What is stored, and for how long
A nightly run removes whatever is past its retention period.
Selfdesk deletes on periods that are set in the software and match what the privacy policy states. A nightly run applies them; there is no setting for this.
| What | How long |
|---|---|
| Invoices, payments, bookings, kiosk purchases | eight years, the statutory retention for accounting records |
| Audit log | three years, then deleted |
| Person link in the door log | 30 days, after that only the anonymous row remains |
| Evidence attached to a document acceptance | three years for IP address and user agent, the acceptance itself stays |
| Closed import rows | 90 days |
| Closed deletion requests | one year |
That includes:
- The eight years are a legal obligation, not a setting. Nothing in that group is deleted automatically, not even after an account deletion. The link to the person is cut instead. See When a member deletes their account.
- The audit log is not covered by the eight years. It is a security record and is deleted after three years.
- Door events lose their link to a person after 30 days. What remains is statistics. See Door log: 30 days, not an attendance record.
- Crash reports are only collected if a member switches them on themselves. The default is off, and the web app collects none at all.
- Every rule runs on its own. If one fails, the others still run.