Bokko
Back to home
ARCHIVED VERSION — no longer in effect. This is the r2 version of the Retention & Deletion Policy. The currently effective text is the r3 version of the Retention & Deletion Policy, which adds the "My Data" central guest data-management portal section.

Legal Document

Retention & Deletion Policy

This document records Bokko's data retention principles and the deletion schedule applied to main data categories. Effective as of: July 1, 2026 (Open Beta — v1-open-beta-r2-en).

Governing Language. This English translation is provided for convenience only. In the event of any discrepancy or dispute, the Hungarian version of this Retention Policy shall be the sole authoritative text.
Important: Where law mandates longer retention, or in case of open legal disputes, authority requests, or security incidents, deletion may be postponed for the necessary duration.

Contents

1. Principles 2. Retention Schedule 3. Deletion Rules 4. Data Subject Requests 5. Review

1. Core Principles

  • Bokko only retains personal data for as long as necessary for the specific purpose.
  • Retention rules follow service delivery, security, and enforcement requirements.
  • Bokko implements retention through system-level automated processes where available; otherwise, administrative or periodic purge processes are used.

2. Retention Schedule

Data Category Retention Period Rule
Service Provider account data During the term of the contract, then 90 days Deleted or anonymized after the export and recovery window.
Service Provider profile and configuration During the term of the contract, then 90 days Retained only for a temporary transition period after termination.
Guest booking records 60 months (5 years) From appointment date or final status update. Based on general statutory limitation periods.
Booking event logs 60 months (5 years) Deleted along with the associated booking.
Guest profile and phone index 60 months (5 years) from last activity Synchronized with guest document deletion. No independent TTL.
Waitlist subscription data Until salon-configured expiry (1–90 days, default: 30) Automatically deleted by scheduled function upon expiry.
Guest response tokens Until booking closure, or max 30 days after Deleted or nulled after the matter is closed.
SMS and email delivery metadata 12 months Deleted after the delivery accountability period.
Review request email audit (task) log 3 months from creation (createdAt) Operational audit and debugging purpose. NOT used for the 90-day frequency cap calculation — that lives on the guest record reviewRequestLastSentAt field. Automatically purged after 3 months by the purgeExpiredData scheduled job.
Rate limiting and security data 12 months May be extended during active incidents.
Customer communication (emails, support tickets) 7 years Based on legitimate interest for accountability and enforcement.
Internal admin notes for profiles 7 years Restricted to platform admin access; for operational accountability.
Legal enforcement communication 5 years from case closure Retained for contractual or legal claims.
Billing and accounting records At least 8 years Mandatory retention under Hungarian accounting laws. Independent controller purpose.
Admin and security audit logs 7 years Based on legal enforcement and security obligations.
Data export audit records & temp files Until signed URL expiry Temporary storage for compliance exports; deleted via TTL.
Lifecycle and system event logs 6 months For operational and incident investigation; automated purge.
Staff invitations 30 days from expiry or acceptance Automatically deleted for email PII cleanup.
Staff profile PII (name, email) after deletion or anonymisation Anonymisation immediate on PII fields; audit log entry 7 years For cases handled by the anonymize_staff_member (PII cleanup), remove_member, and unlink_staff callables, Bokko immediately anonymises the profile PII fields (name, email) and records the operation in the 7-year admin audit log. Booking history is retained in anonymised form for statistical and accounting-record consistency purposes.
Provider-uploaded images (avatar, hero, logo, gallery) and derived image variants For the duration of the contract; deleted alongside the 30-day export window after regular termination Storage triggers automatically generate variants (thumbnails) that are also deleted when the source asset is deleted. „Forward-orphan" cases (object without a Firestore reference) are reconciled by the scheduled cleanupOrphanedStorageRefs job.
Newsletter recipient snapshot and consent audit log Recipient snapshot: 24 months from send; consent audit: 5 years The recipient list snapshot captured at send time is retained for 24 months to handle delivery complaints; the double opt-in consent change audit log is retained for 5 years for the demonstrability purpose referenced in Section 3a.
Subscription lifecycle and refund metadata (subscription doc, Stripe metadata) For the duration of the contract + 8 years from termination The subscription doc contains the firstPaid* fields (amount, currency, Stripe invoice.status_transitions.paid_at), the 30-day refund window state, and the refund saga lifecycle metadata. The 8-year retention follows the accounting obligation (Hungarian Accounting Act § 169).
Terminated (archive_readonly) salon dataset (booking history, profile, images, configuration) Retained until reactivation is possible; not automatically purged together with the 30-day export window from termination Upon termination (Stripe customer.subscription.deleted), the salon enters accountMode = 'archive_readonly'; in this state the dataset is retained in read-only form so the provider can resume the subscription with the existing data in a later reactivation window (create_reactivation_checkout_session). During Open Beta, no automatic archive_readonly purge job runs; an explicit phase-out schedule and data-subject notification will be introduced before GA cutover (see internal rule feedback_archive_readonly_no_auto_purge).
Outbound webhook delivery and retry log 12 months from delivery or terminal exhaustion state Delivery metadata of webhook events sent from Bokko to third-party downstream systems (status, retry count, exhaustion state) — for debug and complaint handling purposes. Details in Terms of Service Section 15.

3. Deletion Rules

  • Booking-related event logs and derived guest indexes are deleted in coordination.
  • Response tokens are deleted or nulled after use or case closure.
  • Bokko uses scheduled cleanup tasks for system-wide execution of the retention policy.

4. Data Subject Requests

Requests regarding guest booking data are handled by Bokko according to instructions from the relevant service provider, as the provider is the data controller. For Bokko's independent purposes, Bokko acts directly.

5. Review

This document is reviewed at least annually, or upon introduction of new data flows, providers, or legal requirements.

Product

Features Sign up Log in Status Help

Legal

All legal documents Privacy Policy Terms of Service Service Agreement Imprint & Contact

Compliance

Sub-processors Retention policy Cookie policy Security & privacy

© 2026 Bokko