The principle
We retain personal data only for as long as necessary to fulfil the purpose we collected it for, to meet legal obligations, to resolve disputes, and to keep our services secure. When data is no longer needed, we delete it or irreversibly anonymise it.
Retention at a glance
| Data | Typical retention | Reason |
|---|---|---|
| Account data | For the life of your account, then deleted on closure subject to the items below | Provide the service |
| Invoices & tax records | Up to 7 years | Dutch and EU accounting and tax law |
| Support & email correspondence | Up to 24 months after the matter is closed | Continuity and dispute handling |
| Security & audit logs | Short, rolling windows aligned to security needs | Detect and investigate abuse |
| Server request logs | Short, rolling windows | Reliability and security |
| Backups | Until they rotate out of the normal backup cycle | Disaster recovery |
These periods are indicative. Specific products may set their own schedules — Vault One's are described in the Vault One Privacy Policy.
Backups
When we delete data from our live systems, copies may persist in encrypted backups for a limited period until those backups are rotated and overwritten. We do not restore deleted personal data from backups except for genuine disaster recovery.
Asking us to delete sooner
You can ask us to delete eligible data before these periods elapse. See the Data Deletion Policy for how, and what we may be required to keep.