Retention Policy
This policy summarizes HOSTELELLA's retention criteria. Periods may be extended where there is a legal obligation, blocking due to a claim, security investigation, audit, fraud prevention or a valid Customer instruction.
Retention matrix
| Category | Indicative period | Reason |
|---|---|---|
| Account, profile and business membership | While the account is active and up to 90 days after deactivation, unless legal blocking applies. | Service provision, security and support. |
| Documents, operational records, expenses, sales and business data | While the Customer maintains the service or until requested deletion/export. After deactivation, reasonable deletion within 30-90 days if no legal obligation applies. | Service provision and Customer instructions. |
| Team, shifts, clock-ins/attendance and planning data (incl., where the Customer enables presence verification at clock-in/out, the inside/outside result and the approximate distance; the worker's coordinates are never stored) | While the Customer maintains the service; operational shift data is typically of limited usefulness over time. The presence-verification result is kept together with the working-time record it accompanies (generally 4 years under Art. 34.9 of the Spanish Workers' Statute). The daily working-time record is kept for four years from each clock-in/out (Art. 34.9 Workers' Statute), also after the person leaves the business. After the Customer's deactivation, reasonable deletion within 30-90 days unless legal obligation or Customer instruction; the Customer may export the full record before that deletion and HOSTELELLA provides it on request. | Work organization and working-time record at the Customer's request (Controller); the Customer decides retention within the platform and is responsible for keeping the exported record for the legal period. |
| Absences / time off (incl. sick leave that may reveal health) | While necessary for planning and per the Customer's instructions; reasonable deletion once no longer necessary or after deactivation, unless the Customer has a legal obligation. | Shift planning; the Customer determines the basis and period under labor and social-security law. |
| Labor rules / collective agreement configured by the business | While the business maintains the service; versions are kept for traceability of the applied configuration. | Service configuration and consistency of the shift validator. |
| AI usage records (requests, events and results of shift generation/extraction) | Normally 12-24 months for traceability, quality and security, unless a valid shorter instruction, incident or longer legal period applies; minimized, pseudonymized where possible and content separated from technical logs. | Traceability, debugging, quality and security within the processing mandate; no model training or own-purpose reuse of Customer personal data. |
| Onboarding, order summary and subscription lifecycle | During the contractual relationship and up to 5 years afterwards; tax or accounting elements are kept for up to 6 years or any longer applicable statutory period. | Evidence of purchase and future-charge authorization, renewal/cancellation management, compliance and legal defense. |
| Technical checkout sessions, webhook events and provider references | While needed to complete, reconcile or retry the operation and then in minimized form with the applicable contractual or tax record. Technical anti-replay keys are deleted after 30 days; other unneeded operational payloads are normally deleted or reduced within 12-24 months, unless fraud, incident or claim applies. | Idempotency, reconciliation, support, security and duplicate-charge prevention. |
| Free trials and cryptographic anti-fraud fingerprint | While trials are offered and up to 5 years after the last associated grant or attempt, unless a claim or fraud applies; then deleted or anonymized. | Preventing duplicate trials and abuse without retaining the full payment-method number. |
| Refund requests and decisions | Up to 6 years after the transaction or the applicable statutory period, retaining the minimum case record and outcome. | Accounting reconciliation, fraud prevention, claim handling and legal defense. |
| Apple/Google external-purchase tokens and reports | Tokens are kept only while valid or needed to report and prevent reuse; minimum evidence of the report and its status is kept for up to 5 years or the required contractual/statutory period. | Meeting the reporting deadline, resolving rejections, settling platform fees and evidencing program compliance. |
| HOSTELELLA's own tax, accounting or billing data | Up to 6 years or the applicable legal period. | Commercial, tax and accounting obligations. |
| Consents, accepted terms and legal audit | During the contractual relationship and up to 5 years afterwards or the period needed to defend claims. After account deletion, only minimal, blocked evidence will be kept where necessary. | Contractual proof, compliance and legal defense. |
| Security, access and technical activity logs | Normally 12-24 months, unless incident, fraud or legal obligation. | Security, abuse prevention and incident investigation. |
| Support, transactional emails and incidents | Up to 3 years from closure, unless claim or higher obligation. | Support, quality, continuity and defense of claims. |
| Communication preferences and proof of consent (event ledger) | The ledger is append-only: every opt-in or opt-out creates a new event with date, version and hash of the text shown, language and origin; earlier events are never overwritten. Kept while the account exists and for up to 5 years after the last decision, even if the account is deleted, in a blocked state and not used for any other purpose. | Proof of consent and of its withdrawal (Arts. 5.2 and 7.1 GDPR) and defence against a complaint about an unsolicited communication. |
| Email delivery outcome (delivered, bounced, failed, marked as spam) | Up to 24 months; a permanent bounce or a complaint also creates an entry in the suppression list, which is indefinite. | Knowing whether a necessary communication arrived, removing invalid addresses and protecting sending reputation. |
| Team-invitation opens and clicks, where lawfully enabled | Only while the invitation is alive; erased on acceptance, expiry or revocation and in any event after 12 months. Proof of the applicable consent or exception is kept for the corresponding accountability period. | Letting the inviter see whether it was opened only after satisfying terminal-access requirements. Otherwise only delivery is retained. |
| Suppression list (opt-outs, permanent bounces and complaints) | Indefinite while communication activity exists and also after account deletion. It holds the strict minimum: a cryptographic fingerprint of the address (HMAC-SHA256 with a separately held key, never the address in clear text), the channel, the reason and the date. | Ensuring that anyone who opted out is not contacted again. Deleting the entry would reintroduce exactly the risk the person asked us to avoid, so it is kept blocked and unused for anything else. |
| Rights requests and account deletion | Up to 5 years from request closure, including normalized email, user identifier, status, timestamps and minimal processing events where necessary. | Proof of compliance and defense against claims. |
| Backups | Usual technical cycle of up to 90 days, unless legal backups or incidents. | Continuity, error recovery and security. |
| Anonymized or aggregated data | No fixed period as long as it does not allow identifying a person. | Statistics, service improvement and internal analysis. |
Deletion and blocking
When the applicable period ends, HOSTELELLA will delete, anonymize or block data as appropriate. Blocking limits processing to legal obligations, security, audit or defense of claims.
In account deletion processes, HOSTELELLA will delete operational account data and may keep, in a blocked state, minimal records of consent, accepted terms, deletion request, fraud/abuse, security and compliance where there is a legal basis or prevailing legitimate interest to demonstrate compliance or defend claims.
Data processed as a processor
When HOSTELELLA acts as a processor (including team, shift and absence data), the Customer decides the retention periods for its data within the platform. HOSTELELLA will apply reasonable deletion or export instructions, except for a legal or legitimate technical obligation. The Customer is responsible for complying with the labor and social-security retention periods applicable to it.