Data Processing Agreement
Last updated: 25 September 2026
Parties, acceptance and priority
This Data Processing Agreement ("DPA") forms part of the Flenno Terms of Service or other service agreement that incorporates it ("Agreement").
The customer is the business identified in the accepted order, registration or service agreement ("Customer"). The processor is Tmi Lauri Koskensalo, trading as Flenno, Business ID 3361714-6, Viholankatu 12 A 16, 37120 Nokia, Finland ("Flenno"). Flenno's privacy and security contact is info@flenno.com.
This DPA becomes binding when an authorised representative of the Customer accepts an Agreement that expressly incorporates this DPA, or when the parties otherwise sign or electronically accept it. Flenno must make the DPA available before acceptance and record the Customer, accepting representative, acceptance time and accepted version. Acceptance must precede processing on the Customer's behalf.
This DPA prevails over conflicting terms concerning the processing of Customer Personal Data. Applicable mandatory law and any applicable international transfer clauses take priority. No term authorises a use of Google user data prohibited by Google's API policies.
Annexes 1 to 4 form part of this DPA. They specify the processing, required security measures, authorised subprocessor arrangements, and return and deletion procedure.
Scope and roles
"Customer Personal Data" means personal data that Flenno processes on the Customer's behalf through the service. "Personal Data Breach", "controller", "processor" and "processing" have the meanings given in the EU General Data Protection Regulation ("GDPR").
The Customer acts as controller, or as a processor acting on a controller's documented instructions. Flenno acts respectively as processor or subprocessor. Where the Customer is itself a processor, it must have the upstream controller's authority to engage Flenno and issue the relevant instructions. Flenno provides assistance through the Customer unless law requires otherwise.
This DPA does not cover information Flenno processes as an independent controller for its own billing, business contacts, contract administration or public website. Those activities are described in the Privacy Policy. This distinction does not permit Flenno to repurpose Customer Personal Data or relabel customer content as its own business data.
The DPA continues for as long as Flenno or its subprocessors retain Customer Personal Data, including during an agreed exit or deletion period.
Documented instructions
Flenno will process Customer Personal Data only on documented instructions from the Customer, including instructions concerning international transfers, unless applicable EU or Member State law requires otherwise. In that case Flenno will inform the Customer of the legal requirement before processing, unless the law prohibits that notification.
The Agreement, this DPA, the Customer's authorised service configuration and use of the requested features, and subsequent verified written requests constitute instructions. Instructions must remain within the purposes and limits in Annex 1. Additional processing or a new purpose requires separate documented agreement and any further authorisation required by law or Google policy.
Flenno will promptly inform the Customer if an instruction appears to infringe applicable data protection law and may suspend the affected processing while the parties resolve it.
The Customer is responsible for its lawful collection and disclosure of data, required notices and permissions, and the instructions it gives. Flenno remains responsible for its own obligations as processor.
Purpose restrictions and Google user data
Flenno will use Customer Personal Data to provide the Customer's requested analytics, reporting, account-access and AI-assisted features and to protect the service in accordance with this DPA.
Flenno will not sell Customer Personal Data, disclose it to data brokers, use it for advertising, or use it to train or improve general-purpose AI or machine-learning models. Customer-specific stored insights and retrieval of existing information are used to provide the Customer's features, not to train shared models.
For information obtained through Google APIs, including derived information, Flenno will comply with the Google API Services User Data Policy and its Limited Use requirements:
https://developers.google.com/terms/api-services-user-data-policy
Transfers of Google user data are limited to the permitted provision of prominently disclosed features with the user's authorisation, necessary security purposes or legal requirements. No sale of the business or other corporate transaction by itself authorises a transfer; any transfer must satisfy Google's requirements, including prior explicit user consent where required.
Flenno will not allow personnel to read Google user data except with the user's affirmative agreement to review specific information, where necessary for security, or where required by law. Technical administrative access does not provide a general permission to inspect customer content.
Confidentiality and security
Flenno will ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations and receive instructions appropriate to their access.
Flenno will implement and maintain the technical and organisational measures in Annex 2, taking account of the nature of the processing, risks, state of the art and implementation costs. Measures may be improved without reducing the overall agreed protection. Material reductions require the Customer's agreement unless mandatory law requires them.
Flenno will limit personnel access to what is necessary, record privileged access, and review and revoke access when it is no longer needed.
Subprocessors
The Customer grants general written authorisation for the arrangements listed in Annex 3 and their disclosed onward processing, subject to this section. An unlisted service is not authorised to receive Customer Personal Data merely because it is generally used by Flenno.
Before engaging a subprocessor, Flenno will assess its suitability and impose written data protection obligations that provide the protection required by Article 28 GDPR. Flenno remains responsible to the Customer for the subprocessor's performance of those obligations.
Flenno will notify the Customer directly, using its designated account or privacy contact, at least 30 calendar days before adding or replacing a subprocessor or materially expanding an authorised processing territory. The notice will identify the legal entity, purpose, data involved, location and relevant transfer safeguards. Merely updating a public webpage is not sufficient notice.
The Customer may object during that notice period on reasonable data protection grounds. The parties will seek a practical resolution. If none is available, the Customer may terminate the affected part of the service before the change and receive a refund of the unused prepaid portion. Flenno will not begin the disputed new processing for that Customer before resolving the objection or ending the affected service.
Flenno will maintain information about relevant onward subprocessors and apply the same authorisation and notice requirements where required by law. Its responsibility is not transferred to the Customer by linking to a vendor's list.
International transfers
The authorised storage and processing arrangements are described in Annex 3. Primary application storage and AI inference use EU regions. The service is not an EU-only processing service: authentication and some infrastructure operations involve the United States and other disclosed infrastructure locations.
Restricted transfers are subject to Chapter V GDPR. Flenno will ensure that an applicable adequacy decision or appropriate safeguards cover the transfer, including the European Commission's international-transfer Standard Contractual Clauses, any required transfer assessment and supplementary measures where applicable.
AWS's published Service Terms incorporate its Data Processing Addendum, supplementary terms and applicable international-transfer Standard Contractual Clauses. WorkOS's published Data Processing Addendum forms part of its subscription terms and provides for applicable Standard Contractual Clauses. The provider terms linked in Annex 3 describe their contractual safeguards. They do not replace Flenno's responsibility to ensure that the relevant processing and transfer arrangements apply to its use of those services.
On request, Flenno will provide information about, or a copy of, relevant transfer safeguards, subject to necessary protection of confidential information.
Flenno will assess requests for government access, notify the Customer where legally permitted, challenge unlawful requests where reasonably available and limit any legally required disclosure to the necessary information.
Data subject requests and assistance
Flenno will promptly forward a request concerning Customer Personal Data to the Customer, normally within two business days. It will not independently decide the Customer's response unless authorised or legally required.
Flenno will provide reasonable technical and organisational assistance with access, correction, deletion, restriction, objection and portability requests. It will provide available information and assistance normally within five business days of the Customer's request, or sooner where needed to meet a legal deadline.
Flenno will also assist with security obligations, data protection impact assessments and prior consultation with a supervisory authority, taking account of the information available to it and the nature of the processing.
Routine assistance and standard exports and deletion are included in the service. Any separately requested work beyond Flenno's legal and contractual obligations requires advance agreement on scope and price. A fee dispute must not delay assistance required by law.
Personal Data Breaches
Flenno will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, with an initial notice no later than 24 hours after awareness.
The notice will describe the nature of the breach, affected data and people where known, likely consequences, steps taken or proposed, and a contact for follow-up. Flenno may provide information in stages and will not delay the initial notice while investigating.
Flenno will take reasonable containment and remediation steps, preserve necessary evidence, cooperate with the Customer and document its response. The Customer determines notifications to authorities and individuals for processing it controls, with Flenno's assistance, unless law imposes a separate duty on Flenno.
Demonstrating compliance and audits
Flenno will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant security information, subprocessor arrangements and evidence of return or deletion.
The Customer or an independent auditor bound by confidentiality may conduct a proportionate audit, including an inspection where needed. Routine audits will normally begin with document review and be coordinated on reasonable notice to protect service continuity and other customers' information.
A routine audit is normally limited to once in 12 months. This does not restrict additional audits justified by a breach, credible compliance concerns or a competent authority's requirements. Flenno will cooperate with supervisory authorities and promptly address substantiated deficiencies.
Return, deletion and retained copies
At the end of processing, the Customer may choose return followed by deletion, or deletion without return. Annex 4 sets out the procedure, configured retention periods and criteria for retained copies. An earlier valid erasure instruction or a mandatory legal deadline takes priority over an agreed retrieval window.
Flenno will apply the procedure to relevant active systems, files, caches, stored AI material and subprocessors. Removing a visible account, disconnecting an integration or soft-deleting a record does not by itself satisfy the obligation to erase the underlying data.
Flenno will arrange deletion of existing copies under Annex 4 unless applicable EU or Member State law requires storage. Residual backups must be isolated from ordinary use, handled under the schedules and criteria in Annex 4 and not be used to restore deleted data into active service. Retention must not continue for an unrelated purpose or indefinitely merely because a copy is a backup. Any legally required retention must be limited, documented and explained to the Customer unless prohibited by law.
Flenno will confirm completion and identify any lawful exception, its scope and planned expiry.
General terms
The Agreement's liability provisions apply only to the extent permitted by law. They do not restrict a data subject's statutory rights or change Flenno's obligations under Article 28 GDPR or applicable transfer clauses.
Material changes to this DPA will be communicated directly in advance. Changes requiring the Customer's agreement will not be introduced merely by publishing a new version. Subprocessor changes follow section 6.
This DPA is governed by Finnish law, subject to applicable mandatory law and the governing-law provisions of any applicable transfer clauses. The Agreement's dispute-resolution provisions apply.
ANNEX 1 - DESCRIPTION OF PROCESSING
A. Parties and contacts
Customer: the business identified in the accepted order or Agreement. Its designated organisation administrator or privacy contact may issue verified instructions within their authority.
Flenno: Tmi Lauri Koskensalo, Business ID 3361714-6, at the address in section 1.
Privacy, security, return and deletion contact: info@flenno.com.
B. Subject matter and purposes
Provision of a business analytics service: authorised account access, collection of reports from connected Google Analytics properties, storage and presentation of reports, customer-specific AI analysis, retrieval of relevant saved context, and associated service security and support on the Customer's instructions.
C. Nature and frequency
Collection through authorised integrations or user input; organisation and storage; retrieval and analysis; generation of reports and responses; display to authorised users; secure return; restriction and erasure. Processing is ongoing while the service is active, with API synchronisation and AI processing triggered by configured jobs and user-facing features.
D. Data subjects
The Customer's authorised users, employees, contractors, representatives and business contacts, and persons whose information the Customer lawfully includes in connected reports, business context or messages. Google Analytics reports are generally aggregated, but user-supplied text, page paths, campaign names and other dimensions can contain personal data and are not treated as necessarily anonymous.
E. Personal data categories
Names, business email addresses, account identifiers, organisation memberships and access roles.
Google account identifiers, property and account information, authorised scopes, connection metadata and encrypted OAuth credentials.
Analytics report dimensions and metrics relating to traffic, acquisition, engagement, campaigns, devices, approximate geography and e-commerce performance.
User questions, conversation content, business context, generated insights, saved customer-specific memory, embeddings and associated metadata, where they contain personal data.
Relevant timestamps, technical identifiers, access and error events, and IP addresses needed for security and operation.
The standard GA4 reporting integration does not request individual visitor User-ID, Client ID or User Pseudo ID fields. This does not guarantee that all other report content is anonymous.
F. Restricted data
Special-category data under Article 9 GDPR, criminal-offence data, payment-card details and passwords are not intended for submission to the service. Any supported exception requires a separately agreed lawful purpose and safeguards before processing. This restriction does not remove Flenno's duties if such data is received accidentally.
G. Duration and instructions
Processing continues for the active service and the limited exit and deletion periods in Annex 4. The Customer may issue lawful instructions through authorised features or info@flenno.com. The Customer's rights and duties include choosing the purposes, providing required notices and lawful permissions, controlling user access, selecting return or deletion, and receiving assistance and compliance information under this DPA.
ANNEX 2 - TECHNICAL AND ORGANISATIONAL MEASURES
Flenno will maintain the following measures for processing covered by this DPA:
Access and confidentiality. Named administrative accounts, multifactor authentication for privileged access, least-privilege permissions, access logging and periodic review. Within Flenno, privileged customer-data access is assigned to the Head of Development. Any additional access must be justified, approved and recorded. Personnel must follow confidentiality and security instructions. Google-data human review remains subject to section 4.
Encryption and credentials. Encrypted transport for service and provider connections; encrypted databases and backups; encrypted OAuth access and refresh tokens. Organisation-specific token encryption keys are protected using AWS key-management services. Secrets are kept out of ordinary logs, support messages and exports.
Tenant separation. Organisation-scoped permissions, database access controls and checks designed to prevent cross-customer access, including in AI retrieval. Production access is restricted and customer data is not copied into development or test environments unless specifically authorised with appropriate protection.
Data minimisation. Collect only fields necessary for authorised features. Use appropriate redaction and masking for personal data, tokens and sensitive URL parameters. Do not place raw prompts, analytics payloads, session credentials or customer content into routine telemetry. Redaction is a safeguard and not a claim that free text is fully anonymous.
AI controls. Use the EU regional or geographic Bedrock arrangements in Annex 3, with model and region restrictions. Provider data-sharing, general-purpose model training and global inference profiles are not authorised for Customer Personal Data under this DPA. Any prompt caching or necessary provider retention remains subject to the applicable service safeguards and this DPA; no blanket zero-retention promise is made.
Operational security. Maintain supported software, vulnerability and dependency management, controlled changes, security monitoring and risk-based remediation. Protect production network access and record privileged operations. Review these controls at least annually and following a material change or incident.
Resilience and backups. Maintain encrypted backups, restricted recovery access and documented restoration and deletion procedures. Test restoration at least annually and after material changes. Apply the separate schedules and deletion criteria in Annex 4 to automated backups, manual and final snapshots, and provider-held copies.
Incident and request handling. Maintain a monitored contact channel, a breach-response process, an inventory of systems holding Customer Personal Data and a record of verified return and deletion requests. The Head of Development owns execution and evidence of the technical steps.
Supplier controls. Complete subprocessor due diligence, maintain applicable processing and transfer arrangements, monitor relevant changes and restrict data supplied to each vendor to its authorised function.
Erasure and restored data. Erase the active records, files, derived AI material, credentials and dedicated keys covered by a deletion instruction; maintain a minimal deletion record. Reapply outstanding deletion instructions before restored data is made available in active service.
ANNEX 3 - AUTHORISED SUBPROCESSOR ARRANGEMENTS AND LOCATIONS
The following are the authorised arrangements for this version of the DPA. Flenno must maintain supplier contracts, settings and transfer safeguards consistent with this annex. A legal entity, service or location outside these arrangements requires the process in section 6.
A. Amazon Web Services
Authorised entities: Amazon Web Services EMEA SARL, Luxembourg, and Amazon Web Services, Inc., United States, as applicable under the AWS Customer Agreement, together with relevant AWS onward subprocessors for the infrastructure functions disclosed below and in AWS's subprocessor register. AWS's agreement determines the contracting entity by the AWS account's country; the authorised infrastructure entities listed here are distinct from that billing-party determination.
Purposes: application hosting, PostgreSQL database, encrypted storage and backups, key management, service logging, network protection, content delivery and Amazon Bedrock AI processing.
Data scope: the Customer Personal Data needed for those infrastructure functions. AI requests are limited to relevant questions, context, retrieved customer-specific material and analytics outputs.
Primary application and database region: Stockholm, Sweden (eu-north-1). Flenno-operated primary customer storage and database backups remain in this EU region unless the Customer agrees to another arrangement.
AI processing: EU geographic inference and EU regional services. Authorised EU destinations are Sweden, Germany, Ireland, France, Italy and Spain, according to the selected profile and region controls. Regional reranking may run in Frankfurt, Germany. No global inference profile is authorised by this annex.
Other infrastructure: CloudFront operates a global edge network. Delivery requests and related network metadata can be processed outside the EEA; the region of the primary database does not constrain every edge operation. AWS WAF security logging for the global distribution may take place in Northern Virginia, United States (us-east-1). Raw analytics reports and AI conversation content must not be intentionally included in edge logs or publicly cached responses.
Relevant AWS support and onward-processing locations are identified in AWS's published register. These are distinct from the primary storage and inference regions. Flenno must assess and disclose the relevant onward access and apply sections 6 and 7.
Provider documentation:
https://aws.amazon.com/agreement/
https://aws.amazon.com/service-terms/
https://aws.amazon.com/compliance/sub-processors/
Anthropic and Cohere are the model developers for the configured Bedrock models. This arrangement authorises AWS-hosted model processing, not direct Anthropic or Cohere API access or disclosure for those developers' own training. Any arrangement making a model developer a separate recipient of Customer Personal Data requires prior assessment and the authorisation process in this DPA.
B. WorkOS
Authorised entity: WorkOS, Inc., United States.
Purpose: authentication, user and organisation membership, access control and session management to the extent performed on the Customer's behalf.
Data scope: user names, business email addresses, authentication and organisation identifiers, membership information and relevant security and session metadata. Google Analytics reporting payloads, AI prompts and the Google Analytics integration's stored OAuth token bundle are not supplied to WorkOS as part of this authorised function. Google sign-in credentials handled within the authentication flow are distinct from that analytics integration.
Processing location: United States, with relevant onward service providers identified in WorkOS's published register. No EU-only WorkOS residency is represented by this DPA.
Provider documentation:
https://workos.com/legal/terms-of-service
https://workos.com/legal/data-processing-addendum
https://trust.workos.com/subprocessors
WorkOS processing, international-transfer safeguards and provider-held copies are governed by the applicable WorkOS service terms and Data Processing Addendum, subject to Flenno's obligations under this DPA. Flenno coordinates individual-user and organisation deletion through the available WorkOS procedures. Ending a Customer's Flenno subscription does not itself terminate Flenno's entire WorkOS service agreement. Backup and archival copies follow the provider schedule described in Annex 4.
C. Customer-selected services and separate website activities
A Google account or Analytics property connected under the Customer's own agreement with Google is a customer-selected source service, not automatically a Flenno-appointed subprocessor. Flenno's access remains limited to the user's authorisation and the Google API policies.
Framer, Leadfeeder, Microsoft Clarity and website Google Analytics are described in Flenno's public-website Privacy Policy. This annex does not authorise sending application Customer Personal Data to those website services. Website tracking must not capture authenticated customer content, OAuth credentials, AI conversations or imported reports.
No additional error-monitoring, AI, support-content or other recipient is authorised to receive Customer Personal Data under this version unless included through section 6. General availability of a software integration does not establish authorisation to activate it.
ANNEX 4 - RETURN, RETENTION AND DELETION PROCEDURE
A. Requests and ownership
Requests are submitted by an authorised Customer representative to info@flenno.com. Flenno will record receipt, scope and the relevant systems and verify authority proportionately. An internal approval step does not restart an applicable statutory deadline.
The Head of Development is responsible for execution and recording completion. Standard requests are acknowledged within two business days.
B. Return format and delivery
On a return request, Flenno will prepare a standard export without undue delay, targeting delivery within 14 calendar days and in any event within 30 calendar days of receipt, unless a different mandatory deadline or agreed statutory switching process applies.
The export includes the Customer's exportable analytics records, supplied business context, organisation-owned conversations and generated insights, settings and relevant metadata within the Customer's lawful authority. Tabular information is supplied as UTF-8 CSV and structured records as JSON, with a description of the fields and relationships. Third-party rights, another customer's data, raw credentials and protected internal software are excluded only as lawfully permitted.
Delivery uses an access-controlled, encrypted transfer, with recipient verification. Raw customer datasets and access tokens are not sent in ordinary email. A download link expires after seven days and may be reissued during the retrieval period. Expiry of a link does not shorten the Customer's retrieval right.
C. Ordinary end of service
The relevant end date is when the Customer's service actually ends, not when it first cancels a future renewal.
Flenno then stops routine ingestion and feature processing and arranges return followed by deletion, or deletion without return, according to the Customer's instructions. This includes ending unnecessary access, dealing with integration authorisations and removing credentials no longer needed for the agreed exit process. The process includes administrative steps; subscription cancellation or integration disconnection alone does not erase the underlying records.
Flenno begins the exit process without undue delay and coordinates any necessary retrieval period with the Customer. If the Customer gives no return instruction, Flenno proceeds with deletion after giving a reasonable opportunity to request return, subject to applicable law. A retained exit copy is restricted to authorised return, security and completing the deletion process and is erased when those purposes end.
Where statutory switching rules apply, data remains available for retrieval for at least 30 calendar days after the transition, as described in the Terms of Service. Flenno will not erase data while a mandatory retrieval period or the Customer's timely return request remains outstanding. An earlier lawful deletion instruction takes priority over an optional retrieval period.
D. Deletion requested during service or before the retrieval period ends
A valid deletion instruction is executed without undue delay and within applicable legal deadlines. The scope may require administrative work and coordination with subprocessors. Flenno identifies the relevant systems and explains any remaining copies, retention basis and deletion schedule or criteria. An acknowledgement or initial response is not represented as completed erasure.
No retrieval window is imposed on a Customer who requests deletion without return. Flenno explains if an instruction necessarily disables a feature or deletes shared organisation data and verifies authority without unnecessary delay.
Deleting one user's account does not authorise erasure of other users' or another organisation's data. Shared identities and records are handled at the correct scope.
E. Systems covered
The process covers active source-report records, derived facts and reports, conversations, generated insights, saved customer-specific memory and embeddings, export files, caches, uploaded files, OAuth grants and tokens, organisation-specific encryption-key records, and relevant identity-provider records.
Flenno will instruct and follow up with subprocessors. It will verify identity-provider deletion separately rather than assuming that deletion of a local user removes the external profile. Data legitimately needed for a different customer or a separate lawful account relationship is isolated from the erased organisation.
Disconnecting one Google Analytics integration stops that integration but can retain its shared Google grant and encrypted tokens. Disconnecting Google entirely clears the active token ciphertext and requests Google revocation; it does not by itself erase previously imported reports or other customer content. Clearing active credentials does not erase copies in earlier backups.
As part of an administrative deletion request, Flenno checks outstanding provider steps and follows up as needed. It does not report successful external revocation solely because the local connection was disabled. The Customer may also revoke access through https://myaccount.google.com/connections.
F. Backups and snapshots
Flenno-operated automated database backups are configured for seven-day retention. Deleting a record from the active database does not immediately remove the record from an existing backup; that backup expires under its retention cycle.
Manual and final database recovery snapshots remain until explicitly deleted and are outside the automated seven-day cycle. Their deletion is Flenno's responsibility. Flenno reviews these copies as part of administrative deletion, restricts their use to a documented necessary recovery or legal purpose, and deletes them when that purpose ends. The absence of automatic expiry does not authorise indefinite retention.
Personal data retained in WorkOS backup and archival systems is deleted in accordance with WorkOS's applicable data retention schedule. WorkOS's Data Processing Addendum describes the handling of those copies. Flenno arranges and follows up on relevant WorkOS deletion requests separately from local deletion and remains responsible for its applicable obligations.
Residual copies are unavailable for ordinary feature processing. Before any restoration is returned to service, applicable deletion instructions are reapplied. Flenno's completion notice distinguishes active-system deletion, scheduled backup expiry, manual snapshot handling and provider-held copies. A provider schedule is not a blanket exception to applicable erasure obligations.
G. Logs and narrow exceptions
Routine production application, database, network and security logs are generally retained for 90 days. Content-delivery access logs expire after 90 days, with older stored versions retained for a further 30 days after becoming noncurrent. Selected backend security and administrative audit records are retained for 1,096 days, approximately three years, from the event. The archive may contain user and organisation identifiers, full IP addresses, timestamps, actions and redacted event details. Raw analytics payloads, conversation content and credentials are excluded from the audit archive.
The restricted archive supports investigation of late-discovered security incidents and the establishment, exercise or defence of legal claims. Account deletion does not automatically erase it. Flenno assesses erasure requests and objections individually, limits any continued retention to a justified lawful purpose described in its Privacy Policy, and does not use these records for marketing. A configured retention period does not itself override a valid erasure right.
A legal preservation requirement is documented by purpose, data category, authority, access restriction and review date. Retained material is not used for analytics, AI or product improvement and is erased when the requirement ends.
H. Completion evidence
Flenno confirms deletion within five business days after completion of the relevant active-system work, specifying the scope, date, remaining-copy schedules or deletion criteria, and any lawful exception. The notice distinguishes completed erasure from a deletion request merely submitted to a vendor.
Flenno records final backup, snapshot and subprocessor completion when established. Minimal request-handling evidence is retained only as needed to demonstrate completion or meet a specific legal requirement; entries in the security audit archive follow section G. It contains no copy of the erased customer content, and applicable data subject rights continue to apply.