What is stored, and for how long
A nightly run removes whatever is past its retention period.
selfdesk deletes on periods that are set in the software and match what the privacy policy states. A nightly run applies them; there is no setting for this.
| What | How long | |---|---| | Invoices, payments, bookings, kiosk purchases | eight years, the statutory retention for accounting records | | Audit log | three years, then deleted | | Person link in the door log | 30 days, after that only the anonymous row remains | | Evidence attached to a document acceptance | three years for IP address and user agent, the acceptance itself stays | | Closed import rows | 90 days | | Closed deletion requests | one year |
That includes:
- The eight years are a legal obligation, not a setting. Nothing in that group is deleted automatically, not even after an account deletion. The link to the person is cut instead. See When a member deletes their account.
- The audit log is not covered by the eight years. It is a security record and is deleted after three years.
- Door events lose their link to a person after 30 days. What remains is statistics. See Door log: 30 days, not an attendance record.
- Crash reports are only collected if a member switches them on themselves. The default is off, and the web app collects none at all.
- Every rule runs on its own. If one fails, the others still run.