient.
For the covered workflow:
- ElevenLabs: conversation deletion must be verified against the exact provider record. A successful operation and subsequent absence of the retrievable conversation do not establish deletion of every provider backup or independent copy.
- Company Azure record: covered content is removed from the existing row; limited disposition and replay-prevention metadata remains as a tombstone. Identifiers may remain linkable, so a tombstone is not represented as anonymous or as erasure of every item of personal information. Its separate retention schedule remains to be approved before a publication promise concerning that metadata is made.
- Notion: the Company inbox page is moved to recoverable Trash. This is not permanent erasure. The Notion API provides trash and restore operations rather than permanent page deletion. Any eventual removal from Trash or provider backups is governed by separately verified provider controls and Company decisions. Notion API reference.
CallDesk Archive and Restore change inbox placement only. They neither delete content nor create, end or extend a Keep exception.
7. Copies requiring separate handling
Email and push messages, downloaded transcripts, PDF or audio files, exports, recipient inboxes and devices, operational logs, provider or infrastructure backups, and any other archive or downstream copy require separate handling. The initial coordinated workflow does not claim to purge these locations. Their inventory, retention rules and disposition evidence must be considered separately; a completed covered-workflow operation is not proof of their erasure. These limitations do not waive privacy-request rights or applicable obligations.
Known unaccounted-for copies or unfinished processing must be identified rather than treated as absent. Turning off the workflow or rolling back its software cannot recover already removed conversation content; recoverability must be explained before a particular disposition is approved.
8. Privacy requests, administration and changes
Privacy requests concerning this workflow may be submitted to support@goddtechnologies.com with the subject Privacy Request. Identity, authority, applicable exceptions and response handling follow the existing corporate Privacy Policy. This policy establishes no additional waiver, request deadline or promise that every copy can be recovered or erased through one operation.
The Company must maintain versioned policy and implementation evidence sufficient to distinguish design approval, verified operating controls, approved execution and completed disposition. Changes affecting this workflow must be reviewed against the current corporate, government and personal-site disclosures. Policy changes require Owner approval, versioned provenance and an accurate effective date. Public disclosures must describe verified practices without retroactively authorizing an unrelated use or altering a controlling order.
Contact: Godd Technologies, LLC, Homestead, Florida, United States — support@goddtechnologies.com.