Quorify

Data Retention Policy

Version 1.1 · Last updated: August 28, 2026

In case of conflict between the two versions, the Romanian version prevails.

We keep personal data only as long as necessary for the purposes for which it was collected (Art. 5(1)(e) GDPR). At the end of the period, data is securely deleted or anonymized.

Data categoryRetentionBasis
Account data (active user)Life of accountContract
Profile dataLife of accountContract
Session / auth data30 daysSecurity
Individually deleted items (tasks, events, announcements, documents, contacts, reviews, budgets, templates, recruitment candidates)30 days in a recoverable trash, then permanent deletionError recovery, defence of legal claims (Art. 17(3)(e) GDPR)
Organization-level snapshots30 days from creation (created automatically weekly)Incident recovery, defence of legal claims (Art. 17(3)(e) GDPR)
CNP data (Formular 230)5 fiscal years + 1 yearFiscal/legal obligation + consent
Recruitment data (rejected candidates, not manually deleted)For the duration of the recruitment cycle; manual deletion by the organization starts the 30-day trash aboveLegitimate interest
Financial data / invoices10 yearsFiscal Code
Audit / activity logs12 months – 5 years (by event type)Security / legitimate interest / legal obligation
Contact form12 monthsLegitimate interest
Calculator leads (email)24 monthsConsent
Consent records (cookie)3 yearsLegal obligation (proof)
Membership history5 years (or until the organization is deleted, if earlier)Legitimate interest

Audit (activity) logs use tiered retention based on the importance of the event: routine (informational) events are kept 12 months; noteworthy changes (e.g. role or settings changes) 24 months; and critical events — security, financial, governance (votes) and destructive actions — 5 years. Critical events are never deleted early, except where the organization itself is deleted (see below).

The 30-day trash for individually deleted items

When you or an administrator delete a task, event, announcement, document, contact, review, budget, template or recruitment candidate, the item disappears immediately from normal user experience - it no longer appears in lists, search or reports. The row remains recoverable for 30 days in an internal "trash," accessible only to an authorized Quorify Super Admin, for error, technical-incident or abuse cases. After 30 days, an automated process permanently deletes the data.

Exception: when a member is removed from an organization, their personal member documents are permanently and immediately deleted (they do not go through the 30-day trash above), to respect the erasure right of a person no longer connected to the organization.

Organization snapshots and disaster recovery

Independent of the trash above, Quorify automatically creates, once a week, a snapshot of each active organization's data, kept for 30 days. An authorized Quorify Super Admin may use such a snapshot to restore an organization to a prior state, solely in serious-incident cases (e.g. accidental bulk deletion, technical error), at the Organization's request or with its knowledge wherever possible. An additional safety snapshot of the current state is automatically created before any restore.

Retaining these snapshots for a limited period rests on the Organization's and Quorify's legitimate interest in being able to recover data lost by error and, where relevant, on the need to be able to establish or defend a legal claim (Art. 17(3)(e) GDPR). Snapshots are not used for any other purpose and are not accessible to an organization's own administrators.

Formular 230 data (including CNP) is automatically deleted by a recurring process after the 5 fiscal years + 1 year archiving period; the records and associated PDF documents are permanently removed. See the 230 DPA.

On account deletion or subscription termination, associated data is deleted per the DPA, except where retention is legally required (e.g. fiscal records) or for the safety snapshots mentioned above, which expire no later than 30 days after their last creation. Requests: contact@usequorify.com.