Data Retention Policy

Reskript® Platform Data retention Policy
Effective date: 30.09.2026
‍
1. Purpose and Scope
‍
This Data Retention Policy explains how MphaR s.r.o. ("MphaR", "we", "us", or "our"), as the operator of the Reskript web application ("Reskript" or the "Service"), retains and deletes data processed through the Service.
‍
This Policy applies to account information, user-provided information, generated documents, technical records, payment-related records, and other data processed in connection with the use of Reskript.
‍
MphaR operates its information security management system in accordance with ISO/IEC 27001 and processes personal data in accordance with applicable data protection requirements, including the General Data Protection Regulation ("GDPR").
‍
2. Retention Principles

‍
MphaR applies data retention periods based on the purpose for which particular data is processed and the technical requirements of operating the Service.
‍
User content and generated documents are retained for as long as the user chooses to keep them within Reskript.
Where a user deletes data or deletes their account, the relevant data becomes unavailable through the Service and is scheduled for deletion from active systems.
‍
Unless otherwise specified in this Policy, deletion from active systems is completed within 30 days.
Residual copies may remain in backups until those backups are automatically deleted or overwritten in accordance with the applicable backup retention cycle.
‍
3. Account Information

‍
When registering an account, Reskript may collect and retain information including:
• first name;
• last name;
• email address;
• country;
• where the user registers as a legal entity: legal entity name, Tax ID, street and building number, city, postal code, and state or region where provided.
‍
Account information is retained for as long as the user's account remains active.
‍
If the user deletes their account, the associated account information is removed from active systems within 30 days, subject to the backup retention provisions described below.
‍
4. User Content and Generated Documents
‍
Reskript allows users to provide information for the purpose of generating documents.
‍
User-provided information and generated documents are retained for as long as the user chooses to keep them within the Service.
‍
There is no predefined automatic expiration period for such content.
‍
Users control the deletion of their content through the functionality provided by the Service.
‍
When a user deletes content:
1. the content becomes unavailable to the user through the Service;
2. the content is scheduled for removal from active systems;
3. full deletion from the system is completed within 30 days;
‍
Deletion of an entire account triggers the same process for all user content associated with that account.
‍
5. Access to User Documents

‍
User-generated documents are accessible to the user through their account.
‍
MphaR administrators do not have access through the application to the contents of user-generated documents.
‍
Technical records used for operating, monitoring, and securing the Service may contain identifiers relating to users or documents, but do not contain the content of the documents themselves.
‍
6. Special Categories of Personal Data
‍
Reskript is not designed or intended for the processing of special categories of personal data within the meaning of Article 9 of the GDPR.
This includes, for example, information concerning:
• racial or ethnic origin;
• political opinions;
• religious or philosophical beliefs;
• trade union membership;
• genetic data;
• biometric data used for identification;
• health information;
• information concerning a person's sex life or sexual orientation.
‍
Users should not submit such information through Reskript.
‍
If a user nevertheless chooses to include special-category personal data or other sensitive information in information submitted through the Service, the user is responsible for ensuring that they have an appropriate legal basis and any required authorization to collect, use, and submit that information.
‍
7. Technical, Security and Application Logs
‍
Reskript maintains technical logs necessary for operation, troubleshooting, monitoring, and security of the Service.
Such logs may contain identifiers relating to:
• users;
• documents;
• system operations;
• application events.
Application logs do not contain the contents of user-generated documents.
‍
Technical and application logs are retained for 90 days and are subsequently deleted or overwritten.
‍
8. Payment Information
‍
Payments are processed by external payment service providers.
‍
Reskript does not store payment card numbers, card security codes, payment credentials, or equivalent sensitive payment information.
‍
Reskript retains a limited internal transaction record relating to purchases made through the Service. This may include information identifying:
• the user who made the purchase;
• the product or service purchased;
• the payment provider used;
• the transaction status;
• the relevant transaction or payment reference.
‍
These transaction records are retained indefinitely for the following purposes:
• maintaining transaction and purchase history;
• handling payment disputes and chargebacks.
‍
Payment information held independently by external payment providers is subject to the retention policies and legal obligations of those providers.
‍
9. Backups
‍
MphaR maintains backups for business continuity, disaster recovery, and protection against accidental loss or system failure.
Backups may contain copies of data that has subsequently been deleted from active systems.
‍
Backups are retained for up to 12 months and are automatically deleted, expired, or overwritten as part of the standard backup rotation process.
Data contained exclusively within backups is not used for ordinary application access.
‍
Where deleted data remains in an existing backup, it will be removed when the relevant backup reaches the end of its retention period.
For this reason, deletion of data from active systems within 30 days does not necessarily mean that every residual backup copy is physically erased within the same 30-day period.
‍
10. Infrastructure and Data Location
‍
MphaR may use third-party service providers and subprocessors where necessary to operate and provide the Service. Primary application data is hosted in the EU region in partner’s cloud infrastructure. Where third-party technology providers are used, Medical Pharma Services, s.r.o. will seek to ensure that appropriate contractual, technical and organizational safeguards are in place.
‍
11. Account Deletion
‍
A user may request or initiate deletion of their Reskript account.
‍
Following account deletion:
• access to the account is disabled and user content and generated documents become unavailable through the Service;
• account and user content data is scheduled for deletion from active systems;
• deletion from active systems is completed within 30 days.
‍
Data may continue to exist temporarily in system backups for up to 12 months, as described in Section 9.
‍
Technical logs are retained independently for up to 90 days.
‍
Transaction and purchase records described in Section 8 are retained indefinitely and are not deleted as part of account deletion.
‍
12. Data Processed by Service Providers
‍
MphaR uses third-party service providers and subprocessors to provide infrastructure, payment processing, application functionality, maintenance, and other technical services required for operation of Reskript.
‍
Such providers may process limited data where necessary to perform their respective services.
‍
MphaR requires processors handling personal data on its behalf to process such data in accordance with applicable contractual and data-protection requirements.
‍
Third-party providers may maintain limited technical or operational copies of data in accordance with their own documented retention mechanisms, provided that such processing is consistent with the services they provide to MphaR and applicable data-protection requirements.
‍
13. Data Deletion and Irrecoverability
‍
Once data has been deleted from active systems and the relevant backup retention periods have expired, the data is no longer maintained by MphaR as part of the Reskript service infrastructure.
‍
Deletion processes are designed so that expired data is deleted or overwritten as part of normal system operation and cannot subsequently be restored through the Service.
‍
14. Changes to This Policy
‍
MphaR may update this Data Retention Policy where necessary to reflect changes. The current version of this Policy will be made available through the Reskript website.
‍
15. Contact

‍
Questions or requests relating to data retention or deletion may be submitted to:
‍
Reskript®
Owned and operated by Medical Pharma Services, s.r.o.
Evropská 846/176a, Prague 160 00
Czech Republic
Company ID / IČO 27084949
VAT ID CZ27084949
support@reskript.com