Data Retention & Deletion Policy
SimpleSecurity is currently in pre-launch. The operating Swedish company (aktiebolag) is under registration — org.nr [ORG-NR] will be inserted here once registration completes.
1. Principles
SimpleSecurity applies the storage limitation principle under GDPR Article 5(1)(e): personal data is kept only for as long as necessary for the purposes for which it was collected. This policy sets out how long each category of data is retained, on what basis, and how it is deleted.
2. Retention Schedule
| Data category | Examples | Retention | Basis |
|---|---|---|---|
| Account & platform data | User accounts, CMDB asset inventory, monitoring configuration, compliance records, and other data entered into the platform. | For the life of the customer relationship; deleted on erasure request or self-service deletion. | Contract performance; GDPR Art. 5(1)(e), Art. 17. |
| Monitoring & scan history + notifications | Uptime checks, SSL scan results, vulnerability scan history, notification/alert delivery logs. | Auto-expires via DynamoDB Time-To-Live (TTL). | Storage limitation; operational necessity. |
| Application logs | AWS CloudWatch logs generated by normal platform operation. | 30 days. | Legitimate interest — debugging and security monitoring. |
| Infrastructure audit logs | AWS CloudTrail records of infrastructure and administrative API actions. | 90 days. | Legitimate interest — security and accountability. |
| Continuous backups | DynamoDB point-in-time recovery (PITR) snapshots. | Rolling 35-day window — deleted data ages out of backups within 35 days. | Resilience and disaster recovery. |
| Billing records | Invoices, subscription/billing status records. | 7 years. | Swedish Bookkeeping Act (bokföringslagen 1999:1078). |
3. Deletion on Termination
Organization admins can permanently delete the entire organization (all users, assets, monitors, incidents, policies incl. uploaded documents, vendor records, and settings) self-service from the dashboard, via the "Danger Zone" in User Management → Security, with typed confirmation.
Deletion is also honored on written request to security@simplesecurity.se within 30 days.
Because SimpleSecurity uses continuous backups (DynamoDB point-in-time recovery), data deleted from the live system is not necessarily removed from backups immediately — it ages out of the rolling 35-day PITR window and is fully gone from backups no later than 35 days after deletion.
4. Data Subject Erasure Requests
If you are an individual whose personal data is processed by a SimpleSecurity customer (for example, an employee listed as an asset owner or contact), and you wish to exercise your erasure or other data subject rights, please contact your organization's admin directly, as they control the data. You may also contact us at security@simplesecurity.se and we will route your request accordingly.