Rocklab
Rocklab

Data Retention Policy

Last Updated: April 2026

This Data Retention Policy explains how long we keep your personal data and why. We retain data only for as long as necessary to fulfill the purposes outlined in our Privacy Policy, comply with legal obligations, and protect our legitimate interests.

This policy complies with GDPR Article 5(1)(e) (storage limitation principle) and Luxembourg data protection law.

Retention Periods

Members can leave Rocklab through two independent paths, both accessible from Settings → Data & Account. Deactivate My Account starts a 6-month grace period during which the account can be reactivated by logging back in; after 6 months, an automated job permanently anonymises the account. Delete My Account anonymises personal data immediately with no grace period. Financial and ticketing records retained under legal obligation are not affected by either path.

Data CategoryRetention PeriodLegal Basis / Justification
Active Member AccountsDuration of membershipContract performance (GDPR Art. 6(1)(b))
Deactivated Accounts6 months after deactivationLegitimate interests - grace period for reactivation, then permanently anonymized
Deleted Account DataAnonymized immediately
Metadata: 3 years
Legal obligation, legitimate interests (dispute resolution)
Profile & EPK ContentDuration of membership + 3 yearsContract performance, legitimate interests
Authentication Sessions7 days (standard)
28 days (remember me)
Security, legitimate interests
Refresh TokensUntil logout or 28 daysSecurity, user convenience
Room Bookings10 yearsLuxembourg legal obligation (Art. 16 Commercial Code — financial records)
Subscription Records10 yearsLuxembourg legal obligation (Art. 16 Commercial Code — financial records)
Financial Transactions10 yearsLuxembourg legal obligation (Art. 16 Commercial Code — tax, accounting)
Posts & CommentsUntil deleted by the member or until account anonymisation (whichever comes first). Author attribution is anonymised on account deletion; post content is retained for community integrity unless the member explicitly deletes the post.Contract performance, community integrity (legitimate interest)
System Logs90 days (general)
1 year (security logs)
Security, troubleshooting, legitimate interests
Security Incident Records3 yearsLegal obligation (breach notification), legitimate interests
Notifications90 days or until dismissedLegitimate interests (user communication)
Cookie Consent Records1 year or until updatedLegal obligation (consent management)
Marketing ConsentUntil withdrawal or 3 years inactivityConsent management, legitimate interests
Rejected Room Subscription Applications6 months after rejectionLegitimate interests - personal data anonymized, application record retained
Event Attendance LogsDuration of membershipLegitimate interests - engagement tracking, members can delete via settings
QR Code Access DataDeleted after each sessionSecurity - access logs retained for 90 days
Admin Private Notes2 years, reviewed quarterlyLegitimate interests - member support continuity
Expert TagsDuration of membership or until removedLegitimate interests - members notified and can request removal
International Expert ProfilesUntil consent withdrawn or profile deletedConsent (GDPR Art. 6(1)(a)) - experts can request deletion at any time
Audit Logs2 yearsSecurity, compliance monitoring
Support/Contact Inquiries3 years after resolutionLegitimate interests (customer service, dispute resolution)

Special Retention Cases

Legal Holds

If data is subject to a legal hold (e.g., pending litigation, regulatory investigation), we will retain the data beyond the standard retention period until the hold is lifted. You will be notified if your data is subject to a legal hold.

Extended Retention Requests

In certain cases, you may request extended retention of your data (e.g., for archival purposes). Such requests will be evaluated on a case-by-case basis.

Anonymized Data

We may retain anonymized or aggregated data indefinitely for statistical analysis, research, and service improvement. Anonymized data cannot be linked back to you and is not subject to GDPR data subject rights.

Data Deletion Process

Automatic Deletion

Our systems automatically delete or anonymize data when retention periods expire:

  • Expired sessions and refresh tokens are purged daily
  • Deactivated accounts are permanently anonymized after 6 months
  • Rejected room subscription personal data is anonymized after 6 months
  • Old logs are deleted monthly
  • Financial records are retained for 10 years (Art. 16 Luxembourg Commercial Code), then deleted

Manual Deletion (Right to Erasure)

You can request immediate deletion of your account at any time:

  1. Go to Settings → Data & Account
  2. Click "Delete My Account"
  3. Confirm your decision by typing "DELETE"
  4. Your personal data will be anonymized immediately

What gets deleted:

  • Name, email, phone, profile information (replaced with "Deleted User")
  • Authentication credentials and sessions
  • EPK content and media files
  • Notifications and non-financial records

What is retained (anonymized or pseudonymized):

  • Financial records (10 years - Art. 16 Luxembourg Commercial Code)
  • Booking history (anonymized - facility management)
  • Posts/comments (soft-deleted, author shown as "Deleted User")
  • Anonymized usage statistics

Retention Policy Review

This Data Retention Policy is reviewed annually to ensure:

  • Compliance with current legal requirements
  • Retention periods remain appropriate for stated purposes
  • Technical deletion processes function correctly
  • Alignment with business needs and risk management

Last review: April 2026 | Next review: April 2027

Questions About Data Retention

If you have questions about our data retention practices or want to request deletion of your data, contact us:

Data Protection Contact: mydata@rockhal.lu

Phone: (+352) 24 555-611

Address: 5, Avenue du Rock 'n' Roll, L-4361 Esch/Alzette, Luxembourg

Related Policies

The Centre de Musiques Amplifiées is under the patronage of and operates with the financial support of

Le Gouvernement du Grand-Duché de Luxembourg — Ministère de la Culture

Rockhal is proud to partner with

Premium partners
Raiffeisen
POST Luxembourg
BMW
Venue partners
CFL
Diekirch
Domaines Vinsmoselle
Pepsi MAX
L'essentiel

Rockhal is member of

European Arena Association
EVVC
Live Europe

Rockhal supports

Kulturpass
© 2026 Rocklab. Part of the Rockhal family.