Legal
Privacy policy
How personal data is processed when you use the service, according to Art. 13 and 14 GDPR.
Last updated: 10 October 2026
This translation is provided for information only. Only the German version is legally binding. Read the German original
1. Controller
The controller within the meaning of the GDPR and the Austrian Data Protection Act (Datenschutzgesetz, DSG) is:
FluxonLab (sole proprietorship, Einzelunternehmen), owner: Çağrı Bozgeyik
Arndtstraße 68, Tür 3, 1120 Wien, Austria
E-mail for data protection requests: contact@fluxonlab.com
2. Purposes of processing and legal bases
a) Providing the software platform (Art. 6(1)(b) GDPR): Processing of master data (name, business e-mail, company, VAT ID) for registration, authentication and providing the functions of Saldek. Without name, e-mail address, password and organisation we cannot create an account; the other details are voluntary. At registration we also store when you confirmed acting as a business and which version of the terms you accepted.
b) Automated document extraction (Art. 6(1)(b) GDPR and Art. 28 GDPR): Processing of the data contained in uploaded invoices, receipts and bank statements (for example issuer, recipient, addresses, bank details/IBAN, tax amounts, line items). Where personal data of third parties on documents is processed, FluxonLab acts as a processor within the meaning of Art. 28 GDPR.
c) Our own retention obligations (Art. 6(1)(c) GDPR in conjunction with § 132 of the Austrian Federal Fiscal Code, BAO): FluxonLab keeps the invoices and accounting records of your subscription for seven years. Documents and entries you record in Saldek are kept by Saldek on your behalf as processor (letter b and section 3); your business is the controller for these data.
d) Billing and payment processing (Art. 6(1)(b) and (c) GDPR in conjunction with § 132 BAO): Processing of name, billing address, VAT ID and subscription data to bill subscriptions through Stripe, and retention of the invoices. Payment data such as card details is collected by Stripe directly; Saldek does not store it.
e) Error monitoring (Art. 6(1)(f) GDPR): If an error occurs in the web app, the interfaces or document processing, a technical error report is sent to the Sentry service: type of error, affected program location, page address without parameters, browser and operating system version and a random event ID. Our legitimate interest is the secure and error-free operation of Saldek. Document data, form and request contents, cookies and user identifiers are not transmitted; e-mail addresses, IBANs and VAT IDs are masked before sending. The browser's IP address is technically transmitted but not stored by Sentry. Error reports are deleted after 90 days at the latest.
f) Service e-mails and contact requests (Art. 6(1)(b) and (f) GDPR): Processing of the e-mail address and the message content in order to send the service's e-mails (confirmation of the e-mail address, password reset, notice of a password change, invitations, confirmation codes to sender addresses of the e-mail document intake, confirmation that an organisation has been closed or deleted) and to handle requests you send to hello@saldek.eu or support@saldek.eu. These requests are forwarded to the contact address of FluxonLab.
g) Sending invoices by e-mail (Art. 28 GDPR): Users can send invoices they create in Saldek to their customers by e-mail from Saldek. For this, the following are processed: the recipient address and, where applicable, a further address in copy (CC) that the user enters, the content of the e-mail including a message from the user if they write one, the invoice as a PDF attachment, and the name and e-mail address of the organisation; this address is set as the reply-to address, so that recipients' replies go directly to the organisation. The e-mails are sent from the address no-reply@saldek.eu via Resend (section 4). The user can instead choose to send through the organisation's own mail server (SMTP; Saldek stores the password encrypted) or through a connected Gmail or Outlook mailbox (letter i); the e-mail is then sent from that address and not via Resend. For this data, FluxonLab acts as the user's processor within the meaning of Art. 28 GDPR; the user is the controller for sending them.
h) Document intake from Google Drive, by e-mail, WhatsApp and Gmail (Art. 6(1)(b) GDPR): Members of an organisation can import files from Google Drive and forward invoices to their organisation's own intake address; the data processed for this is described in section 4 under "Google Drive" and "E-mail document intake". Once the other connections are switched on (not yet in operation), they will also be able to send documents to Saldek via WhatsApp and hand over attachments from Gmail to Saldek through a Gmail add-on; the data processed for this is described in section 4 under "Planned connections". Documents received this way are then processed like uploaded documents (letter b).
i) Connecting a Gmail or Outlook mailbox (Art. 6(1)(b) GDPR): A member can connect a Google account (Gmail) or a Microsoft account (Outlook) to Saldek when they explicitly ask for it. There are two separate permissions, each optional. Sending: Saldek sends an invoice through the mailbox only when a user sends it with this delivery method; the e-mail goes out from the mailbox address, and Saldek processes the recipient address and, where applicable, an address in copy, the message text and the invoice as a PDF attachment. This permission does not allow Saldek to read the mailbox. Reading (import): Only if the member grants this second permission, switches the import on and chooses the date from which to search does Saldek search the mailbox in that period for invoices and receipts, and afterwards new e-mails on an ongoing basis (at regular intervals and on request, "Check new mail now"). The search follows fixed rules on Saldek's servers; no AI is used for it, and the search uses no credits. For this, Saldek reads the header data (such as sender, subject and time received), the text and the attachment names of the e-mails in the chosen period (not sent items, drafts, deleted items or spam). The e-mail text is read only to assess it and is not stored, unless the member imports the e-mail as a document. For hits ("candidates"), Saldek stores the sender's display name and domain, the subject, the name, type and size of the attachments, the assessment with its reasons, the message identifier and the time received (for Outlook also the web link to the message), but not the sender's address and not the text. Undecided candidates lose these details after 30 days and are deleted a further 30 days later; decided candidates are deleted 30 days after the decision; on disconnecting, all of them are deleted at once. The member chooses what is imported; Saldek then imports certain invoices in new e-mails automatically. What is imported is an attachment (PDF, image or XML invoice) or, for an e-mail without an attachment (such as an online purchase receipt), the e-mail itself: Saldek creates a readable PDF version of it and keeps the original e-mail as an e-mail file together with the document for the statutory retention period (section 3). The documents imported are processed like uploaded documents (letter b), in "Standard" mode also by the AI services described in section 4. Saldek stores the mailbox credentials (access and refresh tokens) encrypted. The member can switch the import off at any time and disconnect in the settings or revoke access in the Google or Microsoft account; on disconnecting, Saldek deletes the stored credentials. Documents already taken over remain documents of the organisation (section 3).
j) Voice notes and voice input (Art. 6(1)(b) GDPR): Users can use a microphone in "Ask Saldek" and, once the WhatsApp connection is in operation, send voice messages by WhatsApp, together with a document or on their own. The recording is processed to turn it into text. In "Ask Saldek" the text is inserted into the question box; the user checks and sends it themselves. For a WhatsApp voice message, the text is stored as a note on the document and serves the AI as an additional hint for the booking proposal when it is there before the document has been read; a voice message on its own is stored as an open voice note ("receipt to follow") until a document arrives or a member dismisses it. The text is a hint, not an instruction: Saldek never posts on its own, and spoken instructions are not carried out. Saldek does not store the recording itself, not even for WhatsApp voice messages: it is only processed for the conversion and discarded afterwards. Only the text is stored; as a note on a document, it is deleted with the document (section 3).
k) Questions to "Ask Saldek" (Art. 6(1)(b) GDPR; for data of your business partners Art. 28 GDPR): "Ask Saldek" is an AI assistant. When you ask a question there, in the "Standard" mode Saldek sends the question, the earlier questions of the same conversation and matching extracts from your documents and entries to the AI services under section 4 (TypeSafe to select matching sources, OpenAI for the answer) to produce an answer with sources; in the extracts, IBANs, e-mail addresses and phone numbers are masked first. The answer is an automatically generated proposal: it is not posted and triggers no action. Conversations are stored in your organisation so that you can open them again, and are deleted with the organisation; you can ask for individual conversations to be deleted at any time by e-mail to contact@fluxonlab.com. In the "Without AI" mode no data is sent to AI services.
l) Account security (Art. 6(1)(f) GDPR): On sign-ins and security-relevant changes, Saldek stores the IP address, browser identifier (user agent), the time, the country derived from it and whether a second factor was used, to detect misuse and protect your account; active sessions are shown to you in the settings. Our legitimate interest is the security of the accounts and the platform. These logs are deleted automatically after 90 days; ended sessions 90 days after they end. Entries in an organisation's change log are kept but lose the IP address and browser identifier after 90 days.
m) Contact form and support requests (Art. 6(1)(b) and (f) GDPR): When you write to us through the contact form on our website or through "Help & support" in Saldek, we process your name, your e-mail address, on the contact form the company name if you give it, the topic you chose and your message. From within Saldek we also send what you are shown before sending: your organisation, the page that was open (without search terms or parameters), the app version and the browser (name and operating system, without version numbers), plus a screenshot if you attach one. With a partner application on our partner page we also process the name of your firm, your profession, its country, roughly how many clients you look after and, if you give it, its website, to check the application. We use this information only to answer your request. The legal basis is Art. 6(1)(b) GDPR where the request concerns your contract with us or entering into one, otherwise our legitimate interest in answering requests (point (f)). The information is voluntary; without an e-mail address and a message we cannot answer. The request is stored in the Saldek database (section 4). A notification with your message goes by e-mail to the support inbox of FluxonLab, and you receive a confirmation of receipt; both e-mails are sent through Resend (section 4). Within FluxonLab, only the people who handle requests receive them. To prevent misuse we count the messages sent per IP address or signed-in session; this counter expires after at most one hour and is not stored with the request. A request is deleted automatically three years after it was dealt with.
n) Cookieless audience measurement (Art. 6(1)(f) GDPR): To see where prospective customers leave the path from our website to a paid plan, we count on our own server how often pages of our website are loaded. For each page load we determine only the page area (e.g. "Pricing"), the language of the page and a coarse origin category (e.g. "search engine", "social network", "direct") and add them up to daily totals. The IP address, the browser identifier and the address of the referring page are neither stored nor passed on for this purpose; no cookies are set, nothing is stored on or read from your device and no usage profiles are created. If your browser sends "Do Not Track" or "Global Privacy Control", your page load is not counted. Likewise, from Saldek's own records we count how many accounts were created, e-mail addresses confirmed, set-ups completed, first documents submitted, first bookings approved and subscriptions started or ended on a day — again only as daily totals by language and plan. No third party is involved. The daily totals do not allow conclusions about individuals and are kept without a time limit. Our legitimate interest is to make the website and the sign-up easy to understand and use.
3. Statutory retention obligation (§ 132 BAO, § 147 AO)
Under § 132 BAO, books, records and the documents belonging to them must be kept for seven years. The period starts at the end of the calendar year for which the entries were made or to which the documents relate; for a financial year that differs from the calendar year, at the end of the calendar year in which the financial year ends. In Germany, § 147(3) of the Fiscal Code (AO) requires accounting vouchers to be kept for eight years and books, records and annual financial statements for ten years. The retention obligation lies with your business; Saldek supports you in meeting it. Uploaded documents that are not yet the basis of a posted entry can be deleted together with their file at any time. An archived e-mail through which documents were received also contains their files; it is deleted as soon as none of these documents exists any more. As soon as a document is the basis of a posted entry, it is locked against any change in WORM storage (Write Once, Read Many, with SHA-256 checksums) for seven years (Austria and other countries) or eight years (Germany) from the end of the calendar year; a reversal entry does not lift this lock. While an organisation uses Saldek, posted documents and finalised journal lines therefore cannot be deleted individually within this period, because the retention obligation takes precedence over erasure under Art. 17(3)(b) GDPR.
Ending the use. The owner of an organisation can choose between two ways in the settings:
a) Close the organisation: The organisation becomes read-only. Its members can still sign in, view and export all data; nothing new is recorded. The subscription ends when the paid period expires. After the end of the retention period under § 132 BAO, all data of the organisation is deleted automatically. For organisations outside Austria, for which Saldek does not calculate this period, the data remains stored until the owner deletes the organisation.
b) Delete the organisation immediately: At the express request of the owner, after the notice that the statutory retention obligation remains with the business, all data of the organisation — entries, invoices, documents, contacts, settings and memberships — is deleted immediately; the subscription ends immediately. Locked files in the archive (posted documents and the original e-mails through which they were received) cannot be deleted by anyone before the lock ends, including FluxonLab: they remain in the locked archive, are no longer assigned to any organisation, can no longer be retrieved through Saldek, and are deleted automatically when the lock ends. All other files are deleted immediately. Deleted data remains in the encrypted backups until they expire after 30 days.
4. Data location and hosting
The application and its databases run on servers of Hetzner Online GmbH in Germany; customer data and accounting data are stored there. Documents and document files are stored in the audit-proof archive of Amazon Web Services EMEA SARL in the Frankfurt am Main region (Germany), and the encrypted backups of the databases in a separate storage of Amazon Web Services EMEA SARL in the European Union.
In the "Standard" mode (the default), Saldek uses AI services as sub-processors: OpenAI Ireland Ltd (model "gpt-6-luna"; processing by affiliates of OpenAI in the USA) to read documents, for assessments from the first page of a document (such as the document type, a "paid" mark or, for sole traders and freelancers, whether a purchase is for the business) and to answer questions in "Ask Saldek" (section 2 k); TypeSafe AI, Inc. (model "Jev"; processing in the USA) for assessments of the documents read (such as the document type, the invoice recipient and the link to earlier documents), for booking proposals, to match imported bank transactions to documents and to check for duplicates, and to select matching sources for "Ask Saldek"; and, if OpenAI does not read a document or reads it with nothing usable, Google Cloud EMEA Limited (model "gemini-3.5-flash-lite"; processing in the USA and other countries in which Google operates data centres). To read a document, the image of each of its pages and its text are transmitted (for XML e-invoices and CSV files only the text). For the assessments, OpenAI receives the image of the first page and, for sole traders and freelancers, also the beginning of the document text. TypeSafe receives details and text extracts of the document read as well as booking details and imported bank transactions (business partner, payment reference, reference, amount); in booking details and bank transactions, IBANs, e-mail addresses and phone numbers are masked before transmission.
The AI services keep the transmitted data only for a limited time: OpenAI for up to 30 days to detect abuse, unless a longer retention is required by law or necessary to protect against harm; Google for a limited time to detect violations of its usage policies. TypeSafe does not keep the transmitted data: zero data retention is agreed for Saldek, so the data is processed only to answer the request in question. The transfer to TypeSafe is based on the EU standard contractual clauses (Art. 46(2)(c) GDPR) in its data processing agreement. OpenAI's contracting party is OpenAI Ireland Ltd in Ireland; it transfers the data to OpenAI's affiliates in the USA on the basis of agreements containing the EU standard contractual clauses (Art. 46(2)(c) GDPR; OpenAI's Data Processing Addendum, section 4.1). The transfer to Google is based on the EU-US Data Privacy Framework (Art. 45 GDPR), otherwise also on the EU standard contractual clauses. In the "Without AI" mode, which can be selected in the organisation's settings, no data is transmitted to AI services; documents are then not read automatically.
For voice notes and voice input (section 2 j), Saldek uses two speech-to-text services in "Standard" mode: Microsoft Ireland Operations Limited (Azure Speech, model "MAI-Transcribe-2"; processing in the Azure region North Europe in Ireland) and, if that service does not respond, does not respond in time or cannot process the recording, OpenAI Ireland Ltd (model "gpt-transcribe"; processing by affiliates of OpenAI in the USA). Only the recording is transmitted to Microsoft. OpenAI receives the recording and, as a recognition aid, a fixed accounting vocabulary and the names of up to 30 of the organisation's suppliers. The text comes back in both cases. Saldek does not store the recording after the conversion; the providers keep it only as long as their contract terms provide for operation and the detection of abuse (OpenAI up to 30 days). The transfer to OpenAI is as described for "gpt-6-luna" (EU standard contractual clauses between OpenAI Ireland Ltd and its affiliates in the USA, Art. 46(2)(c) GDPR); an exceptional transfer to a third country by Microsoft is based on the EU standard contractual clauses in Microsoft's Products and Services Data Protection Addendum. In the "Without AI" mode, voice input is not available, because nothing is transmitted to these services.
Error reports (section 2 e) are processed by Functional Software, Inc. (Sentry, USA) in its EU data region in Frankfurt am Main (Germany); administrative data and access by Sentry are also possible from the USA. The transfer is based on the EU-US Data Privacy Framework (Art. 45 GDPR), otherwise on the EU standard contractual clauses in Sentry's Data Processing Addendum.
Payments for subscriptions are processed by Stripe Payments Europe, Ltd. (Ireland); data may be transferred to Stripe, Inc. in the USA (EU-US Data Privacy Framework, otherwise EU standard contractual clauses).
The service's e-mails are sent by Plus Five Five, Inc. (Resend, USA) from the address no-reply@saldek.eu, including the invoices users send from Saldek to their customers (section 2 g); Resend also receives the contact addresses hello@saldek.eu and support@saldek.eu, whose messages are forwarded to the contact address of FluxonLab. The Ireland region from which the e-mails are sent only determines the sending route: according to Resend, all data is stored in the USA, including message contents and attachments, metadata, logs and account data (e-mail contents, metadata and logs for 30 days). The transfer is based on the EU standard contractual clauses (Art. 46(2)(c) GDPR) in Resend's Data Processing Addendum; according to Resend, it also participates in the EU-US Data Privacy Framework. Resend lists its sub-processors at resend.com/legal/subprocessors.
E-mail document intake: Every organisation receives its own intake address under the domain in.saldek.eu. E-mails to this address are received by Mailgun Technologies, Inc. (Mailgun, a Sinch group company, USA) in its EU region (data centres in Germany and Belgium) and forwarded to Saldek. The sender, recipient, subject, text and attachments of the e-mail and the result of the sender check (SPF, DKIM, DMARC) are processed. Saldek only takes attachments from e-mails sent from addresses that a member of the organisation has confirmed with a confirmation code (section 2 f); other e-mails are not taken over as documents. The e-mail is archived with its attachments (section 3). According to Mailgun, it keeps the content of e-mails for up to seven days and event logs for as long as the chosen plan provides (one day on our current plan); access for support and operations is also possible from the USA. Mailgun processes the e-mails as a processor under Sinch's Data Processing Agreement; where this is necessary to operate its e-mail service – for example to prevent spam and fraud, for the security and maintenance of its network and to meet legal obligations – Mailgun also uses them as an independent controller. The transfer is based on the EU-US Data Privacy Framework (Art. 45 GDPR), otherwise on the EU standard contractual clauses (Art. 46(2)(c) GDPR) in Sinch's Data Processing Agreement.
Gmail and Outlook (mailbox connection, section 2 i): When connecting, Saldek receives from Google or Microsoft the e-mail address and an identifier of the account as well as the credentials needed for the chosen permission. To send, Saldek calls the Gmail API (scope "gmail.send") or Microsoft Graph (scope "Mail.Send"); to import, the Gmail API (scope "gmail.readonly") or Microsoft Graph (scope "Mail.Read"). Google LLC (USA) acts as an independent controller under the Google APIs Terms of Service; the transfer relies on the EU-US Data Privacy Framework (Art. 45 GDPR), otherwise on the EU standard contractual clauses in the Google Controller-Controller Data Protection Terms. Your agreements with Microsoft apply to the data in your Microsoft account; Saldek accesses it only with the permission you have granted. Connected mailboxes are your own accounts: Saldek reads or sends only what you trigger through the functions of Saldek or have switched on.
Google user data (Limited Use): Saldek's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Saldek uses Gmail data only to provide the user-facing features (sending invoices, searching the chosen period for invoices and receipts and importing them as documents). Saldek does not transfer it to third parties except as necessary for these features (the processors named in section 4, for example for storage and AI document reading), to comply with law, or as part of a merger, acquisition or sale of the business. Saldek does not use it for advertising or to train general AI or machine-learning models. Humans read it only with your explicit consent, where necessary to investigate abuse or for security, or to comply with law.
Google Drive: A member can connect their Google account to Saldek to select and import files from Google Drive. Saldek receives the e-mail address and an identifier of the Google account, the selected files and an access permission limited to these files, which Saldek stores encrypted until the connection is removed. Google LLC (USA) acts as an independent controller under the Google APIs Terms of Service; the transfer is based on the EU-US Data Privacy Framework (Art. 45 GDPR), otherwise on the EU standard contractual clauses in the Google Controller-Controller Data Protection Terms. The data in your Google account is governed by your agreements with Google. Saldek's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The connection can be removed in the settings or revoked in the Google account at any time.
Planned connections. The following connections are planned but not yet in operation. Data is transmitted through them only once Saldek switches the respective function on and a member sets it up for their organisation; customers are informed before they go into operation.
WhatsApp: Saldek receives documents through its own WhatsApp number, which belongs to the WhatsApp Business account of FluxonLab and is operated through the WhatsApp Business Platform (Cloud API) of Meta Platforms Ireland Limited, Dublin (Ireland). A member links their phone number once with a code from the settings; after that, photos and PDF files they send to this number become documents of their organisation. The sender's phone number and WhatsApp ID, the messages and files sent and the replies from Saldek (for example the confirmation of the link or of receipt) are processed. Saldek stores the phone number only encrypted and as a check value. Meta processes this data as a processor in data centres in Ireland, Denmark, Sweden and the USA, keeps messages for at most 30 days according to its own statements and also uses the data as an independent controller to ensure the security and integrity of the service. For transfers to affiliates such as Meta Platforms, Inc. in the USA, Meta relies under its contract terms on the transfer mechanisms provided for by the GDPR; according to its own statements, Meta Platforms, Inc. participates in the EU-US Data Privacy Framework. The use of WhatsApp itself is governed by WhatsApp's terms and privacy policy. Voice messages that a member sends to this number are also converted to text as described in section 2 j.
Gmail add-on: In the Gmail add-on, a member who has connected their Google account to Saldek can send attachments of the currently open e-mail to Saldek. The permission applies only to the open e-mail and the respective request; from Gmail, Saldek only stores the attachments that are sent to Saldek. The add-on shows the name of the organisation, the status of the link and the file names of the attachments in Gmail; Saldek transmits this information to Google for that purpose. What is said above under "Google Drive" applies to Google LLC.
All service providers in use and planned are listed in the list of sub-processors. Where a transfer is based on standard contractual clauses, they are part of the providers' contracts linked there; for OpenAI, OpenAI Ireland Ltd has agreed them with its affiliates in the USA. You can obtain a copy of the clauses in our contracts on request at contact@fluxonlab.com.
5. No AI model training with customer data
Saldek uses optical character recognition (OCR) and structured extraction models. Invoices, company data and financial amounts are not used to train public or cross-company AI foundation models. TypeSafe, OpenAI, Google and Microsoft also do not use the data transmitted to them to train their models under their contract terms (TypeSafe Master Customer Agreement, section 4.1; OpenAI Services Agreement, section 4.2; Gemini API Additional Terms of Service for paid services; Microsoft Products and Services Data Protection Addendum). This also applies to voice recordings.
6. Your rights and the Austrian Data Protection Authority
You have the right at any time to access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR) and objection (Art. 21 GDPR). An e-mail to contact@fluxonlab.com is sufficient to exercise them.
Right to object (Art. 21 GDPR): Where we process data on the basis of legitimate interests (section 2 e, f, l and n), you can object at any time on grounds relating to your particular situation.
Competent supervisory authority for complaints:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde, DSB)
Barichgasse 40-42, 1030 Vienna, Austria
Phone: +43 1 52 152-0 · E-mail: dsb@dsb.gv.at · Web: www.dsb.gv.at
You can also lodge a complaint with the supervisory authority of the member state of your habitual residence or place of work (Art. 77 GDPR), for example in Germany with the data protection authority of your federal state.
7. No automated decision-making (Art. 22 GDPR)
Saldek makes no decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. AI services only create proposals (document data, account assignment, tax code, answers in "Ask Saldek"); nothing is posted until an authorised person approves it, and nothing is posted or sent to authorities automatically. No profiling takes place.
8. Storage periods
- Account and organisation data: until the account or the organisation is deleted.
- Documents and entries: see section 3.
- Conversations in "Ask Saldek": until the organisation is deleted (section 2 k).
- Invoices and payment data of your subscription with FluxonLab: seven years (§ 132 BAO).
- Contact requests, contact-form messages and support requests from Saldek: until they are dealt with, then three years (section 2 m).
- Sign-in and security logs: 90 days (section 2 l).
- Error reports: at most 90 days (section 2 e).
- Daily totals of the audience measurement: without a time limit; they contain no personal data (section 2 n).
- Encrypted backups: 30 days.