FlowDule
Trust Center

How we store and delete journal data

There is no single lawful retention period that fits everyone. The treatment site selects and documents its profile by country, professional group, authorisation, data category and purpose. Here you can read how FlowDule stores, restricts and deletes journal data - in language anyone can read.

How we store and delete journal data (AI-genereret billede)AI-genereret indhold

Kept as long as the treatment site's documented profile requires

A journal may not always be deleted just because someone asks. If the treatment site is covered by the record-keeping duty, the journal must be preserved for a number of years. In return, it must not be kept longer than necessary: when the period has expired, the treatment site assesses whether another lawful basis still exists, and if there is none and no legal hold applies, the content is removed.

This page describes the principles for retention, erasure requests, legal holds and final deletion. It is an explanation practitioners can take as a starting point with their clients, but it does not replace the treatment site's own privacy information.

Principles

Four principles for journal data

Retention period, erasure requests, legal holds and final deletion

The treatment site selects and documents the period (AI-genereret billede)Retention periodAI-genereret indhold

The treatment site selects and documents the period

There is no single lawful period that fits everyone. How long a record must be kept depends on country, professional group, authorisation, data category and purpose, and the practice selects and documents the profile. FlowDule does not set the practice's professional or legal retention duty. For authorised healthcare professionals (Danish authorisation), the starting point under the journalføringsbekendtgørelsen, the Danish record-keeping order, is at least ten years from the latest entry for some professional groups and at least five years for others. A self-employed psychotherapist who is not an authorised healthcare professional has no automatic 5- or 10-year period and must set a necessary and proportionate period themselves.

Erasure requests get a two-part answer (AI-genereret billede)ErasureAI-genereret indhold

Erasure requests get a two-part answer

Data without a continuing basis is deleted under its lifecycle. A required record is restricted: ordinary broad access, analytics, product improvement and unnecessary sharing stop. Documented persons may still use it for necessary treatment/patient safety, rights requests or a concrete complaint, supervisory or liability case, and every access is logged.

Legal holds during pending cases (AI-genereret billede)Legal holdAI-genereret indhold

Legal holds during pending cases

If a record is part of a complaint, supervisory or liability case, the necessary documented scope is preserved until closure. The person is informed only where lawful and where notice does not prejudice the case or an authority order; the decision is reviewed with every hold review.

Deletion when the period expires (AI-genereret billede)ExpiryAI-genereret indhold

Deletion when the period expires

Once the period has expired and the treatment site has assessed that there is neither another lawful basis nor a legal hold, the content is removed: notes, measurements, treatment plans, reports, attached documents and audio recordings. Deletion also covers files, shares, search indexes, queues and caches, while backups age out through documented rotation. What remains is a skeleton of timestamps, author and codes with no personal content.

Rights

Corrections are made as additions - and reads are logged

If something in a journal is wrong, it is corrected with a new addition stating what is right. In patient records under the authorisation rules the original text remains, because corrections and additions must be traceable so that the original version can still be identified. If the treatment site is not covered by those rules, the need for version history depends on the site's own documented purpose and responsibility. Data subjects can request access, rectification, restriction and erasure, but the rights are not absolute and may be limited by a statutory record-keeping period, a pending case, the rights of others or a necessary legal claim. You can be told who has viewed the journal - reads are recorded in an access log. Complaints can be made to the supervisory authority.

GDPR & Policies
Corrections and access log in the journal (AI-genereret billede)AI-genereret indhold
Roles and responsibility for journal data (AI-genereret billede)AI-genereret indhold
Responsibility

The practice is the data controller - FlowDule is the processor

The individual clinic or chain is the data controller for the journals and decides purpose, access and retention period. FlowDule delivers and operates the journal system as a data processor under a data processing agreement and only processes data on documented instruction. Journal data is encrypted and stored separately per chain.

Read about retention and rights
Questions?

Need documentation or answers?

Contact us if you need a data processing agreement, further documentation or answers to questions about retention and deletion.