Data retention and deletion

What Depozza keeps, for how long, and how you exercise your access, portability and erasure rights.

All compliance documents
Version
1.0 · Effective 2026-08-11
Owner
privacy@depozza.eu
Review cycle
Annual
Mapped controls
GDPR art. 5(1)(e), 15, 17, 20 · ISO 27001 A.5.33–A.5.34

Retention periods

  • Account and profile data: kept while the account is open, then deleted on request or when the account is closed.
  • Bookings, invoices and payout records: kept for the statutory accounting period required by French law (10 years), because we cannot lawfully delete them earlier.
  • Identity-verification data: kept only as long as needed to evidence the check, then minimised to the verification result.
  • Messages and dispute evidence: kept while the related booking or dispute can still be contested, then deleted.
  • Security and audit logs: kept for up to 12 months for investigation purposes.

Your rights, in the product

Signed-in users can export a machine-readable copy of their data and request account deletion directly from Settings — no email ticket is required. Deletion removes profile, listing and message content; records we must keep for tax or legal-defence reasons are retained in a restricted form and are no longer used for any other purpose.

Data minimisation

  • Exact addresses are only revealed to a counterparty once a booking is confirmed; search shows an approximate area.
  • We do not sell personal data and do not use it for third-party advertising.
  • We do not collect health data, and no special-category data is required to use Depozza.

Making a request

Any access, rectification, portability, restriction or erasure request can be sent to privacy@depozza.eu. We answer within one month, as required by the GDPR, and may ask you to confirm your identity before acting.

Questions about this document

privacy@depozza.eu

This document states Depozza SAS's own policy. It is not a certification, an audit report or a legal guarantee.