Data Retention & Deletion
Last updated: 2 September 2026
1. General principle
Amrachi aims to keep personal data only for as long as reasonably necessary for the relevant purpose, taking into account customer instructions, contractual requirements, security needs, applicable limitation periods and legal or record-keeping obligations. Amrachi does not apply one universal retention period to every data category.
2. Individual user accounts
Deleting or disabling an individual user account is not the same as deleting the customer organisation’s records. Account credentials and personal account information that are no longer required are deleted, deactivated or otherwise handled under the applicable account-deletion process.
Historical supervision evidence relating to actions previously performed by that user may remain associated with the customer organisation where preservation remains appropriate for audit, governance or record-keeping. Where appropriate, identifying information may be reduced or dissociated without destroying the underlying historical evidence.
3. Customer Data during the service term
During an active customer relationship, Customer Data is retained as necessary to provide the agreed Service and according to customer instructions, contractual terms and configured retention controls where applicable. Customers may use available export functionality for Customer Data and supervision evidence.
4. Termination or expiry
Following termination or expiry, the customer may request an export of Customer Data and available supervision evidence through available Service functionality or another reasonable secure delivery method. The applicable Order Form may specify an exit period.
After the applicable exit process, Amrachi may delete Customer Data from active systems in accordance with the DPA and applicable procedures, except where retention is required by law or agreed with the customer. Amrachi does not publicly promise a fixed post-termination portal-access period unless expressly stated in the customer contract.
5. Backups and technical copies
Data deleted from active systems may remain temporarily in protected backups, logs or technical copies until deleted or overwritten under the applicable system or provider lifecycle. Backups are not intended as an active source for ordinary customer access after deletion.
6. Logs, diagnostics and transactional email
Security, authentication, operational and diagnostic data may be retained for periods appropriate to security, troubleshooting, abuse prevention and reliability. Periods may depend on provider and configuration. Amrachi avoids publishing fixed vendor-log periods unless verified and operationally applicable.
Transactional email and delivery metadata may be processed for service delivery, security, troubleshooting and delivery-status purposes under the applicable operational and provider lifecycle.
7. Website analytics
Optional GA4 data is processed only after Analytics consent. Analytics retention is separate from core Customer Data and is not used as authenticated portfolio-supervision evidence.
8. Customer record-keeping
A customer may have legal, regulatory, audit or internal-governance obligations requiring preservation of records. Amrachi does not determine those obligations for the customer. Where Amrachi acts as processor, the customer is responsible for determining retention requirements applicable to its Customer Personal Data and supervision evidence.
9. Requests and changes
For Amrachi-controller data, requests may be sent to privacy@amrachi.ch. For Customer Personal Data, requests should normally be directed to the relevant customer/controller. Amrachi may update this page as operational controls evolve; applicable contractual commitments prevail in case of conflict.