Core Principle
Tenants lease the software system. They do not own it permanently. The platform owner retains ownership of the software, infrastructure, and deployment architecture at all times. Tenant private business data is owned by the tenant during the active lease.
Lease Lifecycle States
Every tenant app instance passes through defined lease states based on payment status and admin actions:
1. ACTIVE
Subscription paid and current. Tenant has full access to all features and business operations. No restrictions apply.
- Full access to all app features
- Business operations unrestricted
- Data export available at any time
- Support access available
2. GRACE PERIOD
Subscription has expired but access is maintained for a configured grace period (default: 30 days). Renewal warnings are shown on each login.
- Access maintained for up to 30 days (configurable)
- Renewal warnings shown on dashboard and app launch
- Automated notifications at 7 days, 3 days, and 1 day before grace ends
- All features remain accessible — renew to avoid restriction
3. RESTRICTED MODE
Grace period has ended without renewal. Tenant can only log in to renew, export allowed data, or contact support. All business operations are suspended.
- Login permitted for renewal, export, and support only
- Business operations (new orders, new customers, etc.) suspended
- Premium features disabled
- Data export tools remain available
- Support contact available
4. OFFBOARDING PERIOD
Tenant has initiated departure, or the system enters offboarding after prolonged non-payment. Data export tools are available during this period.
- Duration: 30–60 days (configurable by admin)
- Data export tools fully available
- Account closure tools provided
- Renewal still possible to exit offboarding
- Notification sent 7 days before offboarding expires
5. RECLAIMABLE
Offboarding period has expired without renewal or completion. The system marks this app instance as ready for platform reclaim. Access is disabled.
- Tenant access is disabled
- System instance marked for reclaim
- Data is preserved pending reclaim action
- Chief Admin can initiate reclaim at any time
6. RECLAIMED
Chief Admin has formally reclaimed the software instance. Tenant access is fully terminated.
- Tenant access permanently disabled
- Domain/subdomain detached and returned to platform inventory
- App instance reset or archived per admin decision
- Tenant data archived then deleted per retention policy
- Software license slot returned to platform pool
7. SUSPENDED / BREACH
Account suspended due to fraud, abuse, illegal activity, chargeback abuse, security threat, or material agreement breach. Chief Admin can trigger this state immediately.
- Immediate suspension — no grace period
- Reason recorded in audit log
- Tenant notified of suspension and reason
- Data handled per policy (may be preserved for investigation)
- Reinstatement at Chief Admin discretion only
Reclaim Process
System reclaim happens at the infrastructure / control-plane level — not by entering the tenant's portal or accessing private data.
What Reclaim Does
Disables tenant authentication tokens, detaches domain/subdomain routing, stops app operations, archives tenant data per retention policy, and returns the software instance to the platform pool.
What Reclaim Does NOT Do
The Chief Admin does not access tenant private business records (customers, orders, finances) during reclaim, unless explicitly permitted by the agreement, granted by the tenant, or required for legal/security investigation.
Audit Trail
Every reclaim action is recorded in the audit log with timestamp, acting admin, reason, and data handling decision.
Data Retention Policy
After the offboarding period, tenant data follows this retention schedule:
Retention periods are configurable by Chief Admin. Default values: Grace period 30 days · Offboarding period 30–60 days · Data retention after reclaim 90 days.
Export Availability by State
Data export tools are available during the following lease states:
Automated Notifications
The platform sends automated notices at the following key points in the lease lifecycle:
Notifications delivered via: in-app banner, email (where configured), and dashboard alert.