Dyne

Data Retention Policy

Version 1.1 · 2 August 2026 · Owner: Emilia Huikko and Agathon Westin (trading as Dyne) · Review annually

1. Purpose and principles

This policy implements the GDPR storage-limitation principle (Article 5(1)(e)): personal data is kept only as long as necessary for the purpose it was collected for. Where data still has operational value after that point, it is anonymised rather than kept in identifiable form.

2. Retention schedule

DataRetention periodAction at end of periodEnforcement
Bookings24 monthsAnonymised (name, email, phone, notes cleared)Automatic, nightly
Booking verification codes7 daysDeletedAutomatic, nightly
Device verification cookie90 daysExpires in the browserAutomatic
Diner / partner accountsWhile active; 36 months inactivityDeleted or anonymisedOn request / manual review
Internal support notes24 monthsDeletedAutomatic, nightly
Administrative audit log24 monthsDeletedAutomatic, nightly
Administrator sign-in attempts12 monthsDeletedAutomatic, nightly
Administrator sessions30 days after expiryDeletedAutomatic, nightly
Rate-limiting records30 daysDeletedAutomatic, nightly
Email delivery logs90 daysDeletedAutomatic, nightly
Email unsubscribe tokens12 monthsDeletedAutomatic, nightly
Venue enquiries24 monthsDeletedAutomatic, nightly
Restaurant photos in storageWhile the venue is listedDeleted with the listingManual
Server error logsUp to 90 daysDeleted by providerProvider-managed

3. How the schedule is enforced

A scheduled database routine runs every night at 03:15 Europe/Helsinki. It deletes expired security, verification, logging and enquiry records, and anonymises bookings older than 24 months by clearing the guest name, email, phone number and notes while keeping the row for capacity statistics. The job reports the number of records affected per table.

4. Deletion on request

Erasure requests are handled through the administrator console, which can export all data held about a person and permanently delete their account while anonymising their booking history. Both actions require a stated reason and are written to the append-only audit log. Requests are actioned within one month.

5. Legal holds and exceptions

Retention may be extended where required by accounting or tax law, or where the data is needed to establish, exercise or defend a legal claim. Any such hold is recorded with its reason and lifted as soon as it no longer applies.

6. Backups

Deleted data may persist in encrypted hosting backups for a short period until those backups roll over. Backups are not used for operational access and are subject to the provider's own rotation schedule.

7. Questions

See also our Privacy Notice and Terms of Service.