LegalΕλληνικά

Uploads and Retention Summary

Last updated: 7 September 2026

This summary explains how Service en Place handles uploaded documents and how long information is kept.

Different categories of information have provisional engineering retention targets and lifecycle rules. Some records are kept longer where required for security, billing, employment, audit, or legal reasons; actual enforcement varies by category and requires review.

Uploaded documents

Documents you upload (such as menus or invoices) may be processed to extract operating records. Uploaded-document records and local original bytes follow a retention lifecycle; copies held in external object storage are handled separately.

The current target for original-file retention is 90 days. When eligibility and hold checks permit, authorised retention or data-request actions can clear local database-held original bytes and linked legacy copies. A direct authorised upload-deletion action can mark an original held in external object storage as scheduled for deletion; the current retention batch neither marks nor deletes external objects. This is a lifecycle target, not an instant or guaranteed destructive action today.

Retention rules

Different categories of information are kept for different periods:

- Original uploaded files: short-term retention target (around 90 days), with local and external storage handled differently.

- Raw AI outputs: configured short-term retention target (around 30 days); execution is separately gated and not guaranteed automatic deletion.

- First-party acquisition and product analytics: 365 days is an unapproved engineering target, not an agreed retention period. A separately configured period can identify organisation records for review; this does not claim automatic deletion or removal of attribution fields.

- Security and audit records: no automated 90-day deletion claim; handling and retention require separate security, operational, and legal review.

- Billing and employment records: retained longer where legally required.

Deletion

Retention rules are engineering policy primitives and targets. The current destructive executor covers eligible local uploaded-original bytes and raw AI payload fields, runs dry-run by default, and does not claim automated deletion of audit/security records or external object-storage originals. Analytics and attribution can currently be identified for review only: this process does not delete, clear or anonymise them. It does not cover anonymous analytics records. Existing upload and AI-byte cleanup remains unchanged. Some fields may persist until separately reviewed or fully removed.

Some records may be retained where required for security, billing, employment, audit, or legal reasons.

Exports

Exports are bounded technical inventories generated from selected tenant-scoped categories and direct application links. They may omit raw files or sensitive fields, may not represent every source requiring review, and must be manually checked for coverage, third-party information, exemptions, and secure delivery.

Requesting access or deletion

You can request access or deletion through our data request process by contacting support@serviceenplace.com.

Final retention periods by record type: Legal review required before launch.