Legal
Data Retention Policy
This Policy explains how long Infotech Solutions retains personal data in connection with Tamanor, in line with the storage-limitation principle (Art. 5(1)(e) GDPR) and Slovak legal retention requirements.
Last updated: 17 July 2026
1. Principles
We keep personal data only as long as necessary for the purpose for which it was collected, plus any period required by law or needed to establish, exercise or defend legal claims. When a retention period ends, data is deleted or irreversibly anonymised. For data we process on a Customer's behalf (as processor), retention follows the Customer's instructions and the DPA; the Customer is the controller.
2. Retention schedule (controller data)
| Data | Retention period | Basis |
|---|---|---|
| Active account & tenant data | For the life of the account + up to 30 days wind-down after closure | Contract; then deletion |
| OAuth connection tokens/metadata | Until you disconnect or close the account; deleted/invalidated on disconnect | Contract; security |
| Billing, invoicing & tax records | 10 years from the end of the relevant accounting period | Slovak Accounting Act No. 431/2002 & VAT/tax law |
| Contracts and order records | 10 years after the end of the contract | Legal obligation / limitation periods |
| Audit logs (moderation accountability) | Up to 3 years | Legitimate interest — accountability |
| Operational / security logs | Typically 90 days, up to 12 months for security investigations | Legitimate interest — security |
| Support & correspondence | Up to 3 years after last contact | Legitimate interest |
| Lead / "book a demo" data | Up to 24 months from last contact, or until objection | Legitimate interest / pre-contractual |
| Cookie-consent records | Up to 12 months; consent proof retained to evidence compliance | Legal obligation (accountability) |
| Analytics data (consent-based) | Per the tool's configured retention (e.g. 14 months in GA4); deleted on consent withdrawal | Consent |
| Backups | Overwritten on the ordinary backup cycle (typically ≤ 35 days) | Security/continuity |
Where multiple periods apply, the longest applicable period governs, after which data is deleted or anonymised.
3. Customer content (processor data)
Content and author metadata ingested from connected platforms are retained for the term of the Customer's subscription and deleted or returned after termination (default: deletion within 30 days), except audit-log entries required for accountability. Customers can trigger cleanup/reset of content within the Service. See the DPA.
4. Deletion on request
Data subjects may request erasure (Art. 17 GDPR) as described in the Data Subject Rights Policy. We will erase data unless we are required or entitled to keep it (e.g. tax records, legal claims). Where immediate deletion from backups is not feasible, data is isolated and deleted on the next backup rotation.
5. Anonymisation
We may retain aggregated or anonymised data (which no longer identifies anyone) indefinitely for statistics and product improvement.
6. Review
This Policy is reviewed at least annually. Contact: info@tamanor.com.