Data Catalog
Last updated: June 8, 2026
This catalog sets out the retention specification for the customer data that VATES (operated by STANDOUT Inc.) processes. VATES selects retention periods by referring to the strictest standard among the regulations of every jurisdiction where your data may be relevant (EU, UK, Japan, California, China, Brazil, Korea, Singapore, Canada, Australia, and others). Your data is governed by the most protective baseline regardless of your location. This specification is generated from the canonical source that drives our code, so it never drifts from actual behavior.
1. Account & Organization
Customer account state
The lifecycle state of your account as a whole (active, suspended, and so on).
- Lifecycle: active → suspended → logical deletion → pseudonymization → physical deletion
- Stay in logical deletion: 1 month
- Pseudonymization → physical deletion: 10 years
- Pseudonymization: Yes
- Legally retained: No
Instance state
The lifecycle state of each instance you create.
- Lifecycle: active → suspended → logical deletion → pseudonymization → physical deletion
- Stay in logical deletion: 1 month
- Pseudonymization → physical deletion: 3 months
- Pseudonymization: Yes
- Legally retained: No
User accounts (including personal data)
User account information, including personal data such as login ID, display name, and credentials.
- Lifecycle: active → suspended → logical deletion → pseudonymization → physical deletion
- Stay in logical deletion: 1 month
- Pseudonymization → physical deletion: 3 months
- Pseudonymization: Yes
- Legally retained: No
User–instance access links
The link between a user and the instances they may use. Deleted together with the account.
- Lifecycle: follows the account (no independent retention period)
- Pseudonymization: No
- Legally retained: No
API keys
Issued API keys. Stored only as an irreversible hash; the plaintext is never retained.
- Lifecycle: active → suspended → logical deletion → pseudonymization → physical deletion
- Pseudonymization → physical deletion: 3 months
- Pseudonymization: No
- Legally retained: No
Revoked sessions
Revoked login sessions, kept briefly so they cannot be reused.
- Lifecycle: periodic deletion by an existing batch
- Pseudonymization → physical deletion: 3 months
- Pseudonymization: No
- Legally retained: No
2. Usage Logs
Conversation logs
End-user conversation history. Retention follows the plan you choose (Standard = 30 days / Zero retention = not retained).
- Lifecycle: chosen by you
- Pseudonymization → physical deletion: 1 month
- Pseudonymization: No
- Legally retained: No
Usage records (per-event)
Per-event usage records, used to calculate your charges.
- Lifecycle: active → suspended → logical deletion → pseudonymization → physical deletion
- Stay in logical deletion: 1 month
- Pseudonymization → physical deletion: 3 months
- Pseudonymization: Yes
- Legally retained: No
Usage aggregates (billing basis)
Aggregated usage totals that form the basis of billing. Subject to statutory retention.
- Lifecycle: legally retained (not pseudonymized; physically deleted only after the period)
- Pseudonymization → physical deletion: 10 years
- Pseudonymization: No
- Legally retained: Yes
3. Balance & Billing (legally retained)
Customer balance
Your prepaid balance — the settled record of payment. Retained for the statutory period and not pseudonymized.
- Lifecycle: legally retained (not pseudonymized; physically deleted only after the period)
- Pseudonymization → physical deletion: 10 years
- Pseudonymization: No
- Legally retained: Yes
Balance history (transactions)
The change history of your balance. Transaction amount, currency, and rate are retained for the statutory period (only the operator name is pseudonymized).
- Lifecycle: legally retained (only the operator name is pseudonymized)
- Stay in logical deletion: 1 month
- Pseudonymization → physical deletion: 10 years
- Pseudonymization: Yes (operator name only)
- Legally retained: Yes
4. Audit Logs
Instance audit log
Your instance audit log: a tamper-evident record of security-relevant events.
- Lifecycle: active → suspended → logical deletion → pseudonymization → physical deletion
- Stay in logical deletion: 1 month
- Pseudonymization → physical deletion: 2 years
- Pseudonymization: Yes
- Legally retained: No
5. Your Knowledge Assets & Settings
ES-IFM knowledge assets
Your ES-IFM knowledge assets — your intellectual property. When you delete your account, these assets follow the standard deletion lifecycle and are physically deleted after the retention period.
- Lifecycle: active → suspended → logical deletion → pseudonymization → physical deletion
- Pseudonymization → physical deletion: 1 month
- Pseudonymization: No
- Legally retained: No
Instance settings
Instance settings such as branding, limits, and prompts.
- Lifecycle: active → suspended → logical deletion → pseudonymization → physical deletion
- Pseudonymization → physical deletion: 1 month
- Pseudonymization: No
- Legally retained: No
Shell settings
Shell settings that reference the central master configuration.
- Lifecycle: active → suspended → logical deletion → pseudonymization → physical deletion
- Pseudonymization → physical deletion: 1 month
- Pseudonymization: No
- Legally retained: No
Client-wide settings
Your client-wide default settings.
- Lifecycle: active → suspended → logical deletion → pseudonymization → physical deletion
- Pseudonymization → physical deletion: 1 month
- Pseudonymization: No
- Legally retained: No
This specification is generated from the canonical data catalog. The complete technical specification for each data type (physical location, deletion function, legal basis) is also available in the "Data lifecycle" screen of the console.