CompanyFin LogoCompanyFin
FunktionenPreiseRessourcenFAQ
Zurück zur Startseite

Data Retention and Disposal Policy

Stand / Effective Date: 17. September 2026 · Version 1.0
Richtlinie als PDF herunterladen (Download PDF)
Compliance & Security Overview

Diese Richtlinie definiert die verbindlichen Fristen, technischen Verfahren und Sicherheitsstandards für die Speicherung, Archivierung und sichere Entsorgung von Unternehmens-, Finanz- und Telemetriedaten der Plattform CompanyFin. Sie erfüllt die Anforderungen der DSGVO (Art. 5, 17), des deutschen Handels- und Steuerrechts (§ 257 HGB, § 147 AO, GoBD) sowie internationaler Schnittstellenstandards (u. a. Plaid Inc. & Open Banking).

1. Purpose and Regulatory Alignment

The purpose of this Data Retention and Disposal Policy ("Policy") is to establish formal standards for the retention, archival, and irreversible disposal of customer, financial, and operational data processed by ShiftCore UG (haftungsbeschränkt) within the CompanyFin platform.

This Policy adheres strictly to the following legal and regulatory frameworks:

  • EU General Data Protection Regulation (GDPR / DSGVO): Enforcing the principles of storage limitation (Art. 5(1)(e)), data minimization (Art. 5(1)(c)), integrity and confidentiality (Art. 5(1)(f)), and the right to erasure / "right to be forgotten" (Art. 17).
  • German Commercial Code (§ 257 HGB) & German Fiscal Code (§ 147 AO): Mandatory statutory archival periods of 6 to 10 years for books, inventories, annual accounts, commercial letters, accounting vouchers, and receipts.
  • GoBD (Grundsätze zur ordnungsmäßigen Führung und Aufbewahrung von Büchern): Principles governing electronic accounting and immutable voucher storage in Germany.
  • Financial API & Partner Security Standards: Security and data handling compliance requirements mandated by Plaid Inc. and European Open Banking / PSD2 regulations.
  • NIST SP 800-88 Rev. 1: Guidelines for media sanitization and cryptographic data destruction.

2. Scope and Systems

This Policy applies to all production databases, cloud object repositories, in-memory caches, and API integrations operated by ShiftCore UG:

  • Relational Production Databases (PostgreSQL): User accounts, organizational structures, transaction journals, double-entry ledger postings, and audit logs.
  • Cloud Object Storage (Hetzner Online GmbH S3, Region Nürnberg / Germany): Encrypted receipt images, invoice documents, OCR-extracted text files, and export packages.
  • Financial & Banking API Integrations: Synchronized banking items, encrypted access tokens, transaction history payloads, and cursors (Plaid, Enable Banking, Stripe Connect).
  • In-Memory Caches & Throttling (Redis): Ephemeral authentication tokens, sliding-window rate limit counters, and OAuth exchange state tokens.
  • Communication Infrastructure (Resend): Inbound receipt email processing pipelines (belege.companyfin.de) and outbound transactional notification logs.

3. Data Classification Matrix

All data handled by CompanyFin is classified into five operational sensitivity tiers:

Classification TierDescriptionExamplesSensitivity
Class 1: Master & Account DataUser identity, authentication profiles, and business registration.Company legal name, user full names, email addresses, Argon2/bcrypt password hashes.High
Class 2: Financial & Accounting RecordsStatutory business documents, invoices, journal postings, and bank statements.Receipt files (PDF/PNG), extracted vendor metadata, amounts, tax rates, SKR04 bookings, DATEV files.Critical (Statutory)
Class 3: Provider Credentials & TokensCryptographic credentials enabling automated bank sync.Plaid Item IDs, encrypted Plaid access tokens, Enable Banking tokens, ECDH exchange keys.Highly Critical
Class 4: Ephemeral & Session DataShort-lived authorization tokens and state cookies.HTTP-only session cookies, JWT refresh tokens, OAuth state parameters, password reset tokens.Medium
Class 5: Telemetry & System LogsDiagnostic event streams and error logs.Anonymized IP addresses, HTTP routing codes, Sentry exception traces (PII scrubbed).Low

4. Retention Schedule and Statutory Timelines

Data is stored strictly for the duration required to achieve its operational purpose or to satisfy mandatory statutory retention periods:

Data CategoryRetention PeriodTrigger / CalculationLegal Basis
Statutory Accounting Records & Invoices10 YearsCommences at the end of the calendar year in which the record or booking was finalized.§ 147 Abs. 1 Nr. 1, 4, 4a AO; § 257 Abs. 1 Nr. 1, 4 HGB; GoBD
Commercial Correspondence & Contracts6 YearsCommences at the end of the calendar year of dispatch or receipt.§ 147 Abs. 1 Nr. 2, 3 AO; § 257 Abs. 1 Nr. 2, 3 HGB
Active Customer Profile & Tenant DataActive Contract + 30 DaysMaintained for the duration of the subscription; 30-day export grace period upon cancellation.Art. 6(1)(b) GDPR (Contract Performance)
Financial Provider Credentials (Plaid / Bank Sync)Immediate Purge / RevocationPermanently deleted and revoked upon user-initiated disconnect or account closure.Art. 6(1)(b) GDPR; User Authorization
Temporary Bank SnapshotsMax 90 DaysRetained only until reconciled into confirmed ledger entries or reviewed.Art. 5(1)(c) GDPR (Data Minimization)
Authentication & Session Cookies15 Min to 30 DaysAccess tokens expire in 15 min; rolling refresh tokens expire after 30 days or on logout.§ 25 Abs. 2 TDDDG; Security Best Practice
OAuth State & Reset Tokens30 to 45 MinutesPlaid OAuth state TTL: 45 min; Password reset token TTL: 30 min.Ephemeral Security Token TTL
Security Audit Logs12 to 24 MonthsRolling automated purge; maintained for intrusion detection and forensic audit.Art. 6(1)(f) GDPR (Legitimate Security Interest)
Error Diagnostics (Sentry)90 DaysAutomatic rotation; all request bodies, credentials, and cookies filtered at source.Art. 6(1)(f) GDPR

5. Account Deletion and Right to Erasure Workflow

5.1 User-Initiated Bank Disconnection

When a user disconnects an integrated bank account in CompanyFin settings:

  • The connection token is immediately invalidated with the upstream provider (e.g., Plaid /item/remove).
  • The encrypted access token (encrypted_access_token) and associated sync cursors are permanently deleted from the database.
  • No further transaction polling or webhook ingestion occurs. Existing ledger entries already confirmed into accounting journals remain in place for tax compliance.

5.2 Full Account Termination and Cascading Purge

Upon account cancellation by the authorized business administrator:

  1. Deactivation & 30-Day Grace Period: The account is locked from active modification. The customer may request a comprehensive export of all accounting records (DATEV EXTF, receipt files).
  2. Cascading Database Deletion: Following the 30-day window, automated purge routines execute relational cascading deletions, permanently removing user credentials, organizations, mappings, and API keys.
  3. Object Storage Purge: All files stored under the customer’s tenant prefix in the Hetzner S3 bucket are permanently deleted via API commands.
  4. Customer Statutory Tax Duties: Corporate customers (GmbH/UG) are legally responsible for their own long-term 10-year tax archives under German law. CompanyFin ensures data is fully exportable prior to permanent deletion.

6. Secure Disposal and Sanitization Standards

ShiftCore UG enforces data sanitization aligned with NIST Special Publication 800-88 Revision 1 (Guidelines for Media Sanitization):

  • Cryptographic Erasure (Crypto-Shredding): All third-party financial credentials (such as Plaid access tokens) are stored encrypted at rest using authenticated symmetric Fernet / AES-128-CBC encryption. Deletion of the record and periodic rotation of the master encryption key renders any residual data cryptographically unrecoverable.
  • Logical Database Sanitization: Deleted records are purged using strict SQL commands with foreign-key cascades, followed by regular database vacuuming (VACUUM FULL) to overwrite physical disk allocations.
  • Object Storage Sanitization: S3 object deletions are permanent. S3 bucket policies prevent undelete operations once objects are purged.
  • Physical Infrastructure Sanitization: ShiftCore UG relies entirely on certified cloud infrastructure providers. Physical disk decommission, degaussing, and mechanical shredding are conducted by Hetzner Online GmbH (DIN 66399 / ISO 27001 certified data center in Nürnberg) and Render Services, Inc. (SOC 2 Type II certified).
  • Workstation Security: Administrative workstations enforce mandatory full-disk hardware encryption (LUKS / FileVault / BitLocker) and are sanitized using cryptographic wipe procedures before reassignment.

7. Legal Holds and Dispute Preservation

Pursuant to Article 17(3)(b) GDPR, statutory retention obligations take precedence over immediate erasure requests. If data is subject to an active tax audit, regulatory investigation, or legal dispute, an administrative legal hold is enacted. Affected data is segregated and restricted from active processing until the formal resolution of the matter.

8. Periodic Review and Governance

This Policy is reviewed and reaffirmed on an annual basis by the Managing Director of ShiftCore UG. Immediate ad-hoc evaluations are conducted upon material architectural changes, addition of new banking API providers, or relevant statutory amendments.

Next formal review date: September 2027.

9. Contact and Administration

For questions regarding this Policy, data deletion verification, or data subject rights, please contact:

ShiftCore UG (haftungsbeschränkt)
Attn: Tim Prellwitz, Managing Director
Weilstraße 10
65183 Wiesbaden, Germany
E-Mail: datenschutz@companyfin.de / support@companyfin.de
Phone: +49 1567 9772959

CompanyFin LogoCompanyFin

Die intelligente SaaS-Buchhaltung für Kapitalgesellschaften & KMU in Deutschland.

Produkt

  • Funktionen
  • Ersparnis-Rechner
  • Preise
  • Ressourcen & Wissen
  • FAQ

Unternehmen

  • Über uns
  • Sicherheit & GoBD-Unterstützung
  • Kontakt

Rechtliches

  • Impressum
  • Datenschutzerklärung
  • Aufbewahrung & Löschung
  • AGB
© 2026 ShiftCore UG (haftungsbeschränkt). Alle Rechte vorbehalten.
Made with in Germany
Datenschutz-Einstellungen

Cookies & Analyse

Google Analytics 4 misst Nutzung und Conversions. Ohne Einwilligung werden keine Analytics-Cookies gesetzt; Google erhält nur cookielose Messsignale. Mit Ihrer Einwilligung ermöglichen Sie eine genauere Analyse. Eine Ablehnung hat keine Nachteile.

Notwendig

Speichert Ihre Auswahl und ermöglicht Sicherheits- sowie Anmeldefunktionen.

Immer aktiv

Details finden Sie in unserer Datenschutzerklärung. Sie können Ihre Auswahl jederzeit ändern.