Principle
We do not keep personal data longer than the purpose it is processed for requires. When the purpose falls away, the data is erased, destroyed or anonymised.
Retention table
| Data | Purpose of processing | Legal basis | Retention period |
|---|---|---|---|
| Account record (name, email, password hash) | Providing the service, authentication | Performance of a contract | Until the account is deleted; within 30 days of a deletion request |
| Subscriber record (push endpoint, encryption keys, tags, country, browser, operating system, language, time zone) | Sending and targeting notifications | The customer’s instruction as data controller | Until the subscription ends or the project is deleted |
| Campaign content and send records | Reporting, debugging | Performance of a contract | Until the project is deleted |
| Delivery and click events | Performance statistics | Performance of a contract / legitimate interest | 12 months (deleted automatically as monthly partitions) |
| Outgoing webhook delivery records | Integration debugging | Performance of a contract | 90 days (deleted automatically) |
| Session refresh tokens | Session continuity | Performance of a contract | 30 days (invalid once expired) |
| Invoice and payment records | Obligation under financial legislation | Legal obligation | The period required by financial legislation (10 years) |
Deletion methods
- Event records: deleted by dropping the whole monthly partition — no residual rows are left behind.
- Webhook delivery records: expired ones are deleted from the database.
- Subscriber record: deactivated when the subscription ends; deleted outright when the project or account is deleted.
- Project deletion: subscribers, campaigns, segments, automations, webhooks and API keys attached to the project are deleted together at database level.
- Account deletion: all projects under the account and all data beneath them are deleted.
- Backups: copies in encrypted backups fall away once the backup rotation completes (within 30 days at most).
Exceptions
Invoice and payment records that financial legislation requires us to keep are retained for the statutory period regardless of a deletion request. Where a legal dispute is ongoing, the relevant data may be kept until it is resolved.
Requesting deletion
You can request deletion of the data on your account by writing to [email protected]. We conclude the request within 30 days at the latest and tell you in writing when it is done. A self-service export and deletion flow inside the panel is on the roadmap; for now these are handled through support.