Files
HexaHost-GameCloud/docs/security/data-retention.md

67 lines
2.6 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Data retention
Retention periods and deletion procedures for HexaHost GameCloud customer and operational data.
## Policy summary
| Data type | Retention | Deletion trigger |
|-----------|-----------|------------------|
| Account profile | Life of account + 90 days | Account deletion request |
| Game server world (live) | Life of service | Terminate in WHMCS / admin |
| Automated backups | Per plan (730 days default) | Lifecycle job + S3 expiry |
| Manual backup downloads | Link valid 24 h; object 7 days | Worker cleanup |
| Audit log | 24 months | Scheduled purge job |
| Application logs (Loki) | 30 days (`720h` in loki-config) | Loki compactor |
| Session tokens | 7 days idle / 30 days max | Redis TTL |
| WHMCS sync events | 90 days acknowledged | Addon retention SQL |
| DNS record history | 12 months | DB maintenance |
| Metering / usage samples | 13 months (billing) | Aggregated then purged |
Adjust periods in contracts and WHMCS product terms. Document customer-facing retention in your privacy policy (German: *Datenschutzerklärung*).
## Backup retention
Backup objects live under `s3://{bucket}/backups/{serverId}/`. The worker applies plan-based retention:
- Free/starter plans: 7 daily slots
- Pro plans: 14 daily + 4 weekly
- Enterprise: configurable via admin
Expired backups are deleted from object storage; metadata rows in PostgreSQL are soft-deleted then purged after 7 days.
## Termination flow
When WHMCS calls `TerminateAccount`:
1. Server stopped on node
2. Final backup optional (plan-dependent)
3. World data on node deleted within 24 h
4. S3 prefix `backups/{serverId}/` deleted within 7 days
5. PostgreSQL server row anonymised or hard-deleted per legal requirement
## GDPR / DSGVO considerations
- **Right to erasure:** Export then delete user row; cascade removes owned servers
- **Data portability:** World export ZIP + backup download via panel
- **Processor agreement:** Required between you (controller) and HexaHost GameCloud operator if different entity
Logs may contain IP addresses and user IDs — treat as personal data where applicable.
## Operational data
| Store | Purge method |
|-------|--------------|
| PostgreSQL audit | `DELETE FROM audit_events WHERE created_at < NOW() - INTERVAL '24 months'` (automated job) |
| Redis | TTL-based; no long-term PII |
| MinIO access logs | Provider lifecycle rule |
## Legal hold
Suspend automated deletion for accounts under litigation hold. Flag in admin metadata; worker skips purge for affected `serverId`.
## Related
- [Backup and restore](../operations/backup-restore.md)
- [Object storage](../operations/object-storage.md)
- [Threat model](threat-model.md) — T16 backup integrity