Data Retention Policy
Version 1.1 · 2 August 2026 · Owner: Emilia Huikko and Agathon Westin (trading as Dyne) · Review annually
1. Purpose and principles
This policy implements the GDPR storage-limitation principle (Article 5(1)(e)): personal data is kept only as long as necessary for the purpose it was collected for. Where data still has operational value after that point, it is anonymised rather than kept in identifiable form.
2. Retention schedule
| Data | Retention period | Action at end of period | Enforcement |
| Bookings | 24 months | Anonymised (name, email, phone, notes cleared) | Automatic, nightly |
| Booking verification codes | 7 days | Deleted | Automatic, nightly |
| Device verification cookie | 90 days | Expires in the browser | Automatic |
| Diner / partner accounts | While active; 36 months inactivity | Deleted or anonymised | On request / manual review |
| Internal support notes | 24 months | Deleted | Automatic, nightly |
| Administrative audit log | 24 months | Deleted | Automatic, nightly |
| Administrator sign-in attempts | 12 months | Deleted | Automatic, nightly |
| Administrator sessions | 30 days after expiry | Deleted | Automatic, nightly |
| Rate-limiting records | 30 days | Deleted | Automatic, nightly |
| Email delivery logs | 90 days | Deleted | Automatic, nightly |
| Email unsubscribe tokens | 12 months | Deleted | Automatic, nightly |
| Venue enquiries | 24 months | Deleted | Automatic, nightly |
| Restaurant photos in storage | While the venue is listed | Deleted with the listing | Manual |
| Server error logs | Up to 90 days | Deleted by provider | Provider-managed |
3. How the schedule is enforced
A scheduled database routine runs every night at 03:15 Europe/Helsinki. It deletes expired security, verification, logging and enquiry records, and anonymises bookings older than 24 months by clearing the guest name, email, phone number and notes while keeping the row for capacity statistics. The job reports the number of records affected per table.
4. Deletion on request
Erasure requests are handled through the administrator console, which can export all data held about a person and permanently delete their account while anonymising their booking history. Both actions require a stated reason and are written to the append-only audit log. Requests are actioned within one month.
5. Legal holds and exceptions
Retention may be extended where required by accounting or tax law, or where the data is needed to establish, exercise or defend a legal claim. Any such hold is recorded with its reason and lifted as soon as it no longer applies.
6. Backups
Deleted data may persist in encrypted hosting backups for a short period until those backups roll over. Backups are not used for operational access and are subject to the provider's own rotation schedule.
7. Questions
Contact dynerestaurants@gmail.com.
See also our Privacy Notice and Terms of Service.