Data retention and deletion
This page describes how long different types of data are stored in Revizo, and which routines apply to deletion. We follow GDPR Article 5(1)(e), which requires that personal data is not stored longer than necessary for the purpose.
Retention periods
| Data category | Retention period | Justification |
|---|---|---|
| Accounting data (transactions, balances, reconciliations) | As long as the organisation is active | Necessary to deliver the service |
| User account data (name, email) | Until the account is deleted | Necessary for authentication and access |
| Audit log | As long as the organisation is active | Traceability and compliance |
| AI conversations and AI memories | 90 days, then automatic deletion. The user can delete earlier. | Data minimisation — the history is not needed longer than this. See Revizo AI → Data access |
| Export files created via AI chat | 24 hours | Only for download from the chat |
| Uploaded files and attachments | As long as the organisation is active | Documentation and audit trail |
| Integration tokens (encrypted) | Until the integration is disconnected | Necessary for synchronisation |
| Error logs (Sentry) | 90 days | Troubleshooting and monitoring |
| Deletion history | Permanent | Legal documentation of deletions performed |
| Payment information | Handled by Stripe | Stripe’s retention policy applies |
Deletion of data
Automatic deletion
The following data is deleted automatically:
| Data | Deleted after | Mechanism |
|---|---|---|
| Expired sessions | Automatically | Handled by Clerk |
| Error logs (Sentry) | 90 days | Sentry’s retention policy |
| Request logs (Vercel) | 30 days | Vercel’s retention policy |
| AI conversations and expired AI memories | 90 days | Daily background job |
| Export files from AI chat | 24 hours | Expiry time on the file |
| Scheduled deletions | 30-day grace period | Automatic background job |
User-initiated deletion
Users and administrators can initiate deletion at any time:
Delete user account
- The user’s profile data is removed from Clerk
- The user’s associations in the organisation cease
- The organisation’s data is not affected
Delete organisation
- An administrator schedules deletion
- All members are notified by email
- 30-day grace period — deletion can be cancelled at any time during this period
- 7 days before deletion, a reminder is sent by email
- After 30 days the deletion is performed automatically:
What is deleted:
| Category | Details |
|---|---|
| Database data | All companies, accounts, clients, transactions, reconciliations, contacts, matching rules, tasks, reports, audit log |
| Files | All uploaded files, attachments, and generated reports (Supabase Storage and Cloudflare R2) |
| Integrations | Stripe subscription is cancelled, Tripletex and Visma NXT webhooks are unregistered |
| User associations | The organisation is removed from Clerk |
What is retained:
| Data | Justification |
|---|---|
| Deletion receipt | Legal documentation (who ordered, when, what was deleted) |
| Individual user accounts | Users can create a new organisation or belong to others |
For detailed guidance, see Deleting an organisation and account.
Data export before deletion
Before deletion we strongly recommend that the organisation exports all data. The export includes:
- Companies, accounts, and clients (JSON)
- All transactions (CSV for easy use in Excel)
- Reconciliations and lines (JSON)
- Contacts and relationships (JSON)
- Matching rules (JSON)
- Tasks and task groups (JSON)
- Reports (JSON)
- Full audit log (JSON)
- Metadata with export date and content overview (JSON)
The export is available to all members of the organisation via Settings → Danger zone → Export all data.
After deletion
When deletion has been completed:
- Data cannot be restored
- Database rows are permanently removed (not soft delete)
- Files are deleted from all storage systems
- Integration connections are terminated
- The only thing retained is an anonymised deletion receipt
Questions about data retention
If you have questions about retention periods, want deletion of specific data, or need assistance with data export, contact us:
- Email: karl@savesolutions.no
- Response time: Within 30 days (GDPR requirement)
Last updated: 21 September 2026