Friendly Automate processes different types of data. Some of this data is the responsibility of Friendly (“we”), while other data is the responsibility of Friendly’s customers (“you”). The following sections explain these roles and how the respective obligations are fulfilled.

Legal basis

In accordance with the GDPR and the Swiss FADP, we follow these principles whenever we process data:

Purpose limitation

We only retain data where there is a clear purpose for doing so. We define this purpose for each data category (see table below), document it and review it regularly. Once the purpose no longer applies, we delete the data.

Data minimisation

We only collect and retain data that we genuinely need to operate our services, provide support or meet legal requirements. Features are designed to avoid generating unnecessary data.

Retention requirements

We retain data where this is necessary to fulfil our contractual obligations, handle support requests, ensure technical quality or comply with legal requirements. Retention periods are defined for each data category and supported by a clear rationale (see table below).

Deletion requirements

Once the defined retention period has expired, data is deleted automatically. This applies both to production systems and to actively used archive areas.

Accountability and documentation

We maintain a central overview of all retention periods. We can explain at any time why specific data is retained, for how long, and how it is deleted.

Technical and organisational measures

Deletion processes are automated and tested regularly. Access to systems is protected, and relevant activities are logged. Internal responsibilities for data retention and deletion are clearly defined.

Backups

Backups are used exclusively for recovery in the event of an emergency. They are not used for production purposes. Data is not selectively restored from backups and is automatically removed as part of the backup rotation.

Data categories under our responsibility

Friendly is responsible for retaining and deleting data that is generated technically through the operation of Friendly Automate. This primarily includes:

This data is used to ensure security, traceability and service stability, as well as to provide support where needed. We define and document the applicable retention periods and automatically delete the data once they expire. You can find the full retention periods in the following table:

Data category Retention period Purpose / rationale for retention
Email personalisation tokens 6 months Tokens are only used for the temporary display of personalised emails. After this period, there is no longer a business purpose for retaining them.
Contact activity log 24 months Tracking customer activity, reporting across multi-year campaign cycles and providing evidence for compliance purposes.
Campaign activity log 24 months Same rationale as for contact activity log: long-term campaign analysis and monitoring of campaign performance over time.
Website views and interactions (from known and anonymous contacts) 24 months Required for long-term web analytics, including seasonal trends, performance analysis and channel comparisons.
Audit log (system and contact changes) **12 months Standard
24 months Enterprise** Traceability of changes, troubleshooting and security audits. Enterprise customers have higher compliance requirements.
Unused IP addresses 12 months Technically required to prevent duplicates and misuse.
Anonymous contacts without activity 12 months Retained temporarily for conversion tracking and statistical purposes.

If you require different retention periods for your Friendly Automate instance and can provide a corresponding justification, please contact us so that we can discuss an individual solution.

We are also responsible for deleting your Friendly Automate instance, including all associated data, when your contract with us ends. The instance remains stored in our backups for a longer period and is subsequently deleted automatically as part of our backup rotation. You can find the relevant details and retention periods in our Terms and Conditions.