CedraStack · Legal policies
Data Retention Policy
1. Retention approach
We retain information for agreed service, security, financial and legal needs, then remove or minimize it through the processes below. Periods are not a claim that all provider copies or backups are erased simultaneously. Legal holds or applicable recordkeeping requirements may require a documented exception. Ask hello@cedrastack.com for a category-specific request.
2. Operational events and scheduled jobs
Operational events and scheduled job-run records older than 90 days are purged by the daily retention processor. Aggregate component/job health remains as operational status. Administrative resolution notes should not include unrelated personal information or secrets.
3. Sessions and account tokens
Authentication sessions expire after seven days; password-reset tokens expire after 30 minutes, email verification after 24 hours and invitations after 48 hours. Expiry stops use, but is not immediate deletion of database rows. Expired/revoked sessions and used/expired reset/verification tokens older than 30 days are purged by retention. MFA setup expires after ten minutes; enabled encrypted factors remain until disable/reset or account cleanup.
4. Account deletion
Eligible single-member customer accounts can schedule deletion with a 30-day grace period and cancel before it ends. Shared organizations and accounts belonging to multiple companies require administrator assistance. After the grace period, administrator cleanup removes access and service content; it is not an automatic deletion exactly on day 30. Administrators cannot delete their internal accounts through this client flow.
5. Service content and private files
Eligible cleanup removes tickets/messages, attachments, work logs, assets, onboarding, maintenance, company documents, generated PDFs and reports, along with related tasks. Private files, payment proofs and PDFs are queued for R2 deletion with durable retries; unavailable storage may delay physical removal. Bookings keep minimized historic dates/status after contact links and issue details are removed. Archive is not deletion.
6. Financial, audit and legal history
Invoices, payments, subscriptions, minimized bookings, rollover ledger and legal acceptance receipts remain as historical financial/accountability records. Existing audit detail/IP and identifying account/company fields are scrubbed during eligible cleanup; acceptance receipts also lose network metadata and remain linked to minimized record identifiers. No automatic financial/audit/acceptance purge is implemented. Annual manual review is the policy target; final durations depend on applicable obligations and legal review. These records should not be described as necessarily irreversibly anonymous.
7. Leads, security events and manual review
Converted lead contact text is scrubbed during company cleanup. Unconverted leads, general security history and inactive service records have no blanket automatic purge. Review closed leads after 12 months and security history after 12 months as manual policy targets, deleting or minimizing where no continuing need exists. These reviews are not currently automated. User-linked security events and MFA/session data are removed during eligible account cleanup.
8. Provider copies, return and exceptions
Brevo mailbox/delivery copies, Cloudflare backups and other provider-level records follow their own configured retention and contracts; portal cleanup does not invoke a universal provider deletion API. Return/export and privacy requests require identity/authority checks and may need manual work. Records needed for active disputes or legal obligations may be restricted rather than deleted, with reasons and review recorded. Contact hello@cedrastack.com.
SHA-256: daf5325c077e6bc39735fa16e129adda054824ed7d6d6823b669de290327b6a0
