Data Retention Policy

Effective and last updated 27 September 2026

This policy sets out how long Wellbook keeps data and how it is deleted. Under Indonesia’s Personal Data Protection Law (Law No. 27 of 2022), Singapore’s Personal Data Protection Act 2012 and the GDPR alike, personal data may be kept only as long as it serves the purpose it was collected for, or as the law requires. It supplements our Privacy Policy and Terms of Service.

1. Who decides

A business that uses Wellbook decides how long to keep the data it holds about its own clients and staff; we keep that data on its behalf for as long as its account is open. For the data we hold about users of the Service, and our own records, we decide, as set out below.

2. Retention schedule

Unless the law requires us to keep something longer (section 6):

Business records
Clients, staff, bookings, classes, packages, credits, payment and refund records, the log of messages sent to clients, and the activity log of changes made by the business’s users. Kept while the business’s account is open, unless the business deletes them sooner (section 3). Deleted after the account closes (section 4).
User accounts
Name, email address, password hash and memberships. Kept while the account is open; deleted with the business account it was created under, or earlier on request.
Account links
Password reset links expire after 1 hour, email verification links after 24 hours and invitations after 7 days. They are stored only as hashes and are deleted with the account.
Sign-in cookies
The session cookie expires after 7 days without use; the workspace cookie after 12 months.
Rate-limit counters
IP addresses and email addresses used to limit repeated attempts. Expire within 1 hour.
Hosting logs
Request logs, including IP addresses. Kept by our hosting provider for no more than 30 days.
Email delivery records
Kept by our email provider for no more than 30 days.
Error reports
If error monitoring is on: kept for no more than 90 days.
Product analytics
Only for users who accepted analytics cookies. Events are kept for no more than 12 months and session recordings for no more than 90 days, or deleted sooner on request.
Database backups
Point-in-time recovery covering the last 6 hours. Deleted data leaves the backups once that window has passed. We keep no other backups.
Our billing records
Our invoices to you and the payments for them: 10 years, as Indonesian tax law requires books and records to be kept.
Correspondence
Emails with us, including personal data requests: 2 years after the matter is closed. If we refuse an access request, we keep a copy of the data requested for at least 30 days after refusing, and longer if the refusal is reviewed by the Personal Data Protection Commission.

3. Deleting records while the account is open

  • Users with the right role can delete clients, staff, services, packages and other settings that have no bookings, packages or payments recorded against them. They are removed from the live database immediately.
  • Records with history are kept, so that the business’s bookings, payments and reports stay complete. Their details can be edited to remove anything no longer needed, and duplicate client records can be merged.
  • A business that needs a record with history erased altogether, for example to act on a client’s request, can ask us at privacy@hibeckon.com. We will act on the business’s instruction.

4. When an account closes

  • An administrator can close the business’s account in Settings (Delete organization), or by writing to privacy@hibeckon.com from their email address. It closes at once: no one can use it, and no more emails go to its clients.
  • Before or after closing, an administrator can download everything the account holds from Settings (one spreadsheet workbook). For 30 days after closing, an administrator can still download it or reopen the account.
  • When those 30 days are over, the business’s data is deleted from the live database, including the accounts of users who don’t also belong to another business on Wellbook. It then leaves our backups within 6 hours.
  • A business must keep its own copies of any records the law requires it to retain (for example accounting and tax records); once deleted, we cannot recover them.

5. How we delete

Deleting means removing the data from our live database and letting it expire from backups as described above. Where we keep information for statistics, we first anonymise it irreversibly so that it can no longer identify anyone; anonymised data is not personal data and may be kept.

6. Legal holds

We may keep specific data longer where the law requires it, or where it is needed to establish, exercise or defend a legal claim, or to cooperate with a regulator or law enforcement. We keep only what is needed, restrict access to it, and delete it when the reason ends.

7. Requests from individuals

If you are a client or staff member of a business that uses Wellbook, ask that business to delete or correct your data; we will pass on any request you send us. If you are a user of the Service, write to our Data Protection Officer at privacy@hibeckon.com.

8. Changes

We will update this policy when our practices or providers change, and change the date at the top. Questions: privacy@hibeckon.com.