Version: 1.0 | Classification: Public | Effective Date: 01. 08. 2026. | Last Updated: 24. 07. 2026.
This Data Retention & Deletion Policy describes how Chronos Web Tech Kft. retains, archives, anonymizes, and securely deletes personal data processed through the Appointio platform. The purpose is to ensure that personal data is retained only for as long as necessary and deleted in accordance with applicable legal requirements, contractual obligations, and recognized security practices.
The Company follows the principles of data minimization, storage limitation, integrity and confidentiality, accountability, and lawful processing. Personal data shall never be retained longer than necessary unless required by applicable law.
The lifecycle of personal data generally consists of: Collection, Processing, Active Storage, Restricted Access, Archiving (where applicable), and Secure Deletion or Anonymization. Throughout its lifecycle, personal data is protected using appropriate technical and organizational measures.
Unless a longer period is required by law or contract, the Company generally applies the following retention periods:
| Data Category | Standard Retention |
|---|---|
| Contact enquiries | Up to 12 months after the last communication |
| Quotations | Up to 24 months |
| Customer account data | For the duration of the contractual relationship |
| Appointment records | According to the Controller's configuration or contractual agreement |
| Billing records | As required by applicable tax and accounting legislation |
| Security logs | Up to 12 months |
| Audit logs | Up to 24 months |
| Backup copies | According to the backup rotation schedule |
| Technical diagnostics | As necessary for troubleshooting and security purposes |
Retention periods may vary where legal obligations require longer storage.
When personal data is no longer required, the Company securely deletes or anonymizes the information using secure database deletion, cryptographic erasure where applicable, secure deletion of backup copies, and anonymization of analytical information.
Where processing is based on the Controller's instructions, the Controller may request deletion, export, correction, or restriction of processing. Requests shall be handled without undue delay and in accordance with applicable law.
Where Google OAuth or Google Calendar integration is used, access tokens are revoked when authorization is withdrawn, refresh tokens are securely deleted, and cached Google user data is deleted when no longer required. The Company does not use Google user data for advertising, profiling, or AI model training.
Backup copies are maintained to support disaster recovery and business continuity. Backups are encrypted, protected against unauthorized access, retained only for the defined duration, and automatically removed. Upon termination of the Services, personal data is handled according to contractual obligations. Certain information may continue to be retained where required by applicable accounting, taxation, or legal obligations.
Where necessary, the Company may temporarily suspend deletion of personal data if required by applicable law, a court order, for the establishment, exercise, or defence of legal claims, or during an ongoing regulatory investigation.
The Company is responsible for implementing appropriate procedures to ensure compliance. This Policy is reviewed periodically and updated where necessary to reflect legal developments, technological changes, security improvements, and operational requirements.
Questions regarding this Policy may be directed to: Chronos Web Tech Kft.
Email: [email protected] | Website: www.chronosweb.hu