How does data deletion work at the end of a contract?
At the end of a contract or upon customer request (nDSG Art. 6), a documented 8-step deletion process is carried out:
Client is deactivated in the application
Deletion request is logged
S3 data is completely deleted (all versions)
Database entries are hard deleted — during the contract they carry a deletion marker; at contract end the records themselves are removed
Search indexes are cleaned up
Client-specific encryption key (CMK) is scheduled for deletion (window defined by AWS KMS guidance)
Compliance service validates proper decommissioning of the CMK
Deletion is confirmed to the customer
Residual data: RDS snapshots expire after 30 days. CloudWatch logs after 365 days. S3 non-current versions after 5 days. Search-index snapshots, which the cloud provider manages, expire after 14 days. Subprocessors: the OCR services (Google Document AI, Azure AI Document Intelligence) do not retain any data; under Microsoft's terms, Azure OpenAI may retain prompt and completion content for up to 30 days for abuse monitoring — never for training or model improvement.
The process is auditable and confirmed with documentation.
Deletion confirmation: After the deletion process is complete, customers receive a formal deletion confirmation (Certificate of Destruction) documenting all affected storage layers and timestamps.
Data return: Before deletion, customers can request a complete export of their data. The export format and timeline are agreed upon during contract negotiation. amaise actively supports customers in transitioning to a successor system.
