Legal
Version 1.0Effective 2026-09-01

Data Retention Schedule

Periods run from the trigger in the third column.

Customer and order data

DataKept forFrom
Orders, order items, payments5 years — accounting and tax recordsorder date
Delivery details — name, phone, address5 years, as part of the order recorddelivery
Reservations and waitlist entries12 monthsbooking date
WhatsApp one-time codesminutes — expire on useissue

Employee data

DataKept forFrom
Payroll — payslips, deductions, bonuses, advances5 yearspayroll period
Employment record — profile, contract dates, identification5 yearsend of employment
Attendance GPS coordinates90 days, then permanently erasedpunch
Attendance times, lateness, overtime5 years, as payroll evidencepunch
Leave requests and balances5 yearsrequest
Documents uploaded by the employer5 yearsend of employment

On attendance coordinates. The time of a clock-in has to be kept as long as payroll, because it is the evidence for what someone was paid. The coordinates do not: once a punch is settled, the latitude and longitude have served their only purpose. After 90 days they are erased automatically. What remains is the punch time, the method, and the geofence result — the distance in metres between the employee and the branch — which records that the punch was valid without recording where the employee was.

Account and technical data

DataKept forFrom
User accountslife of the accountdeletion request
Error and diagnostic reports30 days, deleted automaticallyevent
Database backupsrolling cycle — 4 full and 7 differential backupsbackup

Backups are an honest exception. Data deleted from the live system persists in backups until those backups age out on the normal cycle. We do not surgically edit backups: doing so would destroy their integrity as recovery points, which is the entire reason they exist. Deleted data therefore disappears from backups within the backup cycle and is never restored to live systems except as part of a whole-system recovery.

Requests

See Delete your account. Where a record must be kept for a statutory period, we keep it for that period and no longer.

Contact: privacy@madar-pos.cloud