GDPR customer-data retention/deletion policy for bookings #30

Open
opened 2026-07-23 14:09:45 +02:00 by mivanchenko · 0 comments
Owner

Parked from booking-module spec #14 (Out of Scope). The booking module stores end-customer PII (name, email/phone) without the customer ever creating an account or agreeing to terms directly through us. Needs a business/legal decision on retention period and who's the data controller vs. processor (the operator vs. each client business) before any auto-purge/anonymization is built. Deliberately not improvised into the schema during the booking-module build — flagged here so it isn't forgotten.

Parked from booking-module spec #14 (Out of Scope). The booking module stores end-customer PII (name, email/phone) without the customer ever creating an account or agreeing to terms directly through us. Needs a business/legal decision on retention period and who's the data controller vs. processor (the operator vs. each client business) before any auto-purge/anonymization is built. Deliberately not improvised into the schema during the booking-module build — flagged here so it isn't forgotten.
mivanchenko added the needs-triagebooking labels 2026-07-23 14:09:45 +02:00
Sign in to join this conversation.