DAT
Data retention policy
Updated September 25, 20261 min read
How long we keep each kind of data, where it is stored, and how it is protected.
⚠ Draft template — must be reviewed by a lawyer before launch.
The German version is legally binding.
Retention periods#
- Member account: until you delete it, plus 30 days of backups.
- Stamps and rewards: until the account is deleted; unused rewards expire after 12 months.
- Invoices and accounting records: 10 years (§ 147 AO, § 257 HGB).
- Business letters: 6 years.
- Server logs: 14 days.
- Newsletter consent proof: 3 years after unsubscribing.
Where your data lives#
During the current preview, member accounts are stored only in your own browser and are never sent to us. When online accounts go live, account and order data will be stored in EU data centres wherever the provider offers it, and uploaded images in object storage with EU jurisdiction. We will update this page before that happens.
How we protect it#
All connections to this site are TLS-encrypted. When online accounts go live, passwords will be stored only as salted hashes, staff will only get the access their role needs, administrative access will require two-factor authentication, and access to personal data will be logged.
If something goes wrong#
In the event of a data breach we inform the supervisory authority within 72 hours (Art. 33 GDPR) and affected persons without undue delay if there is a high risk to them (Art. 34 GDPR).