Legal

Retention Policy

Version 1.0 · effective 9 August 2026

Principles

  1. We do not keep data longer than necessary for the purpose for which we collected it, unless a legal obligation requires longer retention.
  2. For customer data, such as invoices, email metadata and accounting data, the customer is the controller. The customer determines the retention period within the term of the contract.
  3. The 7-year tax retention duty under Article 52 AWR and Article 2:10 of the Dutch Civil Code rests with the customer, not with us. Invoices are also posted in Exact Online and remain there under the customer's control.
  4. After the contract ends, the exit arrangement in our data processing agreement applies: export first, then deletion.

Customer data

Here we are the processor.

DataPeriod
Invoices: original files, extracted data, approval history and audit trailAvailable during the term of the agreement, per the customer's instructions. After the end date, kept for 90 days so the customer can export or reopen the account. Then deleted from production within 30 days
Inbox Agent email metadata90 days for messages that turned out not to be invoices. Invoice-related records follow the invoice
Email we receive at purchase.useglimps.comWe process the message immediately on receipt. The temporary store of the received message is emptied within 30 days
AI conversations in the platform12 months after the last activity
OAuth tokens for Microsoft and Exact Online connectionsUntil the customer disconnects. Then deleted and revoked
Approval tokens from email linksValid for 7 days. Expired tokens are deleted automatically

Our own data

Here we are the controller.

DataPeriod
Account dataUp to 90 days after deletion of the account or the end of the contract. Minimal contract and billing data we must keep longer by law is excluded
Our own sales invoices and billing data7 years, under the tax retention duty
Payment data and Mollie events7 years, as part of our administration
Product analytics in the platform12 months
Session recordings in the platform30 days
Website analytics14 months
Error and security logs90 days, unless a specific incident requires longer investigation
Support correspondence, including live chat24 months after the question is closed
Demo and call booking data24 months after the appointment. 6 months where no appointment or follow-up took place

AI providers

RouteRetention at the provider
GooglePer our data processing agreement with Google
OpenAIPer our data processing agreement with OpenAI

Our AI providers may retain inputs and outputs briefly for security and abuse monitoring. We do not share data for training or improving models, and we do not use features that store conversations or files at an AI provider.

What we store ourselves in our database in terms of prompts and responses is kept only as far as needed for the product function and for auditability. That follows the customer periods above.

Backups

DataPeriod
Database dumps and file copies, stored at Cloudflare R2Maximum 30 days, then deleted

Deleted data may still appear in a backup up to that period. We use backups only for recovery after an incident, not to restore deleted data. If we must restore fully after an incident, we reapply the deletions afterwards.

Requesting deletion

Send a request for export or deletion to [email protected]. We confirm receipt and handle it within 30 days.

Questions about this document? [email protected]