| Temporary workflow files |
1 hour |
Uploads, in-session edits, previews and temporary exports become eligible for automatic deletion after this configured period. Cleanup runs every 30 minutes, so deletion is not guaranteed at an exact second. |
| Generated downloads |
1 hour |
Generated files held in temporary workflow state follow the same period. Download responses must be returned with no-store cache headers and a secure attachment disposition so customer-entered DPA details and workflow outputs are not cached by the application. |
| Operational metadata |
90 days |
Privacy-minimized usage, processing and audit metadata is removed automatically after this period, subject to specific security or legal needs. |
| Security and server logs |
Up to 7 days |
Host system logs are retained for up to 7 days. Docker container logs use size-based rotation (up to 5 log files of 10 MB per container) and older logs are automatically overwritten as new logs are generated. |
| Contact messages |
Not applicable |
Messages are delivered to the configured SMTP mailbox and are not stored in the UploadWerk application database. |
| Optional update email |
Until consent is withdrawn or the update list is discontinued |
Only the email address and consent status needed for optional updates are retained. |
| Database backups |
14 days |
The production backup job creates daily compressed PostgreSQL backups and removes backup files older than 14 days. |
| Administrator accounts |
While active and as long as reasonably necessary afterward |
Administrator identity, authentication and security records are retained to operate and protect the service. |