Data Retention and Disposal Policy
1. Purpose and Regulatory Alignment
The purpose of this Data Retention and Disposal Policy ("Policy") is to establish formal standards for the retention, archival, and irreversible disposal of customer, financial, and operational data processed by ShiftCore UG (haftungsbeschränkt) within the CompanyFin platform.
This Policy adheres strictly to the following legal and regulatory frameworks:
- EU General Data Protection Regulation (GDPR / DSGVO): Enforcing the principles of storage limitation (Art. 5(1)(e)), data minimization (Art. 5(1)(c)), integrity and confidentiality (Art. 5(1)(f)), and the right to erasure / "right to be forgotten" (Art. 17).
- German Commercial Code (§ 257 HGB) & German Fiscal Code (§ 147 AO): Mandatory statutory archival periods of 6 to 10 years for books, inventories, annual accounts, commercial letters, accounting vouchers, and receipts.
- GoBD (Grundsätze zur ordnungsmäßigen Führung und Aufbewahrung von Büchern): Principles governing electronic accounting and immutable voucher storage in Germany.
- Financial API & Partner Security Standards: Security and data handling compliance requirements mandated by Plaid Inc. and European Open Banking / PSD2 regulations.
- NIST SP 800-88 Rev. 1: Guidelines for media sanitization and cryptographic data destruction.
2. Scope and Systems
This Policy applies to all production databases, cloud object repositories, in-memory caches, and API integrations operated by ShiftCore UG:
- Relational Production Databases (PostgreSQL): User accounts, organizational structures, transaction journals, double-entry ledger postings, and audit logs.
- Cloud Object Storage (Hetzner Online GmbH S3, Region Nürnberg / Germany): Encrypted receipt images, invoice documents, OCR-extracted text files, and export packages.
- Financial & Banking API Integrations: Synchronized banking items, encrypted access tokens, transaction history payloads, and cursors (Plaid, Enable Banking, Stripe Connect).
- In-Memory Caches & Throttling (Redis): Ephemeral authentication tokens, sliding-window rate limit counters, and OAuth exchange state tokens.
- Communication Infrastructure (Resend): Inbound receipt email processing pipelines (
belege.companyfin.de) and outbound transactional notification logs.
3. Data Classification Matrix
All data handled by CompanyFin is classified into five operational sensitivity tiers:
| Classification Tier | Description | Examples | Sensitivity |
|---|---|---|---|
| Class 1: Master & Account Data | User identity, authentication profiles, and business registration. | Company legal name, user full names, email addresses, Argon2/bcrypt password hashes. | High |
| Class 2: Financial & Accounting Records | Statutory business documents, invoices, journal postings, and bank statements. | Receipt files (PDF/PNG), extracted vendor metadata, amounts, tax rates, SKR04 bookings, DATEV files. | Critical (Statutory) |
| Class 3: Provider Credentials & Tokens | Cryptographic credentials enabling automated bank sync. | Plaid Item IDs, encrypted Plaid access tokens, Enable Banking tokens, ECDH exchange keys. | Highly Critical |
| Class 4: Ephemeral & Session Data | Short-lived authorization tokens and state cookies. | HTTP-only session cookies, JWT refresh tokens, OAuth state parameters, password reset tokens. | Medium |
| Class 5: Telemetry & System Logs | Diagnostic event streams and error logs. | Anonymized IP addresses, HTTP routing codes, Sentry exception traces (PII scrubbed). | Low |
4. Retention Schedule and Statutory Timelines
Data is stored strictly for the duration required to achieve its operational purpose or to satisfy mandatory statutory retention periods:
| Data Category | Retention Period | Trigger / Calculation | Legal Basis |
|---|---|---|---|
| Statutory Accounting Records & Invoices | 10 Years | Commences at the end of the calendar year in which the record or booking was finalized. | § 147 Abs. 1 Nr. 1, 4, 4a AO; § 257 Abs. 1 Nr. 1, 4 HGB; GoBD |
| Commercial Correspondence & Contracts | 6 Years | Commences at the end of the calendar year of dispatch or receipt. | § 147 Abs. 1 Nr. 2, 3 AO; § 257 Abs. 1 Nr. 2, 3 HGB |
| Active Customer Profile & Tenant Data | Active Contract + 30 Days | Maintained for the duration of the subscription; 30-day export grace period upon cancellation. | Art. 6(1)(b) GDPR (Contract Performance) |
| Financial Provider Credentials (Plaid / Bank Sync) | Immediate Purge / Revocation | Permanently deleted and revoked upon user-initiated disconnect or account closure. | Art. 6(1)(b) GDPR; User Authorization |
| Temporary Bank Snapshots | Max 90 Days | Retained only until reconciled into confirmed ledger entries or reviewed. | Art. 5(1)(c) GDPR (Data Minimization) |
| Authentication & Session Cookies | 15 Min to 30 Days | Access tokens expire in 15 min; rolling refresh tokens expire after 30 days or on logout. | § 25 Abs. 2 TDDDG; Security Best Practice |
| OAuth State & Reset Tokens | 30 to 45 Minutes | Plaid OAuth state TTL: 45 min; Password reset token TTL: 30 min. | Ephemeral Security Token TTL |
| Security Audit Logs | 12 to 24 Months | Rolling automated purge; maintained for intrusion detection and forensic audit. | Art. 6(1)(f) GDPR (Legitimate Security Interest) |
| Error Diagnostics (Sentry) | 90 Days | Automatic rotation; all request bodies, credentials, and cookies filtered at source. | Art. 6(1)(f) GDPR |
5. Account Deletion and Right to Erasure Workflow
5.1 User-Initiated Bank Disconnection
When a user disconnects an integrated bank account in CompanyFin settings:
- The connection token is immediately invalidated with the upstream provider (e.g., Plaid
/item/remove). - The encrypted access token (
encrypted_access_token) and associated sync cursors are permanently deleted from the database. - No further transaction polling or webhook ingestion occurs. Existing ledger entries already confirmed into accounting journals remain in place for tax compliance.
5.2 Full Account Termination and Cascading Purge
Upon account cancellation by the authorized business administrator:
- Deactivation & 30-Day Grace Period: The account is locked from active modification. The customer may request a comprehensive export of all accounting records (DATEV EXTF, receipt files).
- Cascading Database Deletion: Following the 30-day window, automated purge routines execute relational cascading deletions, permanently removing user credentials, organizations, mappings, and API keys.
- Object Storage Purge: All files stored under the customer’s tenant prefix in the Hetzner S3 bucket are permanently deleted via API commands.
- Customer Statutory Tax Duties: Corporate customers (GmbH/UG) are legally responsible for their own long-term 10-year tax archives under German law. CompanyFin ensures data is fully exportable prior to permanent deletion.
6. Secure Disposal and Sanitization Standards
ShiftCore UG enforces data sanitization aligned with NIST Special Publication 800-88 Revision 1 (Guidelines for Media Sanitization):
- Cryptographic Erasure (Crypto-Shredding): All third-party financial credentials (such as Plaid access tokens) are stored encrypted at rest using authenticated symmetric Fernet / AES-128-CBC encryption. Deletion of the record and periodic rotation of the master encryption key renders any residual data cryptographically unrecoverable.
- Logical Database Sanitization: Deleted records are purged using strict SQL commands with foreign-key cascades, followed by regular database vacuuming (
VACUUM FULL) to overwrite physical disk allocations. - Object Storage Sanitization: S3 object deletions are permanent. S3 bucket policies prevent undelete operations once objects are purged.
- Physical Infrastructure Sanitization: ShiftCore UG relies entirely on certified cloud infrastructure providers. Physical disk decommission, degaussing, and mechanical shredding are conducted by Hetzner Online GmbH (DIN 66399 / ISO 27001 certified data center in Nürnberg) and Render Services, Inc. (SOC 2 Type II certified).
- Workstation Security: Administrative workstations enforce mandatory full-disk hardware encryption (LUKS / FileVault / BitLocker) and are sanitized using cryptographic wipe procedures before reassignment.
7. Legal Holds and Dispute Preservation
Pursuant to Article 17(3)(b) GDPR, statutory retention obligations take precedence over immediate erasure requests. If data is subject to an active tax audit, regulatory investigation, or legal dispute, an administrative legal hold is enacted. Affected data is segregated and restricted from active processing until the formal resolution of the matter.
8. Periodic Review and Governance
This Policy is reviewed and reaffirmed on an annual basis by the Managing Director of ShiftCore UG. Immediate ad-hoc evaluations are conducted upon material architectural changes, addition of new banking API providers, or relevant statutory amendments.
Next formal review date: September 2027.
9. Contact and Administration
For questions regarding this Policy, data deletion verification, or data subject rights, please contact:
ShiftCore UG (haftungsbeschränkt)
Attn: Tim Prellwitz, Managing Director
Weilstraße 10
65183 Wiesbaden, Germany
E-Mail: datenschutz@companyfin.de / support@companyfin.de
Phone: +49 1567 9772959