Friendly Automate processes different types of data. Some of this data is the responsibility of Friendly (“we”), while other data is the responsibility of Friendly’s customers (“you”). The following sections explain these roles and how the respective obligations are fulfilled.
In accordance with the GDPR and the Swiss FADP, we follow these principles whenever we process data:
We only retain data where there is a clear purpose for doing so. We define this purpose for each data category (see table below), document it and review it regularly. Once the purpose no longer applies, we delete the data.
We only collect and retain data that we genuinely need to operate our services, provide support or meet legal requirements. Features are designed to avoid generating unnecessary data.
We retain data where this is necessary to fulfil our contractual obligations, handle support requests, ensure technical quality or comply with legal requirements. Retention periods are defined for each data category and supported by a clear rationale (see table below).
Once the defined retention period has expired, data is deleted automatically. This applies both to production systems and to actively used archive areas.
We maintain a central overview of all retention periods. We can explain at any time why specific data is retained, for how long, and how it is deleted.
Deletion processes are automated and tested regularly. Access to systems is protected, and relevant activities are logged. Internal responsibilities for data retention and deletion are clearly defined.