Privacy / Data Rights / Last updated July 1, 2026
Your Data Rights
Depending on where you live and how your data entered the service, you may have rights to access, correct, delete, export, restrict, or object to the use of personal information.
What you can ask for
- Access or export personal information we hold about you.
- Correct personal information that is wrong or out of date.
- Delete personal information when we do not need to retain it for law, security, accounting, contract, or audit reasons.
- Restrict or object to certain processing where the law gives you that right.
- Receive portable information where technically feasible.
- Withdraw optional consent, including marketing consent, without affecting the paid service.
Controller and processor requests
For customer data processed by an operator, the customer is usually the controller and we act as processor. For account, marketing, website, or support data that Five Star Solutions controls directly, contact us and we will handle the request ourselves.
How long we keep things
| Store | Retention |
|---|---|
| Audit log | Six years in WORM export. It stores compliance metadata and redacted row images, not free-text PHI payloads. |
| Run steps | About 90 days, then removed by the scheduled retention task. |
| Pending approvals | Seven days after expiry, then removed. |
| Agent memory | About 180 days by default for org-scoped memory/vector rows. |
| Usage and cost ledger | About two years for finance, support, and abuse review. |
| Work items | Two years by default unless the customer contract sets a shorter or longer product-specific window. |
| Artifacts | Customer-contract dependent. Rows without an explicit expiry use a one-year default TTL backstop. |
| Processed-item ledger | Long-lived by design for idempotency and duplicate-prevention evidence. |
How to ask
Email us with the right you want to exercise and the email address or phone number tied to the data. Email Justin to start.