Data Retention & Deletion Policy
How long data is kept and how deletion works.
- Version
- 1.0
- Effective date
- 17 August 2026
- Last updated
- 17 August 2026
- Document owner
- the Groundmaster project, with responsibility assigned to its legal and compliance function
- Applicable jurisdiction
- Portugal, European Union
- Permanent URL
- https://www.groundmaster.pt/legal/retention
1.Principles
- data is retained only as long as necessary for the purposes for which it is processed;
- records with traceability, audit or statutory significance are preserved for the applicable period;
- corrections are made by amendment with an audit trail rather than by silent overwriting;
- deletion is applied consistently across primary storage and, on expiry, across backups.
2.Retention by category
| Category | Retention approach |
|---|---|
| Operational and technical records | Retained for the duration of the Subscription and any period the Customer or applicable law requires; not deleted automatically |
| Uploaded documents and certificates | Retained with the record they support, for the same period |
| Audit and activity logs | Retained for a defined security and accountability period appropriate to the record type |
| Account and profile data | Retained while the account exists; suspended accounts retain their historical contribution records |
| Authentication and session data | Retained only for the life of the session and a short security window thereafter |
| Support correspondence | Retained for a limited period after resolution |
| Billing and accounting records | Retained for statutory accounting and tax periods |
| AI interaction records | Retained for a limited period for traceability, troubleshooting and abuse prevention |
| Backups | Retained on a rolling cycle and overwritten or expired automatically |
3.Suspension instead of deletion of users
User accounts are suspended rather than deleted so that historical attribution of work, sign-offs and record changes remains intact and auditable. A suspended account cannot sign in or act, while its historical contributions stay visible to authorised personnel.
4.Deletion requests
Deletion requests from individuals are handled as described in the Privacy Policy and are normally routed to the Organisation acting as controller. Deletion may be refused or deferred where retention is required by law, needed for the establishment or defence of legal claims, or necessary to preserve aviation traceability or audit integrity; in such cases restriction of processing may be applied instead.
5.Termination and post-termination handling
After termination, access is disabled and a defined export window is provided so that the Customer can retrieve the records it must retain. After that window, workspace data is deleted or anonymised on our normal schedule, and backup copies expire on their rolling cycle. Records we must keep for statutory reasons are retained separately with restricted access.
6.Anonymisation
Where retention of information remains useful for reliability, capacity planning or aggregate statistics, data may be anonymised so that it no longer relates to an identifiable individual, and such data may be retained without the limits above.
Change history
| Version | Date | Change |
|---|---|---|
| 1.0 | 17 August 2026 | Initial retention and deletion policy. |
Questions about this document can be sent to groundmaster.web@gmail.com. Formal legal, privacy, security and regulatory requests should follow the routes described in the legal requests page. Fields shown as bracketed placeholders are pending confirmation by the operating legal entity and do not constitute a statement of fact.