BilagPilot UK Data Retention Schedule

Version: 1.1 Last updated: 15 August 2026

Canonical URL: https://bilagpilot.com/retention

Related documents:

1. Purpose and scope

This Data Retention Schedule explains how Bjorvand Solutions retains and deletes personal data in connection with the United Kingdom version of BilagPilot.

It covers:

  1. Customer Personal Data, where a BilagPilot customer is the controller and Bjorvand Solutions acts as processor; and
  2. BilagPilot Controller Data, where Bjorvand Solutions determines the purposes of processing, including account administration, billing, support, security, abuse prevention, analytics and legal compliance.

This Schedule forms part of the Data Processing Agreement for Customer Personal Data. It should also be read with the Privacy Policy and Terms of Service.

BilagPilot is not an official accounting archive. Customers must export and retain accounting documents and other records for any period required by law, professional obligations or their own client engagements.

2. How to read this Schedule

This Schedule distinguishes between:

  • confirmed product behaviour, which describes what the audited application currently does;
  • fixed technical expiry, where the application has a confirmed expiry rule;
  • retention criteria, which describe why data remains necessary; and
  • operational targets, which describe the period Bjorvand Solutions normally aims to meet through technical or manual processes.

An operational target is not a guarantee that every copy will be removed automatically on an exact day. Where automatic deletion is not available, deletion is completed through a verified manual or operational process. Bjorvand Solutions must still avoid retaining identifiable personal data indefinitely or longer than reasonably necessary.

3. Current implementation position

The current technical position is:

  • Trial expiry changes the trial state, access rights, grants and inbound-upload permissions, but does not delete Customer Personal Data.
  • Deleting a request is primarily an archive operation. Public tokens are revoked and reminders are stopped, while history and uploaded files may remain.
  • Deleting a client marks the client inactive or soft-deleted and archives active requests, while related history and uploaded files remain available.
  • Account deletion sends a six-digit email verification code with a ten-minute validity period, registers a deletion request and creates an internal notification. It does not perform full deletion automatically. Ownership, authority, subscription status, export needs, accounting records and lawful retention may require manual review.
  • The repository audit found no evidence of a general automatic job that deletes or anonymises all Customer Personal Data within a fixed 90-day period.
  • A cleanup process for expired, unfinished upload reservations is not the same as deletion of completed Customer documents.
  • Provider contracts, exact backup periods, processing locations and transfer arrangements still require verification for some providers.
  • A partial English supplier page exists, but a complete international supplier and Subprocessor register is not yet available. The DPA, its schedules and direct written notices are the contractual baseline in the meantime.

The periods below are written to reflect this position rather than implying automatic deletion that the audited code does not currently perform.

4. General retention rules

  • Personal data is retained only for as long as reasonably necessary for the relevant purpose.
  • A shorter period applies where a valid deletion instruction, objection or legal requirement makes earlier deletion appropriate.
  • A longer period applies only where required or justified by law, a regulator, a court order, a documented legal hold, an active dispute, fraud or abuse investigation, security needs, accounting duties or another documented purpose.
  • Archived or soft-deleted data is not necessarily physically deleted.
  • Where a deletion request affects Customer Personal Data, Bjorvand Solutions verifies identity, authority, workspace ownership and scope before acting.
  • Where data is no longer needed in identifiable form, it is deleted or irreversibly anonymised through the available technical or operational process.
  • Data removed from active systems may remain in protected backups or provider systems until ordinary deletion or rotation completes. It is not intended for ordinary product use during that period.
  • Bjorvand Solutions may retain a minimal deletion record showing the category, time, basis and person or process responsible, without retaining the deleted content itself.

5. Customer Personal Data processed on behalf of the Customer

Data category or eventCurrent behaviourRetention rule or operational targetEnd action
Active workspace data, including client and contact records, periods, requests, responses, comments, statuses, reminders, message content, inbound email, files, receipt declarations, workflow history, integration data and BilagPilot-stored AI resultsAvailable while the service is active and the relevant workspace rights permit access.Retained while needed to provide, secure and support the service, and until a valid return, deletion or closure process is completed.Return through available export, secure deletion or irreversible anonymisation, subject to lawful exceptions.
Expired TrialThe workspace normally becomes read-only. Customer Personal Data remains. Existing Client links may continue receiving material already requested during the configured inbound period, currently up to seven days.Retained until the Customer upgrades, closes the workspace, gives a verified deletion instruction, or the data is otherwise no longer necessary. Trial expiry itself is not a deletion trigger.Return, deletion or anonymisation through the applicable operational process.
Subscription ended or workspace closedAccess may be restricted or read-only while export, ownership, billing, return and deletion issues are resolved.Bjorvand Solutions normally targets completion of active-system deletion within 90 days after closure is operationally confirmed and any necessary return or export step is resolved. This is a target, not an automatic or guaranteed deadline.Secure deletion or irreversible anonymisation from active systems, subject to legal holds and provider dependencies.
Verified Customer deletion instructionThe request is reviewed manually after identity, authority, workspace ownership and scope are verified.Bjorvand Solutions normally targets completion in active systems within 30 days after the instruction becomes verified and actionable. More time may be needed for complex scope, dependent records, legal holds, Subprocessors or provider cycles.Secure deletion or irreversible anonymisation, with a minimal compliance record where necessary.
Archived or deleted requestPublic tokens may be revoked and reminders stopped, but history and files may remain.Retained with the related workspace until a verified deletion instruction, workspace deletion or another lawful end-of-retention event.Deleted or anonymised through the workspace or instruction process.
Deleted or archived clientThe client is marked inactive or soft-deleted and active requests are archived. Related history and uploaded files remain available.Retained with the related workspace until a verified deletion instruction, workspace deletion or another lawful end-of-retention event.Deleted or anonymised through the workspace or instruction process.
Public upload links and token secretsLinks expire after the selected period, currently 7, 14, 30 or 60 days, with 14 days as the standard confirmed configuration. Links may be revoked earlier. Tokens are stored as hashes where implemented.Link access ends at expiry or revocation. Hashed token metadata and link history follow the related request or workspace. Raw links in email or SMS history follow the relevant message record.Access blocked; metadata later deleted or anonymised with the related records.
Integration access tokens, API keys and client keysCredentials are retained while the integration is connected and needed. Disconnection may disable or revoke access before stored secret material is removed.Deletion from active secret storage is normally targeted within 30 days after the credential is confirmed as no longer needed, where technically supported. Provider-side copies follow the provider's own process.Revoke, disable or delete the credential; retain only justified non-secret audit records.
Expired, abandoned or unfinalised upload reservationsA cleanup process exists for unfinished reservations. This does not delete completed Customer documents.Retained until reservation expiry and the configured cleanup process runs, or longer where needed to investigate abuse or a technical incident. No universal fixed deletion period is represented here.Release reservation and delete temporary data where supported.
Customer content sent to OpenAI through Smart Kontroll, where enabledSelected files and context may be sent when the feature is used.OpenAI API inputs and outputs may be retained for up to 30 days under standard abuse-monitoring controls, subject to the endpoint, account configuration, provider terms, legal requirements and any approved modified or zero-retention arrangement. BilagPilot-stored results follow the related workspace data.Deletion under the applicable provider control and BilagPilot process.
Customer Personal Data in protected backupsData may remain after active-system deletion until the relevant provider's backup rotation completes.Put beyond ordinary use where reasonably practicable. A further 90-day removal period is an operational target only where supported and verified for the relevant provider. No unverified universal maximum is promised.Automatic overwrite, provider rotation or secure deletion.
Customer Personal Data held by a SubprocessorDepends on the feature and provider.Bjorvand Solutions passes relevant return or deletion instructions to the Subprocessor and uses reasonable steps to obtain completion under its contract. Exact backup and deletion periods are provider-dependent.Return, deletion, anonymisation or restricted legal retention under the applicable contract.

6. BilagPilot Controller Data

Data categoryStandard retention rule or targetEnd action
Customer account and User profile data, including name, business email, verified telephone number, role, workspace membership and settingsRetained while the relationship is active and while needed to administer closure, deletion, security, billing and legal obligations. Active-system deletion is normally targeted within 90 days after closure, unless another category or lawful reason applies.Secure deletion or irreversible anonymisation.
Email and telephone verification codesThe code expires after ten minutes. Code values are stored in a protected or hashed form rather than as readable verification codes where confirmed.Expiry and deletion through the relevant authentication or cleanup process.
Verification events, login events and routine authentication metadataNormally reviewed for deletion or anonymisation within 12 months of the event, subject to provider configuration, security incidents, disputes and legal holds.Secure deletion or aggregation.
Trial registration records and internal trial notificationsRetained while needed to operate the Trial, contact the Customer where permitted, investigate failed setup, prevent abuse and document the relationship. Internal copies are normally targeted for review within 90 days of creation.Secure deletion, anonymisation or continued retention only where justified.
Minimal trial anti-abuse identifiers, including normalised or hashed business and matching accounting-system tenant keysRetained only as long as reasonably necessary to enforce the one-Trial rule and prevent abuse. The current policy target is up to three years after the Trial ends or the workspace is deleted, subject to periodic necessity review.Secure deletion or irreversible anonymisation.
Terms, DPA and related acknowledgement records, order records, contract records and material account-change recordsNormally retained for the period reasonably needed to prove the agreement and manage claims, commonly up to six years after the relationship ends, unless a shorter or longer legal period applies. The Privacy Policy is recorded as having been made available or acknowledged, not as separate consent.Secure deletion or continued retention only where legally justified.
Billing, invoice, tax, payment-status, refund and chargeback records held by BilagPilotRetained for the statutory period required by applicable Norwegian accounting and tax law and, where necessary, for debt recovery, chargebacks or contractual claims. Full card numbers are not stored by BilagPilot.Secure deletion after the statutory and claims periods expire.
Support requests, onboarding correspondence and ordinary customer communicationsNormally retained for up to 24 months after the matter is closed or the last substantive contact, unless part of a contract, complaint, security incident or dispute.Secure deletion or irreversible anonymisation.
Privacy rights requests, deletion requests and privacy complaintsNormally retained for up to three years after closure. Records connected to litigation, regulatory action or a material dispute may be retained longer, commonly up to six years after closure.Secure deletion while retaining only a minimal compliance record where necessary.
Routine application, access, webhook, delivery, rate-limit and security logsNormally reviewed for deletion or aggregation within 12 months of the event. Logs needed for an incident, investigation or legal claim follow the longer applicable period.Secure deletion or irreversible aggregation.
Security incidents, material abuse investigations and breach-response recordsRetained as long as reasonably necessary to investigate, remediate, demonstrate compliance and handle claims. The current policy target is up to six years after closure of a material incident, unless law or a regulator requires otherwise.Secure deletion or documented continued retention.
Product analytics and performance event data that remains personal or pseudonymousNormally targeted for deletion or irreversible aggregation within 12 months, subject to provider configuration and any shorter consent or cookie setting. Public upload routes under /u and /upload are excluded from the confirmed BilagPilot product-analytics filter.Secure deletion or irreversible aggregation.
Sales enquiries and marketing contact dataNormally retained for up to 24 months after the last meaningful interaction, unless the person becomes a Customer, asks for earlier deletion or another lawful reason applies.Secure deletion.
Marketing suppression recordsA minimal record, normally the email address and opt-out status, may be retained as long as reasonably necessary to respect the opt-out and prevent renewed marketing.Delete when no longer needed to honour the suppression.
Anonymous or irreversibly aggregated statisticsMay be retained without a fixed period where the information no longer identifies an individual and cannot reasonably be re-identified.Periodic review of the anonymisation basis.

7. Suppliers, Subprocessors and Customer-directed services

Subprocessors may retain personal data for shorter operational periods or for limited legal, security and backup purposes under their contracts with Bjorvand Solutions. Bjorvand Solutions requires relevant return, deletion or restricted-retention obligations where Applicable Data Protection Law requires them.

A Customer-directed service, such as an accounting system or identity provider independently selected and contracted by the Customer, may retain data under the Customer's separate agreement with that provider. The Customer should review that provider's retention terms.

A partial English supplier page exists, but a complete international supplier and Subprocessor register is not yet available. The partial page may be supplemented by Schedule 3 to the DPA and direct notices. Contract entity, processing location, backup period and transfer mechanism must be verified for the relevant provider and must not be inferred from a partial list.

A scheduled or requested deletion may be paused for the data reasonably necessary where:

  • a law, regulator, court or competent authority requires retention;
  • the data is relevant to an actual or reasonably anticipated legal claim;
  • the data is required to investigate a security incident, fraud, abuse or unauthorised access;
  • deletion would interfere with completing a valid rights request or investigation;
  • a provider's ordinary backup or deletion process has not completed; or
  • the Customer gives a lawful written instruction for a different period and Bjorvand Solutions accepts it.

Data subject to a hold is isolated or access-restricted where reasonably practicable. Deletion resumes when the reason for the hold ends.

9. Customer responsibilities

The Customer is responsible for:

  • deciding how long it lawfully needs Customer Personal Data;
  • configuring and using BilagPilot consistently with its own retention policy;
  • deleting or instructing deletion of data that is no longer needed;
  • giving clear return or deletion instructions through an authorised person;
  • exporting accounting documents and other required records before access ends;
  • maintaining any official accounting archive outside BilagPilot; and
  • informing Bjorvand Solutions promptly where a legal hold or shorter retention instruction applies.

10. Review and changes

Bjorvand Solutions reviews this Schedule when the service, deletion processes, providers or legal requirements materially change.

A change may update a target, confirm a provider-specific period, correct a technical description or reflect a new legal requirement. Material changes will be notified as described in the Terms of Service or DPA. Shortening a period may take effect sooner where it improves data minimisation and does not materially prevent the Customer from using or exporting its data.

11. Contact

Questions, return instructions or deletion instructions may be sent to:

Bjorvand Solutions Organisation number: 836 135 652 c/o Rengjøringshjelpen Kragerø AS Kirkegata 12 3770 Kragerø Norway Email: kevin@bilagpilot.no