Files
HexaHost-GameCloud/docs/security/data-retention.md

2.6 KiB
Raw Permalink Blame History

Data retention

Retention periods and deletion procedures for HexaHost GameCloud customer and operational data.

Policy summary

Data type Retention Deletion trigger
Account profile Life of account + 90 days Account deletion request
Game server world (live) Life of service Terminate in WHMCS / admin
Automated backups Per plan (730 days default) Lifecycle job + S3 expiry
Manual backup downloads Link valid 24 h; object 7 days Worker cleanup
Audit log 24 months Scheduled purge job
Application logs (Loki) 30 days (720h in loki-config) Loki compactor
Session tokens 7 days idle / 30 days max Redis TTL
WHMCS sync events 90 days acknowledged Addon retention SQL
DNS record history 12 months DB maintenance
Metering / usage samples 13 months (billing) Aggregated then purged

Adjust periods in contracts and WHMCS product terms. Document customer-facing retention in your privacy policy (German: Datenschutzerklärung).

Backup retention

Backup objects live under s3://{bucket}/backups/{serverId}/. The worker applies plan-based retention:

  • Free/starter plans: 7 daily slots
  • Pro plans: 14 daily + 4 weekly
  • Enterprise: configurable via admin

Expired backups are deleted from object storage; metadata rows in PostgreSQL are soft-deleted then purged after 7 days.

Termination flow

When WHMCS calls TerminateAccount:

  1. Server stopped on node
  2. Final backup optional (plan-dependent)
  3. World data on node deleted within 24 h
  4. S3 prefix backups/{serverId}/ deleted within 7 days
  5. PostgreSQL server row anonymised or hard-deleted per legal requirement

GDPR / DSGVO considerations

  • Right to erasure: Export then delete user row; cascade removes owned servers
  • Data portability: World export ZIP + backup download via panel
  • Processor agreement: Required between you (controller) and HexaHost GameCloud operator if different entity

Logs may contain IP addresses and user IDs — treat as personal data where applicable.

Operational data

Store Purge method
PostgreSQL audit DELETE FROM audit_events WHERE created_at < NOW() - INTERVAL '24 months' (automated job)
Redis TTL-based; no long-term PII
MinIO access logs Provider lifecycle rule

Suspend automated deletion for accounts under litigation hold. Flag in admin metadata; worker skips purge for affected serverId.