§ Law & obligations · 12 min read
Retention periods
Two obligations pull in opposite directions: keep data for as long as the law requires it — delete it as soon as its purpose has lapsed (Art. 5(1)(e) GDPR). Anyone who knows only one of the two makes a mistake.
The statutory periods at a glance
| Type of data | Period | Basis |
|---|---|---|
| Working-time records | at least 2 years | § 16 Abs. 2 ArbZG (German Working Hours Act), § 17 MiLoG (German Minimum Wage Act) |
| Payroll records and payroll accounts | 6 years | § 41 Abs. 1 Satz 9 EStG (German Income Tax Act), § 257 Abs. 4 HGB (German Commercial Code) |
| Accounting vouchers, annual financial statements | 10 years | § 147 AO (German Fiscal Code), § 257 HGB — kept by your bookkeeping, not by Zeitflex |
| Social security contribution records | until the end of the calendar year following the last audit | § 28f SGB IV (German Social Code, Book IV) — kept by your payroll accounting, not by Zeitflex |
| Sick notes | no statutory period; purpose is proof, after that an obligation to delete | Art. 5(1)(c)/(e) GDPR |
| Application documents of rejected applicants | usually 6 months | § 15 Abs. 4 AGG (German General Equal Treatment Act) plus a buffer — Zeitflex does not store applicant data |
When a period starts depends on the type of data. Periods under tax and commercial law run from the end of the calendar year (§ 257 Abs. 5 HGB, § 147 Abs. 4 AO). The working-time period, by contrast, runs record by record from the day of each recording — a clock-in on 3 March is old enough on 3 March two years later, not only at the end of the year.
All periods Zeitflex has set
Zeitflex has a retention matrix that states for each type of data from when it may be deleted, from which date the period is calculated and why exactly this value was chosen. You can see the same table in the application under Settings → Data & deletion → Retention periods. Here is the complete list:
| Type of data | Period | Calculated from | Basis |
|---|---|---|---|
| Working-time records (time entries, correction history) | 2 years | time of clocking in/out | § 16 Abs. 2 ArbZG, § 17 Abs. 1 MiLoG |
| Absences (vacation, illness, other absences) | 2 years | last day of the absence | § 16 Abs. 2 ArbZG, § 17 Abs. 1 MiLoG |
| Payroll records (locked pay periods, pay items, export logs) | 6 years | 31 Dec of the year of the last payment of pay | § 41 Abs. 1 Satz 9 EStG, § 257 Abs. 4 HGB, § 147 Abs. 3 AO |
| Sick notes (files) | 2 years | last day of the absence | chosen; Art. 5(1)(c)/(e) GDPR |
| GPS snapshots on time entries | 6 months | time of clocking in/out | chosen; Art. 5(1)(c)/(e) GDPR |
| Change log | 3 years | time of the event | chosen; Art. 5(2) GDPR, § 195 BGB (German Civil Code) |
| Open invitations (email address before the account is created) | 30 days | expiry or acceptance of the invitation | chosen; Art. 5(1)(e) GDPR |
| Sign-in, confirmation and refresh tokens | 30 days | expiry or revocation | chosen; Art. 5(1)(e) GDPR |
| Master data of former employees (name, email, personnel number) | 3 months, then anonymisation | leaving date | § 26 Abs. 1 BDSG (German Federal Data Protection Act), Art. 17(1)(a) GDPR |
| Withdrawal period after deleting the business | 30 days | time the deletion was requested | contractual commitment (AVV § 10, the data processing agreement) |
| Contract documents (employment contract, amendments, certificates) | 10 years | 31 Dec of the year in which employment ends | chosen; § 195, § 199 BGB, § 17 MiLoG, § 28f SGB IV |
| Photo records (proof of work for a job or shift) | 5 years | 31 Dec of the year the photo was taken | chosen; § 634a Abs. 1 Nr. 2 BGB |
| Other documents in the file store | 3 years | 31 Dec of the year of upload | chosen; § 195, § 199 Abs. 1 BGB |
| Safety briefing records (occupational safety, hazardous substances, hygiene) | length of employment + 3 years | 31 Dec of the year in which employment ends | chosen; § 12 ArbSchG (German Occupational Safety and Health Act), § 4 DGUV Vorschrift 1 (accident prevention regulation of the statutory accident insurance), § 195 BGB — to be confirmed by the owner |
| Application documents of hired people | 10 years | 31 Dec of the year in which employment ends | chosen; as for contract documents — to be confirmed by the owner |
| Team chat messages | at most 90 days | time of the message | chosen; Art. 5(1)(e) GDPR — not a record |
| Chat messages secured by a moderation action | 6 months | time of removal | chosen; § 12, § 13, § 15 Abs. 4 AGG |
| Screenshot attached to feedback | 12 months | upload | discontinued — no new ones are created |
“Chosen” means: the law names no period, and Zeitflex has made a reasoned decision. For sick notes, for example, there is no retention obligation; what matters is how long the file is needed as proof towards the health insurance fund and the audit service (continued pay under § 3 EFZG (German Continued Remuneration Act), reimbursement under the AAG (German Expenditure Compensation Act), standard limitation period § 195 BGB). Two years after the end of the absence is a reasonable middle ground — shorter than payroll records, because this is health data. This is a product decision, not legal advice.
The one adjustable period: the team chat
For the chat, the period works the other way round from everywhere else. For all other types of data the value is a minimum duration; for the chat it is a maximum duration. Messages are kept for at most 90 days, and the owner can only shorten this duration per group: to 7, 30 or 90 days. The default for a new group is 30 days. Only the owner may set the duration; the group learns about it through a notice in the history.
The reason: the chat is expressly not a record and not an archive. A quick shout of “Who is taking the early shift tomorrow?” should not turn up years later in an unfair dismissal case. If you want to record something bindingly, use an announcement with read receipt or enter it in the shift plan. More on this under Team chat: a quick shout, not an archive.
The only case in which a chat text outlives its period is a moderation action because of harassment: the removed message is secured for six months so that the employer can meet its duty of protection under § 12 AGG and the person affected can substantiate their complaint.
What the deletion run does every night
Zeitflex has a daily deletion run that is scheduled to start at 4:30 am — after the database backup at 2:30 am and after the clean-up job at 4:00 am, which removes expired invitations and sign-in tokens. The deletion run proceeds in this order, from the inside out — individual data before people, people before businesses:
- Documents whose period has expired — sick notes, contracts, photos, other. First the file in storage, then the record. Each category gets its own log entry with the correct legal basis.
- GPS snapshots older than 6 months. The coordinates are removed from the time entry; the entry itself remains.
- Making due departures effective: anyone entered with “notice effective” whose last working day has passed is set to inactive that morning and signed out of open phone sessions. This is not a deletion step — it only ends an authorisation.
- Former employees are anonymised three months after leaving: name, email, personnel number and login details are replaced with a pseudonym, and free texts and coordinates on their time entries are cleared. **Employment contract, safety briefing records and application documents are kept** until their own period expires — they outlast pseudonymisation and are then attached to the pseudonym. Sick notes, photo records and other documents are deleted along with them. The times themselves remain in full as a record. Three months, because follow-up payroll items — payment in lieu of vacation, correction payroll runs — experience shows arise up to a quarter after leaving. See Employee leaves the business.
- Businesses whose 30-day withdrawal period has expired: everything without a retention obligation is deleted, the rest is anonymised and locked. The owners receive a confirmation email listing what was kept and for what reason.
- Change log entries older than 3 years.
- Team chat: messages whose group period has expired, and secured complaints after 6 months.
Every deletion is logged. Owners and managers can see the deletion log under Settings → Data & deletion. It is your proof that data was deleted — without it you would have to prove that data is missing.
Just as important is what the deletion run does not do: it does not delete time entries, absences or pay periods of an active business — not even after two or six years. The two- and six-year periods are minimum periods, not deletion dates. If you want to get rid of old time data, you have to delete the business; and even then the anonymised remains stay. There is currently no automatic deletion of these remains after the minimum periods have expired.
Backups
The database is backed up every night at 2:30 am. Backups are deleted after 30 days at the latest. They serve to restore the whole system after an outage and are not used to recover individual deleted records or businesses.
Important for understanding: it is the database that is backed up, not the file storage. Uploaded files — sick notes, contracts, photos — are stored outside the database and are gone immediately after the deletion run. Only the database rows linger in the backups for up to 30 days; after that, not even those. Neither is accessible to you anyway. If you want to keep a file, download it beforehand.
Deleting the business
If you delete your business in Zeitflex, this happens in two stages:
- The business is marked for deletion and locked. The subscription is cancelled immediately.
- After 30 days, it is permanently deleted at the next deletion run. Within this period you can withdraw.
These 30 days are a safety net against the click at 23:00. The full export and the data access report expressly remain usable during this time. Export everything you need to keep — see Cancel your account and take your data with you.
Your obligation remains
Access requests from employees
Every employee can request access to their data under Art. 15 GDPR. In Zeitflex they can request this access themselves — Settings → Data & deletion → Download data copy, without going through you. They receive a readable version and a JSON file; the retention period of each type of data is included in the report. For a former employee, management triggers the report in employee management. This takes work off your hands and meets the one-month deadline more reliably than any manual process.
Frequently asked questions
An employee left four months ago. Why does she only appear as a pseudonym in the timesheet?
Because three months after she left, the deletion run anonymised her master data. Her times are all there — only name, email and personnel number have been replaced with a pseudonym. If you still need to know who it was, for example for a correction payroll run, the full export or the data access report you downloaded before the three months expired will help. After anonymisation, not even Zeitflex restores the name.
The labour court is hearing a dismissal case in a year. Will Zeitflex delete my sick note?
Yes, if the absence was more than two years ago — the period runs on a fixed basis, and there is no setting to extend it. Download the file under Documents and put it in your case file. Time entries and absences themselves are kept; the deletion run does not delete them.
Can I set the chat to one year so that agreements are not lost?
No. 90 days is the upper limit; 7, 30 or 90 days can be set per group. Anything that is meant to be binding belongs in an announcement with read receipt or in the shift plan — not in the chat.
Customs was here. Do I now have to keep things for longer?
During ongoing proceedings — labour court, company audit, inspection by customs (FKS, German financial control of undeclared work) — a retention obligation applies beyond the standard period. Zeitflex does not know about these proceedings and does not extend anything automatically. The deletion run does not delete time entries anyway; what is at risk are sick notes, GPS coordinates and documents whose period has expired. Save the affected files outside Zeitflex beforehand, see Customs is inspecting — what now?.
Still stuck?
Write to us via Support; what you should save before a deletion is explained under Cancel your account and take your data with you, and what is stored about an individual person under What Zeitflex stores about me.
Last checked on . We check every article against the application — if something no longer matches, that is a bug and not a difference of opinion.
Was this helpful?
Related articles
- Record-keeping duty — clearly explainedWho has to record working time, what exactly, since when — and what already applies today from the planned change in the law.
- Recording a sick noteHow a sick note works in Zeitflex, how the doctor’s certificate is uploaded securely, who may see it — and how to undo a typo.
- Cancelling your account and taking your data with youWhat to export before cancelling, how to end the subscription, how the two-stage deletion works and which obligations remain with you.
- Team chat: a shout across the yard — no archive, no recordThree commitments: at least three people per group, a retention period instead of an archive, and management never reads along silently.
- Employment contract, records, photos: documents in ZeitflexFour document types, clear visibility, fixed deletion periods — and why the tax adviser sees nothing here.
- An employee leaves: deactivate, leaving date, what remainsDeactivate instead of delete — from the next billing period the seat costs nothing, the times remain auditable, and after three months the person disappears from the names.
- What Zeitflex stores about me — the data access reportEvery person obtains their own access report under Art. 15 GDPR themselves — readable and as a file, without going through the business.