Bossete · Legal
Data Retention & Deletion
How long Bossete keeps personal and financial data, how deletion works, and how often this policy is reviewed.
1. Principles
We retain personal data only as long as needed for the purposes described in the Privacy Policy, for security and dispute resolution, and as required by law. This policy is defined, enforced in operations, and reviewed periodically (at least annually, and when products or laws change).
2. Retention periods
| Data class | Typical retention | Notes |
|---|---|---|
| Web / edge access logs | Up to 90 days | Platform defaults may vary; used for security and reliability. |
| Payment records (status, amount, ids) | 7 years or legal minimum | Accounting and fraud defense; card PAN not stored by us when using hosted checkout. |
| Bank-connection tokens (e.g. Plaid) | While connection is active + short deactivation buffer | Revoked on disconnect or account deletion request. |
| Account balances / transactions (derived) | While needed for product purpose, then deleted or anonymised | Shorter windows preferred; not used for resale. |
| Support / security email | Up to 24 months after closure | Unless a longer legal hold applies. |
| Security incident records | Up to 3 years | Post-incident learning and accountability. |
3. Deletion
You may request deletion of personal data by emailing legal@bossete.com. We will:
- Verify the request (to prevent abusive deletion of another person's data);
- Delete or anonymise data we control within a reasonable period (target: 30 days);
- Request deletion from processors where data remains under their control, as the contract allows;
- Retain what law still requires (for example payment records under tax rules) and tell you if retention blocks full erasure.
Disconnecting a bank Link and requesting token revocation is available through product controls where implemented, and always via the contact above.
4. Enforcement and review
- Operational systems and scripts are expected to honour retention windows when purging logs and caches.
- This policy is reviewed at least yearly with the Information Security Policy.
- Material vendor diligence findings that change retention practices will be reflected here.
5. Contact
Deletion and retention questions: legal@bossete.com
Security: security@bossete.com