Halcyra's internal Owner CRM stores encrypted authorisation tokens while a supported email and calendar connection is active. Correspondence is not automatically synchronised into Halcyra; relevant mail is looked up on demand for the authorised Owner workflow. Disconnecting the service removes the stored connection and encrypted tokens. Mail remains with the connected provider under the Owner's normal retention settings.
An admin can permanently erase a tenant's record — contact details, address, and message history — from the job's detail panel in the dashboard at any time. This is immediate and irreversible.
On cancellation, your firm's data is retained for 30 days to allow export or reactivation, then permanently deleted, except where we're required to retain billing records for longer under UK tax law (currently up to 6 years, for financial records only — not tenant data).
Deleted records are removed from backups within a reasonable operational window as part of routine backup rotation, rather than instantly across every backup copy.