How does data deletion work at the end of a contract?
At the end of a contract or upon customer request (nDSG Art. 6), a documented 8-step deletion process is carried out:
Client is deactivated in the application
Deletion request is logged
S3 data is completely deleted (all versions)
Database entries are hard deleted (no soft delete)
Search indexes are cleaned up
Client-specific encryption key (CMK) is scheduled for deletion (7-day window)
Compliance service validates proper decommissioning of the CMK
Deletion is confirmed to the customer
Residual data: RDS snapshots expire after 30 days. CloudWatch logs after 365 days. S3 non-current versions after 5 days. Subprocessors: Azure OpenAI and Google Document AI do not retain any data.
The process is auditable and confirmed with documentation.
Deletion confirmation: After the deletion process is complete, customers receive a formal deletion confirmation (Certificate of Destruction) documenting all affected storage layers and timestamps.
Data return: Before deletion, customers can request a complete export of their data. The export format and timeline are agreed upon during contract negotiation. amaise actively supports customers in transitioning to a successor system.