Data Retention Policy

Data Retention Policy

This policy describes how long we retain different types of personal data. It complements our Privacy Policy.

Last updated: 2026-04-29

1. Security and Access Logs

Data Type Retention Period Legal Basis
Audit Logs 365 days Legitimate interest - Security monitoring
Login Attempts 90 days Legitimate interest - Fraud prevention
Session Data 30 days Contract performance

2. User Data

Data Type Retention Period Note
Deleted Accounts 30 days Recovery period before permanent deletion
GDPR Data Exports 30 days Temporary storage for download

3. Billing and Financial Records

Data Type Retention Period Legal Basis
Invoices & Payments 10 years Legal obligation - Tax regulations

4. Coaching and Session Data

Coaching notes, mood check-ins, and wellness data are retained as long as your account is active. This data is deleted when you delete your account or request deletion under Art. 17 GDPR.

5. Backups

Encrypted backups are retained for 7 days to ensure business continuity and disaster recovery.

6. Your Rights

You can request deletion of your data at any time using our GDPR Request Form. Note that certain data must be retained longer due to legal retention requirements.

For questions about this policy, please contact info@bold-bloom.com.