Aufbewahrungsfristen für Daten

    Vorläufige Fassung in rechtlicher Prüfung

    Version 0.9.0

    Dieses Dokument ist noch nicht ins Deutsche übersetzt. Es wird auf Englisch angezeigt; bis zur Veröffentlichung der Übersetzung ist der englische Text maßgeblich.

    Table of contents

    1. Scope and principles
    2. Retention table
    3. Details for each category
    4. How we delete
    5. Backups
    6. Legal holds
    7. Anonymization and aggregated data
    8. Data held by providers and on your device
    9. Customer Data and Customer instructions
    10. Review of this Schedule

    1. Scope and principles

    This Schedule applies to personal data handled by L. M. PEREZ MONTANA ("SonhoLab", "we", "us"):

    • as controller, under our Privacy Policy (02-privacy-policy.md); and
    • as processor, for Customer Data, where the Customer has not given a different instruction under the Data Processing Addendum (DPA) (03-data-processing-addendum.md).

    Terms such as "System", "Customer", "Customer Data" and "Organization Account" have the meanings given in the Privacy Policy.

    We follow these principles:

    • Storage limitation. We keep personal data in identifiable form no longer than necessary (LGPD arts. 6 III and 15-16; GDPR art. 5(1)(e); CCPA §1798.100(a)(3)).
    • End of processing. When the purpose is met, the relationship ends, consent is withdrawn or an authority orders it, we delete the data, unless a legal reason to keep it applies (LGPD arts. 15-16).
    • Keep only what the reason requires. When we must keep data for a legal reason, we keep only the data that reason covers, restrict access to it and use it only for that reason.
    • Customer control. For Customer Data, the Customer's instructions come first.

    2. Retention table

    DataRetention
    Account & organization datalife of account + 30 days after cancellation, then deleted
    Free plan inactivepurged after 90 days of inactivity, with 2 prior notices
    Customer Data after terminationexport available 30 days, then deleted; backups roll off within 30 days
    Access/application logs6 months (Marco Civil art. 15), up to 12 months for security investigations
    Billing, invoices, tax5 years (Brazil tax law) or longer if required
    Consent and legal-acceptance records5 years after the relationship ends
    Privacy requests & responses24 months
    Incident register5 years
    Marketing leads / waitlistuntil unsubscribe or 24 months without interaction
    Support tickets24 months after closure
    Hades voice profiles & recordingsuntil the voice owner or account holder revokes, or account deletion + 30 days; biometric data never kept > 3 years after last use
    Hades conversation historyuntil user deletes or account deletion + 30 days
    Clinic records (controller = clinic)as instructed by the clinic; the clinic is responsible for legal minimums (e.g., Brazil 20 years, Lei 13.787/2018)
    Student data (controller = school)as instructed by the school; deleted within 60 days after contract end unless the school requests export
    CobraDia debtor IDs & locationsas instructed by the lender; default deletion 90 days after the debt is settled
    WhatsApp agent conversations12 months rolling unless the business sets shorter

    The retention periods above are the ones that apply. Section 3 explains each row: when the period starts, our legal basis for keeping the data, and how we delete it.

    3. Details for each category

    3.1 Account & organization data

    • Retention: life of account + 30 days after cancellation, then deleted.
    • Includes: Organization Account details, each User's name, email, phone, role, password hash, sign-up and last-access dates, plan and System selections.
    • Starts: the day the account is cancelled, by the Customer or by us under the Terms of Service (01-terms-of-service.md).
    • Legal basis for keeping it: performance of the contract while the account exists (LGPD art. 7 V; GDPR art. 6(1)(b)). The 30 days after cancellation let the Customer export data or change its mind; our basis is legitimate interest (LGPD art. 7 IX; GDPR art. 6(1)(f)).
    • Deletion: removed from the active database and control panel; then rolls off backups (section 5).
    • Kept longer only for: billing records (section 3.5) and acceptance records (section 3.6), which have their own periods.

    3.2 Free plan inactive

    • Retention: purged after 90 days of inactivity, with 2 prior notices.
    • Inactivity means that no User of the Organization has signed in to any of its Systems.
    • Notices: we send 2 notices to the account owner's email before the purge: 30 days and 7 days before the purge date. Logging in before the purge date keeps the account.
    • Legal basis: storage limitation and data minimization (LGPD art. 6 III; GDPR art. 5(1)(c) and (e)).
    • Deletion: the Organization Account and its Customer Data are deleted from active systems; then roll off backups.

    3.3 Customer Data after termination

    • Retention: export available 30 days, then deleted; backups roll off within 30 days.
    • Starts: the day the subscription or contract ends.
    • Export: the Customer can export its data during the 30 days. Export is also available on every plan throughout the contract.
    • Legal basis: the Customer's instructions and the end-of-service duty to return or delete (LGPD arts. 16 and 39; GDPR art. 28(3)(g)).
    • Deletion: removed from the active database and file storage of every System the organization used; then rolls off backups within 30 days.
    • Exceptions: a different period set by a product rule below (sections 3.13-3.16), a written instruction from the Customer, or a legal hold (section 6).

    3.4 Access/application logs

    • Retention: 6 months (Marco Civil art. 15), up to 12 months for security investigations.
    • Includes: IP address, date and time with time zone, and the resource accessed, for our websites, apps and Systems.
    • Legal basis: legal obligation to keep application access logs for 6 months, confidentially and in a controlled environment (Marco Civil da Internet, Lei 12.965/2014, art. 15; Decreto 8.771/2016; LGPD art. 7 II). For EEA/UK users, legitimate interest in security (GDPR art. 6(1)(f)). Extension to 12 months: legitimate interest in investigating a specific security event, and the exercise of rights in proceedings (LGPD art. 7 VI and IX).
    • Deletion: logs are rotated and deleted automatically at the end of the period. Logs kept for an investigation are listed in the investigation file and deleted when it closes, no later than 12 months.
    • Authority requests: a police authority, administrative authority or the Public Prosecutor may ask us to keep specific logs for longer (Marco Civil art. 15 §2). We treat that as a legal hold (section 6).

    3.5 Billing, invoices, tax

    • Retention: 5 years (Brazil tax law) or longer if required.
    • Includes: invoices, payment records, tax identifiers, billing contacts and refund records. We do not hold full card numbers; Stripe does.
    • Starts: from the first day of the fiscal year after the one in which the record was created, as Brazilian tax law counts it.
    • Legal basis: legal obligation under Brazilian tax and accounting law (LGPD art. 7 II). For EEA/UK users, legitimate interest in complying with that law (GDPR art. 6(1)(f)).
    • Longer if required: for example, while a tax audit, tax dispute or chargeback is open.
    • Deletion: removed from our billing records at the end of the period. Stripe keeps its own records as required by its legal duties.
    • Retention: 5 years after the relationship ends.
    • Includes: acceptance of the Terms of Service, Privacy Policy, DPA and product addenda (document, version, digital fingerprint, date, time, account and IP address); marketing consents and withdrawals; cookie choices; Hades voice-owner consents and heir declarations.
    • Legal basis: we must be able to prove consent and acceptance (LGPD art. 8 §2; GDPR arts. 5(2) and 7(1)); the 5-year period matches the limitation period for consumer claims in Brazil (Código de Defesa do Consumidor art. 27); exercise of rights in proceedings (LGPD art. 7 VI).
    • Relationship ends: when the account is deleted or, for a person with no account, when the consent is withdrawn or expires.
    • Deletion: deleted at the end of the period. A Hades voice consent record is kept after the voice itself is deleted, only as proof of consent and revocation.

    3.7 Privacy requests & responses

    • Retention: 24 months.
    • Starts: when the request is closed.
    • Legal basis: accountability (LGPD art. 6 X; GDPR art. 5(2)) and the handling of any complaint or appeal.
    • Deletion: the request file is deleted at the end of the period. Identity documents sent for verification are deleted as soon as the request is closed, as stated in Your Privacy Rights and How to Exercise Them (09-data-rights-requests.md).

    3.8 Incident register

    • Retention: 5 years.
    • Includes: every security incident involving personal data, whether or not it was notified: facts, effects, data and people affected, measures taken and notices sent.
    • Legal basis: legal obligation (Resolução CD/ANPD nº 15/2024; GDPR art. 33(5)).
    • Deletion: deleted at the end of the period. Personal data in the register is limited to what is needed to document the incident.

    3.9 Marketing leads / waitlist

    • Retention: until unsubscribe or 24 months without interaction.
    • Interaction means clicking a link in one of our messages, replying, logging in, or asking us something.
    • Legal basis: consent (LGPD art. 7 I; GDPR art. 6(1)(a)) or legitimate interest for existing business customers (LGPD art. 7 IX; GDPR art. 6(1)(f)).
    • After you unsubscribe: we delete your lead record, but keep a minimal entry (your email or phone) on a suppression list so that we do not contact you again.
    • Deletion: removed from our marketing lists and contact records.

    3.10 Support tickets

    • Retention: 24 months after closure.
    • Includes: ticket text, comments, attachments and screenshots, and the requester's contact details.
    • Legal basis: performance of the contract and legitimate interest in handling repeat issues and claims (LGPD art. 7 V and IX; GDPR art. 6(1)(b) and (f)).
    • Deletion: the ticket and its attachments are deleted from the support desk. Customer Data that appears in a screenshot follows the same period.

    3.11 Hades voice profiles & recordings

    • Retention: until the voice owner or account holder revokes, or account deletion + 30 days; biometric data never kept > 3 years after last use.
    • Includes: uploaded voice samples, voice models and embeddings, and generated audio stored by us.
    • Revocation: the voice owner or the account holder may revoke a voice at any time. When the voice owner revokes it, the voice is removed for everyone (the account holder who created it and all other users, including through the shared library) and deleted from all our systems automatically. For a deceased person, a person with standing may also ask for removal; we act on takedown notices within 48 hours.
    • "Last use" means the last time the voice was used to generate audio.
    • Legal basis: explicit, separate consent of the voice owner (LGPD art. 11 I; GDPR art. 9(2)(a)). The 3-year limit follows the Illinois Biometric Information Privacy Act (740 ILCS 14/15(a)) and applies to all users.
    • Deletion: samples, models, embeddings and stored outputs are deleted from our servers and from the equipment SonhoLab operates in Brazil for Hades; then roll off backups. The Hades Addendum: Voice, Biometrics, Memorials and Companion AI (P-voice-biometric-deceased.md) sets the details.

    3.12 Hades conversation history

    • Retention: until user deletes or account deletion + 30 days.
    • Legal basis: performance of the contract (LGPD art. 7 V; GDPR art. 6(1)(b)).
    • Deletion: the user can delete conversations in the app. On account deletion, remaining history is deleted after 30 days; then rolls off backups.

    3.13 Clinic records (controller = clinic)

    • Retention: as instructed by the clinic; the clinic is responsible for legal minimums (e.g., Brazil 20 years, Lei 13.787/2018).
    • Our role: processor. We keep and delete records only on the clinic's instructions. Brazilian law requires patient records to be kept for at least 20 years from the last entry (Lei 13.787/2018 art. 6); other countries set their own periods. The clinic must export and keep its copy before its contract ends.
    • Deletion: on the clinic's instruction or at the end of the export period in section 3.3; then rolls off backups. The Health Data Addendum (P-health.md) has the details.

    3.14 Student data (controller = school)

    • Retention: as instructed by the school; deleted within 60 days after contract end unless the school requests export.
    • Our role: processor. During the contract, the school decides what to keep and delete.
    • After the contract: we delete student data within 60 days after the contract ends. If the school asks for an export, we provide it before deletion.
    • Deletion: removed from the Verita web and app databases and file storage; then rolls off backups. The Children and Student Data Addendum (Verita) (P-children-education.md) has the details, including US student-data rules.

    3.15 CobraDia debtor IDs & locations

    • Retention: as instructed by the lender; default deletion 90 days after the debt is settled.
    • Includes: debtor identity-document numbers and images, addresses, and map locations.
    • Our role: processor. The lender is the controller.
    • Deletion: removed from the active database and file storage; then rolls off backups. The Debt Collection Addendum (P-debt-collection.md) has the details.

    3.16 WhatsApp agent conversations

    • Retention: 12 months rolling unless the business sets shorter.
    • Rolling means each message is deleted 12 months after it was sent or received.
    • Our role: processor for the businesses that use Jesse, Digital Team OS and other AI agents; controller for our own WhatsApp sales and support assistant.
    • Deletion: messages, transcribed voice notes and processed images older than the period are deleted automatically; then roll off backups. The AI Agents and Messaging Addendum (P-ai-agents-messaging.md) has the details.

    Some data types have periods stated in other documents:

    DataPeriodSource
    Files uploaded to a free web tool for processingDeleted within 1 hour after processingPrivacy Policy, section 3.2.10
    Website analytics (with consent)Google Analytics 4 event data: 2 months; cookie lifetimes in the Cookie Policy (05-cookie-policy.md)Cookie Policy
    Website chat transcripts that do not become a ticket or lead12 monthsPrivacy Policy, section 3.2.3
    Public procurement contact data (Bidstream)24 months after the notice closesPrivacy Policy, section 3.2.12
    Job Portal candidate profiles and ApplicationsProfiles: deleted after 24 months without activity, after a prior notice. Applications: 24 months after the job closesRecruiting and Job Portal Addendum (P-recruiting.md), section 11
    Content notices, counter-notices, decisions and complaints3 years, to apply the repeat-infringer policy and defend claimsCopyright and Content Removal Policy (11-copyright-dmca.md), section 16
    Identity documents sent to verify a privacy requestDeleted when the request is closedYour Privacy Rights and How to Exercise Them (09-data-rights-requests.md)

    4. How we delete

    Where the data isMethod
    Active databasesRecords are permanently deleted (not only hidden) by a scheduled deletion process or on request
    File and object storageFiles are permanently deleted
    LogsRotated and deleted automatically at the end of the period
    Email mailboxes on our mail serverMessages are deleted with the related record or at the end of the period
    BackupsNot edited one by one. Deleted data disappears as each backup expires (section 5)
    Equipment SonhoLab operates in Brazil for HadesFiles and models are permanently deleted
    Your deviceData stored by our apps is removed when you delete it in the app or uninstall the app

    Hardware disposal at our hosting provider is handled by Hetzner under its contractual security obligations.

    We run deletion within a reasonable time after each period ends.

    5. Backups

    • What: we back up our databases and files so we can recover from failures or incidents.
    • Where: Hetzner's automated server backups in Finland (EU), and an off-site copy on equipment operated by SonhoLab in Brazil. Brazil and the EU recognize each other as adequate.
    • Protection: off-site backups are encrypted before they leave the server.
    • How long: database backups are kept up to 14 days on the server side and up to 14 days off-site.
    • Deleted data: data deleted from active systems stays in backups until they expire, and then disappears. The longest period is 30 days.
    • No other use: while data remains in a backup after deletion, we do not access or use it except to restore our systems after a failure or incident.
    • Restores: if we must restore a backup, we re-apply deletions made since that backup before the restored data goes back into use.

    A legal hold pauses deletion of specific data.

    When we apply one:

    • a court order, a subpoena or a request from a competent authority, including a request to keep logs longer under Marco Civil art. 15 §2;
    • a lawsuit, claim, regulatory inquiry or investigation that is pending or reasonably expected;
    • the investigation of a security incident;
    • a Customer's written instruction, for Customer Data.

    How we apply it:

    • the hold covers only the data needed for that matter;
    • access to the held data is restricted;
    • we record why the hold was set, who approved it, what data it covers and when it will be reviewed;
    • for Customer Data, we inform the Customer, unless the law forbids it;
    • we review each hold at least every 6 months, and release it when the matter ends.

    After a hold is released, normal retention applies. If the normal period has already passed, we delete the data promptly.

    Government and Law Enforcement Requests (12-law-enforcement.md) explains how we review authority requests.

    7. Anonymization and aggregated data

    • Anonymized data is data that can no longer identify a person by reasonable means (LGPD arts. 5 III and 12; GDPR Recital 26). It is no longer personal data, so this Schedule does not limit how long we keep it.
    • What we keep: aggregated statistics, such as the number of active accounts per product, System usage totals, support volumes, and anonymous usage counts of our free tools.
    • How: we remove identifiers and combine data so that no person can be singled out. We do not try to re-identify anonymized data.
    • Pseudonymized data is still personal data. Data where identifiers are replaced by codes, but which could be linked back, follows the normal periods.
    • Customer Data: we do not anonymize Customer Data for our own use unless the Customer instructs us or the DPA allows it.

    8. Data held by providers and on your device

    • Subprocessors keep data only as needed to provide their service to us, under our contracts. When we delete data, copies at our subprocessors are deleted under their own processes and time frames. AI providers keep the data we send them only as their API terms allow. Subprocessors and International Transfers (04-subprocessors.md) lists them.
    • Independent controllers, such as Stripe for its own legal duties, app stores or Roblox, keep data under their own policies.
    • Your device: data our apps store on your device stays there until you delete it or uninstall the app.

    9. Customer Data and Customer instructions

    For Customer Data:

    • the Customer decides how long data is kept during the contract, and can delete data in the System at any time;
    • the defaults in this Schedule apply only where the Customer has not given another instruction;
    • the Customer is responsible for meeting any minimum retention its own law sets (for example, patient records, school records or tax records). We give Customers export tools so they can keep their own copies;
    • when the contract ends, section 3.3 applies, unless a product rule (sections 3.13-3.16) sets a different period;
    • deletion requests from people whose data is Customer Data are handled through the Customer, as set out in Your Privacy Rights and How to Exercise Them (09-data-rights-requests.md).

    10. Review of this Schedule

    Our Encarregado (data protection officer), reachable at contacto@sonholab.com, owns this Schedule. We review it at least once a year and whenever we add a product, a data category or a provider, or when the law changes. Each change creates a new version.


    Version 0.9.0 (preliminary) · Effective 26 September 2026 · © L. M. PEREZ MONTANA (SonhoLab), CNPJ 61.620.014/0001-00. This version is under legal review; we will notify material changes as described in these documents.

    Vorläufige Fassung in rechtlicher Prüfung

    Version 0.9.0

    SHA-256-Fingerabdruck dieses Textes: 579b6237ace5d9205bbb46ea38933b3c12161dc36cf3f90510f286462ea5b9ce

    Zurück zum Rechtszentrum