Legal & data
Rule

What is stored, and for how long

A nightly run removes whatever is past its retention period.

Selfdesk deletes on periods that are set in the software and match what the privacy policy states. A nightly run applies them; there is no setting for this.

WhatHow long
Invoices, payments, bookings, kiosk purchaseseight years, the statutory retention for accounting records
Audit logthree years, then deleted
Person link in the door log30 days, after that only the anonymous row remains
Evidence attached to a document acceptancethree years for IP address and user agent, the acceptance itself stays
Closed import rows90 days
Closed deletion requestsone year

That includes:

  • The eight years are a legal obligation, not a setting. Nothing in that group is deleted automatically, not even after an account deletion. The link to the person is cut instead. See When a member deletes their account.
  • The audit log is not covered by the eight years. It is a security record and is deleted after three years.
  • Door events lose their link to a person after 30 days. What remains is statistics. See Door log: 30 days, not an attendance record.
  • Crash reports are only collected if a member switches them on themselves. The default is off, and the web app collects none at all.
  • Every rule runs on its own. If one fails, the others still run.