Data Deletion
How and when applicant data is deleted.
Timely deletion of data is an important part of data protection. Sophie supports you in this.
Automatic Deletion
Configuration
Under Settings > Data Protection > Deletion Periods:
- Define when data should be deleted
- Select which data is affected
- Activate automatic deletion
Standard Periods
| Data Type | Period After Rejection |
|---|---|
| Contact Data | 6 months |
| Communication | 6 months |
| Documents | 30 days |
| Notes | 6 months |
Reminders
30 days before automatic deletion:
- You receive a notification
- You can postpone or confirm deletion
Manual Deletion
Delete Individual Applicant
- Open applicant profile
- Click Delete Applicant
- Confirm
Delete Individual Data
- Open applicant profile
- Go to Data Protection
- Select data to delete
- Click Delete Selected
Delete Multiple Applicants
- Go to applicant overview
- Select multiple applicants
- Click Delete
- Confirm
Deletion on Request
When Applicant Requests Deletion
- Applicant writes: "Please delete my data"
- Sophie informs you
- You review the request
- You approve deletion
Review Request
Before deletion, Sophie checks:
- Is the applicant identified?
- Is there an active process?
- Are there legal retention obligations?
During Active Process
Sophie informs the applicant:
"Your deletion request has been noted. As your application process is still active, your data will be deleted after its completion. You can withdraw your application at any time."
What Gets Deleted?
Complete Deletion
When deleting an applicant, the following is removed:
- Name and contact details
- Email address and phone number
- All uploaded documents
- Communication history
- Reviews and notes
- Appointment history
Anonymized Statistics
The following data remains anonymized:
- Number of applications (without names)
- Average processing time
- Success rates
This data cannot be attributed to any person.
Deletion Log
Documentation
Every deletion is documented:
- Time of deletion
- Reason (automatic, manual, request)
- Executing user
- Affected data types
View Log
Under Settings > Data Protection > Deletion Log:
- All performed deletions
- Filter by period and type
- Export as PDF
Retention Obligations
Legal Periods
Some data must be retained:
- Tax-relevant documents: 10 years
- Contract documents: 6 years after contract end
Marking
Sophie marks data with retention obligations:
- Cannot be deleted prematurely
- Automatic deletion after expiration
Secure Deletion
Encrypted Destruction
Deleted data is:
- Overwritten (not just marked)
- Removed from all backups (after 30 days)
- Logged
Irreversible
Deleted data cannot be recovered.
Best Practices
- Regularly review deletion logs
- Respond promptly to deletion requests
- Configure sensible automatic periods
- Document deletions for proof obligations