Skip to main content
CedraStack
ServicesPlansAboutContactEmergencyKnowledge BaseFAQRequest Support
/

CedraStack · Legal policies

Data Retention Policy

Version 2026-10-07.1 · Effective 2026-10-07 · Updated 2026-10-07

1. Retention approach2. Operational events and scheduled jobs3. Sessions and account tokens4. Account deletion5. Service content and private files6. Financial, audit and legal history7. Leads, security events and manual review8. Provider copies, return and exceptions

1. Retention approach

We retain information for agreed service, security, financial and legal needs, then remove or minimize it through the processes below. Periods are not a claim that all provider copies or backups are erased simultaneously. Legal holds or applicable recordkeeping requirements may require a documented exception. Ask hello@cedrastack.com for a category-specific request.

2. Operational events and scheduled jobs

Operational events and scheduled job-run records older than 90 days are purged by the daily retention processor. Aggregate component/job health remains as operational status. Administrative resolution notes should not include unrelated personal information or secrets.

3. Sessions and account tokens

Authentication sessions expire after seven days; password-reset tokens expire after 30 minutes, email verification after 24 hours and invitations after 48 hours. Expiry stops use, but is not immediate deletion of database rows. Expired/revoked sessions and used/expired reset/verification tokens older than 30 days are purged by retention. MFA setup expires after ten minutes; enabled encrypted factors remain until disable/reset or account cleanup.

4. Account deletion

Eligible single-member customer accounts can schedule deletion with a 30-day grace period and cancel before it ends. Shared organizations and accounts belonging to multiple companies require administrator assistance. After the grace period, administrator cleanup removes access and service content; it is not an automatic deletion exactly on day 30. Administrators cannot delete their internal accounts through this client flow.

5. Service content and private files

Eligible cleanup removes tickets/messages, attachments, work logs, assets, onboarding, maintenance, company documents, generated PDFs and reports, along with related tasks. Private files, payment proofs and PDFs are queued for R2 deletion with durable retries; unavailable storage may delay physical removal. Bookings keep minimized historic dates/status after contact links and issue details are removed. Archive is not deletion.

6. Financial, audit and legal history

Invoices, payments, subscriptions, minimized bookings, rollover ledger and legal acceptance receipts remain as historical financial/accountability records. Existing audit detail/IP and identifying account/company fields are scrubbed during eligible cleanup; acceptance receipts also lose network metadata and remain linked to minimized record identifiers. No automatic financial/audit/acceptance purge is implemented. Annual manual review is the policy target; final durations depend on applicable obligations and legal review. These records should not be described as necessarily irreversibly anonymous.

7. Leads, security events and manual review

Converted lead contact text is scrubbed during company cleanup. Unconverted leads, general security history and inactive service records have no blanket automatic purge. Review closed leads after 12 months and security history after 12 months as manual policy targets, deleting or minimizing where no continuing need exists. These reviews are not currently automated. User-linked security events and MFA/session data are removed during eligible account cleanup.

8. Provider copies, return and exceptions

Brevo mailbox/delivery copies, Cloudflare backups and other provider-level records follow their own configured retention and contracts; portal cleanup does not invoke a universal provider deletion API. Return/export and privacy requests require identity/authority checks and may need manual work. Records needed for active disputes or legal obligations may be restricted rather than deleted, with reasons and review recorded. Contact hello@cedrastack.com.

SHA-256: daf5325c077e6bc39735fa16e129adda054824ed7d6d6823b669de290327b6a0

Client Terms of ServicePrivacy PolicySupport Policy and Response TargetsData Processing AgreementProviders and SubprocessorsData Retention Policy
CedraStack
CedraStack

Remote IT & Cloud Support for Modern Businesses.

Beirut, Lebanon

Services

Microsoft 365Servers & VirtualizationNetworking & SecurityCloud & Infrastructure

Support

Support PlansEmergency SupportClient Portal

Contact

FAQRequest IT Supporthello@cedrastack.comsupport@cedrastack.com

Monday–Friday
08:00–18:00 Beirut

Legal

Client Terms of ServicePrivacy PolicySupport Policy and Response TargetsData Processing AgreementProviders and SubprocessorsData Retention Policy
© 2026 CedraStack. All rights reserved.