§ Law & obligations · 12 min read

Retention periods

Two obligations pull in opposite directions: keep data for as long as the law requires it — delete it as soon as its purpose has lapsed (Art. 5(1)(e) GDPR). Anyone who knows only one of the two makes a mistake.

The statutory periods at a glance

Type of data Period Basis
Working-time recordsat least 2 years§ 16 Abs. 2 ArbZG (German Working Hours Act), § 17 MiLoG (German Minimum Wage Act)
Payroll records and payroll accounts6 years§ 41 Abs. 1 Satz 9 EStG (German Income Tax Act), § 257 Abs. 4 HGB (German Commercial Code)
Accounting vouchers, annual financial statements10 years§ 147 AO (German Fiscal Code), § 257 HGB — kept by your bookkeeping, not by Zeitflex
Social security contribution recordsuntil the end of the calendar year following the last audit§ 28f SGB IV (German Social Code, Book IV) — kept by your payroll accounting, not by Zeitflex
Sick notesno statutory period; purpose is proof, after that an obligation to deleteArt. 5(1)(c)/(e) GDPR
Application documents of rejected applicantsusually 6 months§ 15 Abs. 4 AGG (German General Equal Treatment Act) plus a buffer — Zeitflex does not store applicant data

When a period starts depends on the type of data. Periods under tax and commercial law run from the end of the calendar year (§ 257 Abs. 5 HGB, § 147 Abs. 4 AO). The working-time period, by contrast, runs record by record from the day of each recording — a clock-in on 3 March is old enough on 3 March two years later, not only at the end of the year.

All periods Zeitflex has set

Zeitflex has a retention matrix that states for each type of data from when it may be deleted, from which date the period is calculated and why exactly this value was chosen. You can see the same table in the application under Settings → Data & deletionRetention periods. Here is the complete list:

Type of data Period Calculated from Basis
Working-time records (time entries, correction history)2 yearstime of clocking in/out§ 16 Abs. 2 ArbZG, § 17 Abs. 1 MiLoG
Absences (vacation, illness, other absences)2 yearslast day of the absence§ 16 Abs. 2 ArbZG, § 17 Abs. 1 MiLoG
Payroll records (locked pay periods, pay items, export logs)6 years31 Dec of the year of the last payment of pay§ 41 Abs. 1 Satz 9 EStG, § 257 Abs. 4 HGB, § 147 Abs. 3 AO
Sick notes (files)2 yearslast day of the absencechosen; Art. 5(1)(c)/(e) GDPR
GPS snapshots on time entries6 monthstime of clocking in/outchosen; Art. 5(1)(c)/(e) GDPR
Change log3 yearstime of the eventchosen; Art. 5(2) GDPR, § 195 BGB (German Civil Code)
Open invitations (email address before the account is created)30 daysexpiry or acceptance of the invitationchosen; Art. 5(1)(e) GDPR
Sign-in, confirmation and refresh tokens30 daysexpiry or revocationchosen; Art. 5(1)(e) GDPR
Master data of former employees (name, email, personnel number)3 months, then anonymisationleaving date§ 26 Abs. 1 BDSG (German Federal Data Protection Act), Art. 17(1)(a) GDPR
Withdrawal period after deleting the business30 daystime the deletion was requestedcontractual commitment (AVV § 10, the data processing agreement)
Contract documents (employment contract, amendments, certificates)10 years31 Dec of the year in which employment endschosen; § 195, § 199 BGB, § 17 MiLoG, § 28f SGB IV
Photo records (proof of work for a job or shift)5 years31 Dec of the year the photo was takenchosen; § 634a Abs. 1 Nr. 2 BGB
Other documents in the file store3 years31 Dec of the year of uploadchosen; § 195, § 199 Abs. 1 BGB
Safety briefing records (occupational safety, hazardous substances, hygiene)length of employment + 3 years31 Dec of the year in which employment endschosen; § 12 ArbSchG (German Occupational Safety and Health Act), § 4 DGUV Vorschrift 1 (accident prevention regulation of the statutory accident insurance), § 195 BGB — to be confirmed by the owner
Application documents of hired people10 years31 Dec of the year in which employment endschosen; as for contract documents — to be confirmed by the owner
Team chat messagesat most 90 daystime of the messagechosen; Art. 5(1)(e) GDPR — not a record
Chat messages secured by a moderation action6 monthstime of removalchosen; § 12, § 13, § 15 Abs. 4 AGG
Screenshot attached to feedback12 monthsuploaddiscontinued — no new ones are created

“Chosen” means: the law names no period, and Zeitflex has made a reasoned decision. For sick notes, for example, there is no retention obligation; what matters is how long the file is needed as proof towards the health insurance fund and the audit service (continued pay under § 3 EFZG (German Continued Remuneration Act), reimbursement under the AAG (German Expenditure Compensation Act), standard limitation period § 195 BGB). Two years after the end of the absence is a reasonable middle ground — shorter than payroll records, because this is health data. This is a product decision, not legal advice.

The one adjustable period: the team chat

For the chat, the period works the other way round from everywhere else. For all other types of data the value is a minimum duration; for the chat it is a maximum duration. Messages are kept for at most 90 days, and the owner can only shorten this duration per group: to 7, 30 or 90 days. The default for a new group is 30 days. Only the owner may set the duration; the group learns about it through a notice in the history.

The reason: the chat is expressly not a record and not an archive. A quick shout of “Who is taking the early shift tomorrow?” should not turn up years later in an unfair dismissal case. If you want to record something bindingly, use an announcement with read receipt or enter it in the shift plan. More on this under Team chat: a quick shout, not an archive.

The only case in which a chat text outlives its period is a moderation action because of harassment: the removed message is secured for six months so that the employer can meet its duty of protection under § 12 AGG and the person affected can substantiate their complaint.

What the deletion run does every night

Zeitflex has a daily deletion run that is scheduled to start at 4:30 am — after the database backup at 2:30 am and after the clean-up job at 4:00 am, which removes expired invitations and sign-in tokens. The deletion run proceeds in this order, from the inside out — individual data before people, people before businesses:

  1. Documents whose period has expired — sick notes, contracts, photos, other. First the file in storage, then the record. Each category gets its own log entry with the correct legal basis.
  2. GPS snapshots older than 6 months. The coordinates are removed from the time entry; the entry itself remains.
  3. Making due departures effective: anyone entered with “notice effective” whose last working day has passed is set to inactive that morning and signed out of open phone sessions. This is not a deletion step — it only ends an authorisation.
  4. Former employees are anonymised three months after leaving: name, email, personnel number and login details are replaced with a pseudonym, and free texts and coordinates on their time entries are cleared. **Employment contract, safety briefing records and application documents are kept** until their own period expires — they outlast pseudonymisation and are then attached to the pseudonym. Sick notes, photo records and other documents are deleted along with them. The times themselves remain in full as a record. Three months, because follow-up payroll items — payment in lieu of vacation, correction payroll runs — experience shows arise up to a quarter after leaving. See Employee leaves the business.
  5. Businesses whose 30-day withdrawal period has expired: everything without a retention obligation is deleted, the rest is anonymised and locked. The owners receive a confirmation email listing what was kept and for what reason.
  6. Change log entries older than 3 years.
  7. Team chat: messages whose group period has expired, and secured complaints after 6 months.

Every deletion is logged. Owners and managers can see the deletion log under Settings → Data & deletion. It is your proof that data was deleted — without it you would have to prove that data is missing.

Just as important is what the deletion run does not do: it does not delete time entries, absences or pay periods of an active business — not even after two or six years. The two- and six-year periods are minimum periods, not deletion dates. If you want to get rid of old time data, you have to delete the business; and even then the anonymised remains stay. There is currently no automatic deletion of these remains after the minimum periods have expired.

Backups

The database is backed up every night at 2:30 am. Backups are deleted after 30 days at the latest. They serve to restore the whole system after an outage and are not used to recover individual deleted records or businesses.

Important for understanding: it is the database that is backed up, not the file storage. Uploaded files — sick notes, contracts, photos — are stored outside the database and are gone immediately after the deletion run. Only the database rows linger in the backups for up to 30 days; after that, not even those. Neither is accessible to you anyway. If you want to keep a file, download it beforehand.

Deleting the business

If you delete your business in Zeitflex, this happens in two stages:

  1. The business is marked for deletion and locked. The subscription is cancelled immediately.
  2. After 30 days, it is permanently deleted at the next deletion run. Within this period you can withdraw.

These 30 days are a safety net against the click at 23:00. The full export and the data access report expressly remain usable during this time. Export everything you need to keep — see Cancel your account and take your data with you.

Your obligation remains

Access requests from employees

Every employee can request access to their data under Art. 15 GDPR. In Zeitflex they can request this access themselves — Settings → Data & deletionDownload data copy, without going through you. They receive a readable version and a JSON file; the retention period of each type of data is included in the report. For a former employee, management triggers the report in employee management. This takes work off your hands and meets the one-month deadline more reliably than any manual process.

Frequently asked questions

An employee left four months ago. Why does she only appear as a pseudonym in the timesheet?

Because three months after she left, the deletion run anonymised her master data. Her times are all there — only name, email and personnel number have been replaced with a pseudonym. If you still need to know who it was, for example for a correction payroll run, the full export or the data access report you downloaded before the three months expired will help. After anonymisation, not even Zeitflex restores the name.

The labour court is hearing a dismissal case in a year. Will Zeitflex delete my sick note?

Yes, if the absence was more than two years ago — the period runs on a fixed basis, and there is no setting to extend it. Download the file under Documents and put it in your case file. Time entries and absences themselves are kept; the deletion run does not delete them.

Can I set the chat to one year so that agreements are not lost?

No. 90 days is the upper limit; 7, 30 or 90 days can be set per group. Anything that is meant to be binding belongs in an announcement with read receipt or in the shift plan — not in the chat.

Customs was here. Do I now have to keep things for longer?

During ongoing proceedings — labour court, company audit, inspection by customs (FKS, German financial control of undeclared work) — a retention obligation applies beyond the standard period. Zeitflex does not know about these proceedings and does not extend anything automatically. The deletion run does not delete time entries anyway; what is at risk are sick notes, GPS coordinates and documents whose period has expired. Save the affected files outside Zeitflex beforehand, see Customs is inspecting — what now?.

Still stuck?

Write to us via Support; what you should save before a deletion is explained under Cancel your account and take your data with you, and what is stored about an individual person under What Zeitflex stores about me.

Last checked on . We check every article against the application — if something no longer matches, that is a bug and not a difference of opinion.

Dieser Artikel auf Deutsch

Was this helpful?

Related articles

Retention periods · Zeitflex