Data Retention & Deletion Policy
DeepTech sp. z o.o. · Version 1.2 — pending management approval · October 2026
| Field | Value |
|---|---|
| Owner | DeepTech sp. z o.o. — CTO (system owner) and data protection coordinator (Kacper Raubo); approved by the Management Board |
| Version | 1.2 |
| Status | Pending management approval (Management Board of DeepTech sp. z o.o.) |
| Effective | On approval — October 2026 (supersedes v1.1, v1.0 and Draft v0.9) |
| Review | Every 12 months or after a material change |
| Classification | Public |
This policy states how long DeepTech keeps data and how it is deleted. Part A covers personal data for which DeepTech is the controller, organised by category of data subject (art. 5(1)(e), 13(2)(a) GDPR). Part B covers the data classes held in the Audomate platform, where DeepTech acts as processor on the client's instructions under the Data Processing Agreement (DPA; in legal review by an external law firm since 10 October 2026). Where the DPA sets a different period for a client, the DPA prevails.
Part A — Personal data by category of data subject
| Category of data subjects | Categories of data | Role of DeepTech | Retention |
|---|---|---|---|
| Clients or their representatives | Ordinary (name, business e-mail, phone, position, company); confidential (bank account numbers on invoices) — invoicing and accounting in mOrganizer finansów (mBank S.A., Poland) | Controller | Billing / accounting data: 5 years from the end of the calendar year in which the tax payment fell due. Contact and contractual data: for the term of the contract and until the limitation period for claims expires (3 years after the contract ends) |
| Users of the Audomate platform | Ordinary (name, business e-mail, role); authentication logs | Processor (client is controller) | For the period the account is active; after deletion at most 3 years for defence against claims, or immediate deletion / anonymisation where no claims are pending — as instructed in the DPA |
| Representatives of cooperating companies (vendors, partners) | Ordinary; confidential (bank account numbers) | Controller | For the duration of the cooperation or until the contact person changes / an effective objection is raised; after the cooperation ends — 3 years; accounting data 5 years as above |
| Employees and contractors | Ordinary; confidential (PESEL, bank account); data required by labour law | Controller | Personnel files: 10 years from the end of the calendar year in which employment ended (employees hired from 2019) — art. 94(9b) of the Polish Labour Code; B2B contractors — as for cooperating companies |
| Prospective clients (demo / pilot form, leads) | Ordinary; content of the enquiry — handled in the business mailbox (sales@deeptech.pl / contact@deeptech.pl); no CRM is used. Audomate is sold to businesses only (B2B-only, confirmed by the Management Board on 10 October 2026), so consumers are not a category of data subjects | Controller | Until consent is withdrawn or an objection is raised; where no cooperation follows — at most 12 months from the last contact |
| Job candidates | Ordinary; application documents | Controller | 3 months after the recruitment ends; with separate consent for future recruitments — 12 months from the application or until consent is withdrawn |
| General enquiries (contact) | Ordinary; content of the message | Controller | Duration of handling + 12 months |
| Website visitors | IP address and technical connection data (server logs); anonymised statistics (Plausible) | Controller | Server logs: 30 days. Analytics: no personal data retained beyond the 24-hour hash rotation |
Special categories of data (art. 9 GDPR) are not knowingly processed. Where they occur incidentally in client documents they fall under Part B and the client's instructions.
Part B — Platform data classes (DeepTech as processor)
| Data class | Where held | Retention |
|---|---|---|
| Uploaded client documents (PDF / DOCX) | EEA object storage (Google Cloud Storage, dual-region europe-west1 + europe-west4) + vector index (Qdrant / pgvector) | Until client deletion request or contract end — then hard-deleted |
| Personal data extracted to database | EEA relational database (Cloud SQL PostgreSQL, Belgium) | No longer than necessary for the service (GDPR art. 5); at latest, deleted with the contract-end purge |
| AI session context | Memory only (per-tenant session) | Cleared at session end — never persisted; prompts and completions are not retained by the model provider (OpenAI Ireland Ltd — OpenAI API, EU data residency, Zero Data Retention) |
| Compliance reports | EEA storage, versioned (Cloud Storage + PostgreSQL) | Duration of the agreement; on termination exported (open formats) and hard-deleted after the 30-day transition window, unless the client instructs otherwise |
| Audit trail / logs | Hash-chained, immutable log (Cloud Logging + PostgreSQL) | Minimum 1 year (supports clients' DORA record-keeping — register of information under art. 28(3) and incident records under art. 19 DORA); default 3 years; maximum 5 years, then automatic deletion |
| Secrets / API keys | Managed secret vault (Google Secret Manager, CMEK) | Rotated every 90 days; revoked on termination |
| Website lead-form data | Business mailbox (sales@deeptech.pl / contact@deeptech.pl); no CRM is used. E-mail provider: Home.pl (home.pl sp. z o.o., ul. Zbożowa 4, 70-653 Szczecin, Poland) | 12 months from last contact (per Privacy & Cookie Policy; previously 24 months — aligned) |
| Backups | EEA, encrypted; Cloud SQL automated backups + point-in-time recovery; Cloud Storage dual-region | Backup retention window: 7 days (Cloud SQL automated backups: 7 days; point-in-time recovery: 7 days). Consequence: deleted data ages out of backups within 7 days at the latest, and restores are possible up to 7 days back |
2. Deletion
- On request / right to erasure: hard delete via the purge pipeline covering vector, relational and object-storage records in one operation; confirmation provided to the requester (for platform data: to the client as controller). Requests are received by e-mail (privacy@audomate.eu; platform clients: support@audomate.eu) — no third-party ticketing tool is used.
- On termination: full export offered in open formats (PDF, DOCX, CSV, JSON), then purge; transition assistance for 30 days.
- Scheduled deletion: the retention periods above are enforced by scheduled jobs in the platform and by periodic review of business mailboxes and records; the CTO reviews the schedule at least annually together with this policy.
- Backup nuance: deleted records persist in encrypted backups until the 7-day backup window elapses — i.e. for at most 7 days after deletion; backups are not restored except for disaster recovery, and any record restored from backup that was previously deleted is re-deleted.
3. Legal holds
A documented legal hold (statutory obligation, regulatory request, or litigation) suspends scheduled deletion for the identified records only. Each hold is recorded in the audit trail with scope and legal basis, reviewed quarterly, and released in writing; deletion resumes automatically on release.
4. Contact
Deletion requests and questions: privacy@audomate.eu (data protection coordinator: Kacper Raubo). Platform clients submit deletion and export instructions through support@audomate.eu or the channels defined in the DPA.
Document control
| Version | Date | Author | Approved by | Changes |
|---|---|---|---|---|
| 0.9 | September 2026 | DeepTech (CTO / CEO) | — (working draft, not adopted) | Working draft published for transparency; items marked "to confirm". |
| 1.0 | October 2026 | DeepTech (CEO / CTO) | — (superseded by 1.1) | Changes after the GDPR (RODO) / NIS2 audit of 7–8 October 2026: policy split into Part A (personal data by category of data subject — new, public) and Part B (platform data classes — original table kept and completed); audit-trail retention referenced to art. 28(3) and art. 19 DORA (not art. 25); lead-form retention aligned to 12 months; backup window and lead-handling tool flagged; scheduled deletion added. |
| 1.1 | 10 October 2026 | DeepTech (CEO / CTO / data protection coordinator) | Management Board — pending | Updates after Management Board decisions of 10 Oct 2026: backup window set to 7 days (Cloud SQL automated backups 7 days + PITR 7 days) — deleted data ages out of backups within 7 days; lead handling described as mailbox only (no CRM), deletion requests by e-mail (no ticketing tool); mOrganizer finansów (mBank S.A.) named as invoicing provider; model provider corrected to OpenAI Ireland Ltd (OpenAI API, EU data residency, ZDR); Data Protection Coordinator named (Kacper Raubo); B2B-only confirmed; DPA in legal review (law firm) since 10 Oct 2026. |
| 1.2 | 11 October 2026 | DeepTech (CEO / CTO / data protection coordinator) | Management Board — pending | Open item closed on the basis of Management Board answers of 11 Oct 2026: business e-mail provider named (Home.pl), Part B. |