FlowDule
Trust Center

How long do we keep data?

There is no single lawful retention period for all FlowDule customers. Here you will find who sets the period for each data type, what the system supports, and what applies to the data where the law decides the length.

How long do we keep data? (AI-genereret billede)AI-genereret indhold

Specific deadlines, not vague intentions

Some retention periods follow your own documented profile, which you choose according to country, professional group, authorisation, treatment, data category and purpose. Others are set by legislation and by how long the customer relationship lasts. This page draws a clear line between the two, so you know what rests on your assessment and what follows from an obligation.

Journal data follows its own rules, because a statutory record-keeping period can limit the right to erasure. We describe those in detail on a separate page.

Retention schedule

Deadlines and who sets them

Data types where deletion or anonymisation happens once the period expires. A legal hold can block the deletion temporarily, and information may sit in rolling backups until the copies are overwritten under the documented rotation

Journal data (AI-genereret billede)Your documented profileAI-genereret indhold

Journal data

There is no single lawful retention period for all FlowDule customers. You choose a documented profile according to country, professional group, authorisation, treatment, data category and purpose. For authorised healthcare professionals in the 10-year group, the starting point is at least 10 years from the most recent record, and at least 5 years for other authorised professionals. A self-employed psychotherapist without a relevant authorisation has no automatic 5- or 10-year period and sets a necessary and proportionate period themselves. FlowDule does not set your professional or legal retention obligation.

AI processing data (AI-genereret billede)By activated configurationAI-genereret indhold

AI processing data

Input and output from the AI features follow the use case, model, supplier, region and retention activated in Customer Annex A to the Data Processing Agreement. FlowDule must be able to document supplier terms, data flow, retention and deletion before an AI feature is activated in production, and your client and journal data must not be used to train general models.

Journal access log (AI-genereret billede)By the control purposeAI-genereret indhold

Journal access log

The log of who has viewed a journal has a documented retention period and is deleted automatically once the control and security purpose has been met. A specific case can be placed under legal hold. The log is what allows us to tell a data subject who has had access.

Usage data (AI-genereret billede)By the billing purposeAI-genereret indhold

Usage data

Metering data for SMS and AI usage is used for billing and to show current usage within the subscription. Where data forms part of accounting records, it is kept for 5 years from the end of the financial year; other metering data is deleted once the purpose and any limitation period have expired.

Technical error logs (AI-genereret billede)Normally 12 monthsAI-genereret indhold

Technical error logs

Security and operational logs are normally kept for 12 months. They are used to find and fix faults in the platform and to protect individuals, customers and the service. Significant incident files are normally kept for 5 years after closure.

Unconfirmed image uploads (AI-genereret billede)Short automatic expiryAI-genereret indhold

Unconfirmed image uploads

An image that is uploaded but never put to use is a temporary processing file with a short automatic expiry and secure deletion. That way no loose files sit around without a purpose.

Erasure requests

Each data category is assessed - required records are restricted

You are the controller and decide the request; FlowDule provides export, restriction and deletion functions and acts on your documented instructions. Data without a continuing lawful basis is deleted according to its lifecycle. A legally required record is restricted instead: ordinary broad access, secondary purposes and unnecessary sharing stop, while documented persons may still use the material for necessary lawful purposes. Every access is logged, and content is removed once the period and any legal hold expire. After that, the information may be technically inaccessible in rolling backups until the copies are overwritten under the documented rotation.

See journal data retention
Erasure request and pseudonymisation (AI-genereret billede)AI-genereret indhold
Operational data such as bookings and invoices (AI-genereret billede)AI-genereret indhold
Other operational data

Bookings, invoices, message history and audit trails

Bookings, message history and audit trails are your data and follow your documented retention profile and the Data Processing Agreement. FlowDule's own contract and billing data is kept for as long as the customer relationship lasts, and after that in accordance with applicable law - accounting records for 5 years from the end of the financial year. FlowDule's bookkeeping obligation is not a basis for retaining your client or journal data. We do not promise a fixed automatic deletion here, because the right period depends on what the individual data documents.

Questions?

Missing a period that is not listed here?

Write to us if you need documentation for a specific data type or a clarification for your own record of processing activities.