Quorify

Data Retention Policy

Version 1.0 · Last updated: August 31, 2026

In case of conflict between the two versions, the Romanian version prevails.

We keep personal data only as long as necessary for the purposes for which it was collected (Art. 5(1)(e) GDPR). At the end of the period, data is securely deleted or anonymized.

Data categoryRetentionBasis
Account data (active user)Life of accountContract
Profile dataLife of accountContract
Session / auth data30 daysSecurity
CNP data (Formular 230)5 fiscal years + 1 yearFiscal/legal obligation + consent
Recruitment data (unsuccessful)6 months after decisionLegitimate interest
Financial data / invoices10 yearsFiscal Code
Audit / activity logs12 months – 5 years (by event type)Security / legitimate interest / legal obligation
Contact form12 monthsLegitimate interest
Calculator leads (email)24 monthsConsent
Consent records (cookie)3 yearsLegal obligation (proof)
Membership history5 yearsLegitimate interest

Audit (activity) logs use tiered retention based on the importance of the event: routine (informational) events are kept 12 months; noteworthy changes (e.g. role or settings changes) 24 months; and critical events — security, financial, governance (votes) and destructive actions — 5 years. Critical events are never deleted early.

Formular 230 data (including CNP) is automatically deleted by a recurring process after the 5 fiscal years + 1 year archiving period; the records and associated PDF documents are permanently removed. See the 230 DPA.

On account deletion or subscription termination, associated data is deleted per the DPA, except where retention is legally required (e.g. fiscal records). Requests: contact@usequorify.com.