Data Retention & Deletion Policy

Version 1.0 · Last updated: 24 July 2026

On this page

  1. Principles
  2. Retention Schedule
  3. Deletion on Termination
  4. Data Subject Erasure Requests
  5. Related Documents

  SimpleSecurity is currently in pre-launch. The operating Swedish company (aktiebolag) is under registration — org.nr [ORG-NR] will be inserted here once registration completes.

1. Principles

SimpleSecurity applies the storage limitation principle under GDPR Article 5(1)(e): personal data is kept only for as long as necessary for the purposes for which it was collected. This policy sets out how long each category of data is retained, on what basis, and how it is deleted.

2. Retention Schedule

Data category Examples Retention Basis
Account & platform data User accounts, CMDB asset inventory, monitoring configuration, compliance records, and other data entered into the platform. For the life of the customer relationship; deleted on erasure request or self-service deletion. Contract performance; GDPR Art. 5(1)(e), Art. 17.
Monitoring & scan history + notifications Uptime checks, SSL scan results, vulnerability scan history, notification/alert delivery logs. Auto-expires via DynamoDB Time-To-Live (TTL). Storage limitation; operational necessity.
Application logs AWS CloudWatch logs generated by normal platform operation. 30 days. Legitimate interest — debugging and security monitoring.
Infrastructure audit logs AWS CloudTrail records of infrastructure and administrative API actions. 90 days. Legitimate interest — security and accountability.
Continuous backups DynamoDB point-in-time recovery (PITR) snapshots. Rolling 35-day window — deleted data ages out of backups within 35 days. Resilience and disaster recovery.
Billing records Invoices, subscription/billing status records. 7 years. Swedish Bookkeeping Act (bokföringslagen 1999:1078).

3. Deletion on Termination

Organization admins can permanently delete the entire organization (all users, assets, monitors, incidents, policies incl. uploaded documents, vendor records, and settings) self-service from the dashboard, via the "Danger Zone" in User Management → Security, with typed confirmation.

Deletion is also honored on written request to security@simplesecurity.se within 30 days.

Because SimpleSecurity uses continuous backups (DynamoDB point-in-time recovery), data deleted from the live system is not necessarily removed from backups immediately — it ages out of the rolling 35-day PITR window and is fully gone from backups no later than 35 days after deletion.

4. Data Subject Erasure Requests

If you are an individual whose personal data is processed by a SimpleSecurity customer (for example, an employee listed as an asset owner or contact), and you wish to exercise your erasure or other data subject rights, please contact your organization's admin directly, as they control the data. You may also contact us at security@simplesecurity.se and we will route your request accordingly.

5. Related Documents

  • Data Processing Agreement
  • Technical & Organisational Measures
  • Privacy Notice
  Trust Center Privacy Notice Terms of Service