Data Retention and Disposal Policy
Effective June 9, 2026
Caipibara provides bookkeeping, reconciliation, and tax-preparation software for Canadian accounting firms. This Data Retention and Disposal Policy describes the categories of data we hold, how long we keep them, and how we securely dispose of them when they are no longer needed.
Data we hold
- Account information — names, emails, and firm details used to create and secure accounts.
- Connected accounting data — transactions, chart of accounts, and balances retrieved from accounting platforms (QuickBooks Online, Xero) you authorize.
- Bank-connection data — where a client links a bank account through our bank-aggregation provider (Plaid), the access token for that connection and the transactions and balances retrieved through it.
- Documents — bank statements, invoices, receipts, ledgers, and similar records you upload, and the data extracted from them.
- Operational logs — diagnostics and audit records needed to operate and secure the service.
Data residency
Data is hosted in Canada (AWS ca-central-1) in support of PIPEDA, encrypted in transit and at rest.
Retention principles
We retain data only as long as necessary to provide the service and to meet legal, regulatory, and professional record-keeping obligations. Because the service supports Canadian accounting and tax work, certain books and records are retained for the period required by the Canada Revenue Agency (generally six years).
Retention periods
- Bank-connection tokens — retained only while the connection is active. When a connection is disconnected, it is revoked at the provider (the bank-aggregation item is removed at Plaid) and the stored access token is deleted.
- Client financial data and documents — retained for the duration of the engagement and any applicable statutory retention period, after which they are deleted or returned to the firm.
- Account information — retained while the account is active.
- Operational and audit logs — retained for a limited period appropriate to security and troubleshooting needs.
- Backups — retained on a rolling basis and overwritten on a defined cycle.
Secure disposal
When data reaches the end of its retention period or a deletion request is honored, it is securely removed from our databases and object storage. Encrypted data is rendered unrecoverable through deletion of the underlying records, and backups containing the data age out on the backup cycle.
Deletion on request
Subject to applicable law and professional record-keeping obligations, a firm may request deletion of its data and its clients’ data, and an individual may request deletion of their personal information. We honor verified requests except where retention is required by law or a legal hold. Disconnecting an integration stops further access to that platform.
Review
This policy is reviewed periodically and updated as our systems and obligations evolve; the effective date above reflects the latest version.
Contact
Questions about this policy: johnyin@synervex.ai.