Trust Center · version 1.2

Data Retention & Deletion Policy

DeepTech sp. z o.o. · Version 1.2 — pending management approval · October 2026

Document details
FieldValue
OwnerDeepTech sp. z o.o. — CTO (system owner) and data protection coordinator (Kacper Raubo); approved by the Management Board
Version1.2
StatusPending management approval (Management Board of DeepTech sp. z o.o.)
EffectiveOn approval — October 2026 (supersedes v1.1, v1.0 and Draft v0.9)
ReviewEvery 12 months or after a material change
ClassificationPublic

This policy states how long DeepTech keeps data and how it is deleted. Part A covers personal data for which DeepTech is the controller, organised by category of data subject (art. 5(1)(e), 13(2)(a) GDPR). Part B covers the data classes held in the Audomate platform, where DeepTech acts as processor on the client's instructions under the Data Processing Agreement (DPA; in legal review by an external law firm since 10 October 2026). Where the DPA sets a different period for a client, the DPA prevails.

Part A — Personal data by category of data subject

Category of data subjectsCategories of dataRole of DeepTechRetention
Clients or their representativesOrdinary (name, business e-mail, phone, position, company); confidential (bank account numbers on invoices) — invoicing and accounting in mOrganizer finansów (mBank S.A., Poland)ControllerBilling / accounting data: 5 years from the end of the calendar year in which the tax payment fell due. Contact and contractual data: for the term of the contract and until the limitation period for claims expires (3 years after the contract ends)
Users of the Audomate platformOrdinary (name, business e-mail, role); authentication logsProcessor (client is controller)For the period the account is active; after deletion at most 3 years for defence against claims, or immediate deletion / anonymisation where no claims are pending — as instructed in the DPA
Representatives of cooperating companies (vendors, partners)Ordinary; confidential (bank account numbers)ControllerFor the duration of the cooperation or until the contact person changes / an effective objection is raised; after the cooperation ends — 3 years; accounting data 5 years as above
Employees and contractorsOrdinary; confidential (PESEL, bank account); data required by labour lawControllerPersonnel files: 10 years from the end of the calendar year in which employment ended (employees hired from 2019) — art. 94(9b) of the Polish Labour Code; B2B contractors — as for cooperating companies
Prospective clients (demo / pilot form, leads)Ordinary; content of the enquiry — handled in the business mailbox (sales@deeptech.pl / contact@deeptech.pl); no CRM is used. Audomate is sold to businesses only (B2B-only, confirmed by the Management Board on 10 October 2026), so consumers are not a category of data subjectsControllerUntil consent is withdrawn or an objection is raised; where no cooperation follows — at most 12 months from the last contact
Job candidatesOrdinary; application documentsController3 months after the recruitment ends; with separate consent for future recruitments — 12 months from the application or until consent is withdrawn
General enquiries (contact)Ordinary; content of the messageControllerDuration of handling + 12 months
Website visitorsIP address and technical connection data (server logs); anonymised statistics (Plausible)ControllerServer logs: 30 days. Analytics: no personal data retained beyond the 24-hour hash rotation

Special categories of data (art. 9 GDPR) are not knowingly processed. Where they occur incidentally in client documents they fall under Part B and the client's instructions.

Part B — Platform data classes (DeepTech as processor)

Data classWhere heldRetention
Uploaded client documents (PDF / DOCX)EEA object storage (Google Cloud Storage, dual-region europe-west1 + europe-west4) + vector index (Qdrant / pgvector)Until client deletion request or contract end — then hard-deleted
Personal data extracted to databaseEEA relational database (Cloud SQL PostgreSQL, Belgium)No longer than necessary for the service (GDPR art. 5); at latest, deleted with the contract-end purge
AI session contextMemory only (per-tenant session)Cleared at session end — never persisted; prompts and completions are not retained by the model provider (OpenAI Ireland Ltd — OpenAI API, EU data residency, Zero Data Retention)
Compliance reportsEEA storage, versioned (Cloud Storage + PostgreSQL)Duration of the agreement; on termination exported (open formats) and hard-deleted after the 30-day transition window, unless the client instructs otherwise
Audit trail / logsHash-chained, immutable log (Cloud Logging + PostgreSQL)Minimum 1 year (supports clients' DORA record-keeping — register of information under art. 28(3) and incident records under art. 19 DORA); default 3 years; maximum 5 years, then automatic deletion
Secrets / API keysManaged secret vault (Google Secret Manager, CMEK)Rotated every 90 days; revoked on termination
Website lead-form dataBusiness mailbox (sales@deeptech.pl / contact@deeptech.pl); no CRM is used. E-mail provider: Home.pl (home.pl sp. z o.o., ul. Zbożowa 4, 70-653 Szczecin, Poland)12 months from last contact (per Privacy & Cookie Policy; previously 24 months — aligned)
BackupsEEA, encrypted; Cloud SQL automated backups + point-in-time recovery; Cloud Storage dual-regionBackup retention window: 7 days (Cloud SQL automated backups: 7 days; point-in-time recovery: 7 days). Consequence: deleted data ages out of backups within 7 days at the latest, and restores are possible up to 7 days back

2. Deletion

  • On request / right to erasure: hard delete via the purge pipeline covering vector, relational and object-storage records in one operation; confirmation provided to the requester (for platform data: to the client as controller). Requests are received by e-mail (privacy@audomate.eu; platform clients: support@audomate.eu) — no third-party ticketing tool is used.
  • On termination: full export offered in open formats (PDF, DOCX, CSV, JSON), then purge; transition assistance for 30 days.
  • Scheduled deletion: the retention periods above are enforced by scheduled jobs in the platform and by periodic review of business mailboxes and records; the CTO reviews the schedule at least annually together with this policy.
  • Backup nuance: deleted records persist in encrypted backups until the 7-day backup window elapses — i.e. for at most 7 days after deletion; backups are not restored except for disaster recovery, and any record restored from backup that was previously deleted is re-deleted.

A documented legal hold (statutory obligation, regulatory request, or litigation) suspends scheduled deletion for the identified records only. Each hold is recorded in the audit trail with scope and legal basis, reviewed quarterly, and released in writing; deletion resumes automatically on release.

4. Contact

Deletion requests and questions: privacy@audomate.eu (data protection coordinator: Kacper Raubo). Platform clients submit deletion and export instructions through support@audomate.eu or the channels defined in the DPA.

Document control

VersionDateAuthorApproved byChanges
0.9September 2026DeepTech (CTO / CEO)— (working draft, not adopted)Working draft published for transparency; items marked "to confirm".
1.0October 2026DeepTech (CEO / CTO)— (superseded by 1.1)Changes after the GDPR (RODO) / NIS2 audit of 7–8 October 2026: policy split into Part A (personal data by category of data subject — new, public) and Part B (platform data classes — original table kept and completed); audit-trail retention referenced to art. 28(3) and art. 19 DORA (not art. 25); lead-form retention aligned to 12 months; backup window and lead-handling tool flagged; scheduled deletion added.
1.110 October 2026DeepTech (CEO / CTO / data protection coordinator)Management Board — pendingUpdates after Management Board decisions of 10 Oct 2026: backup window set to 7 days (Cloud SQL automated backups 7 days + PITR 7 days) — deleted data ages out of backups within 7 days; lead handling described as mailbox only (no CRM), deletion requests by e-mail (no ticketing tool); mOrganizer finansów (mBank S.A.) named as invoicing provider; model provider corrected to OpenAI Ireland Ltd (OpenAI API, EU data residency, ZDR); Data Protection Coordinator named (Kacper Raubo); B2B-only confirmed; DPA in legal review (law firm) since 10 Oct 2026.
1.211 October 2026DeepTech (CEO / CTO / data protection coordinator)Management Board — pendingOpen item closed on the basis of Management Board answers of 11 Oct 2026: business e-mail provider named (Home.pl), Part B.

Back to the Trust Center document library