Attendae
← Legal center πŸ‡²πŸ‡½ ES

Legal center β†’ Data Retention & Deletion

Data Retention & Deletion Policy

How long we keep different categories of data and how to request deletion

Contents

  1. Retention principles
  2. Retention periods by data category
  3. Account cancellation
  4. ARCO Cancellation requests
  5. Anonymization vs. deletion
  6. Backups
  7. Contact

1 Retention principles

Attendae retains personal data only for as long as necessary to fulfil the purpose for which it was collected, to comply with legal obligations, or to resolve disputes. Our retention practices are guided by:

  • Purpose limitation: Data is not kept once the purpose for which it was collected no longer applies
  • Legal compliance: Mexican tax, accounting, and data protection law impose minimum and maximum retention obligations
  • Data minimization: At the end of the retention period, data is deleted or anonymized β€” not simply archived indefinitely
  • Controller responsibility: For participant data processed on behalf of institutions (as Processor), the institution as Data Controller determines retention within the bounds of applicable law

2 Retention periods by data category

Data category Retention period Legal basis Action at end of period
Administrator account data
(name, email, institution, password hash)
Duration of active account + 12 months after cancellation Contractual necessity; LFPDPPP Deletion
Participant data
(name, email, ID, group)
Duration of institution's active account + 12 months Institution's instruction as Controller Deletion or anonymization at institution's discretion
Attendance records
(check-in timestamp, method, session)
Duration of institution's active account + 12 months Contractual necessity; legitimate interest (audit) Anonymization (attendance counts retained for statistics)
Geolocation data
(coordinates captured at check-in)
6 months from check-in date Legitimate interest (fraud audit); LFPDPPP minimization Deletion
Issued certificates
(folio, name on certificate, verification code)
5 years from issue date (or lifetime of institution account if longer) Legitimate interest (verification); contractual Anonymization of name; folio and verification code retained for historical integrity
Payment records
(amount, date, Stripe payment ID, invoice)
10 years Mexican Fiscal Code (CFF) Art. 30 β€” accounting records Secure archival then deletion
Access audit logs
(login events, admin actions)
2 years Legitimate interest (security); LFPDPPP Deletion
Support tickets
(email thread, issue description)
3 years from ticket closure Legitimate interest (service quality, dispute resolution) Deletion

3 Account cancellation

When an institutional administrator closes their Attendae account, the following process applies:

  • 1
    Cancellation request received β€” the administrator submits a cancellation request via the dashboard or by emailing soporte@attendae.com.
  • 2
    Grace period (30 days) β€” the account is deactivated but data is retained for 30 days to allow for accidental cancellations or data export requests. The account can be reactivated during this period.
  • 3
    Data export β€” during the grace period, the institution may export participant lists, attendance reports, and certificate records in standard formats (XLSX, CSV, PDF).
  • 4
    Deletion initiated β€” after the grace period, account data, participant records, and attendance data are deleted. Payment records and issued certificate verification data are retained per the table above.
  • 5
    Confirmation β€” Attendae sends a written confirmation that deletion has been completed, within 20 business days of the grace period ending.

4 ARCO Cancellation requests

An individual may request deletion of their personal data at any time by exercising the Cancellation right under the LFPDPPP. See ARCO Rights for the full process.

Cancellation requests may be limited or deferred in the following circumstances:

  • A contractual relationship is still active (e.g., an ongoing event subscription)
  • Applicable law requires the data to be retained for a minimum period (see table above)
  • The data is necessary to resolve a pending dispute or legal claim
  • Issued certificates cannot have beneficiary names deleted without invalidating the certificate's authenticity β€” in this case, the certificate may be cancelled (status set to ANULADA) instead

When cancellation cannot be completed immediately, data is placed in a blocking period during which it is not actively processed until it can be deleted. We will inform you of the applicable timeline.

For participant data processed on behalf of an institution, cancellation requests should be directed to the institution as Data Controller in the first instance. Attendae will assist the institution in fulfilling the request within the required timeframes.

5 Anonymization vs. deletion

Deletion

The data is permanently removed from all active systems. Deletion is applied to data that is no longer needed for any purpose and where no legal obligation to retain applies.

Anonymization

Identifying fields (name, email, ID number) are replaced with non-reversible tokens or removed, while aggregate records are retained. Used for statistical purposes where the individual record is no longer needed but aggregate data has legitimate value.

Anonymized data is no longer personal data under the LFPDPPP and is therefore not subject to data subject rights after anonymization is complete. Anonymization is always irreversible β€” Attendae does not maintain a mapping that would allow re-identification.

6 Backups

Attendae maintains automated backups of its database for disaster recovery purposes. Backup retention is aligned with the retention periods in this policy β€” backups are not used as a mechanism to retain data beyond its applicable retention period.

When data is deleted from active systems, it will also be purged from backups within the next backup cycle (typically within 30 days). During this interval, the data exists only in backup storage and is not actively accessible or processed.

7 Contact

For account cancellation: soporte@attendae.com
For ARCO Cancellation requests: privacidad@attendae.com
Subject line: Data Deletion Request β€” [your name or institution name]

This policy was last updated in 2025 and applies to all data processed by Attendae on attendae.com and attendae.app.

Legal center Terms of Service Privacy Policy Privacy Notice Participant Privacy ARCO Rights Acceptable Use Refund Policy SLA DPA Minor Protection Security Policy Cookie Policy Sub-processors Home Contact πŸ‡²πŸ‡½ VersiΓ³n en espaΓ±ol

© 2026 Attendae. All rights reserved.