In this document
Your request
For access, correction, erasure or other privacy rights, email privacy@nfceez.de. Supply only information necessary to identify the request, such as account email and merchant. Do not send passwords or unsolicited full identity-document copies. The relevant merchant is involved for instructed processing. Statutory conditions govern handling.
Delete a business account
The Business app includes deletion with reauthentication. The intended process removes account data and associated files but may require follow-up after errors. Apple subscriptions must be managed separately. Notification device tokens are deleted with the account; the app-lock setting exists only on your device and is removed when you delete the app. Lawfully necessary billing or abuse-prevention evidence and other controllers’ data may need separate treatment.
Remove a branch
A branch is initially disabled with a 30-day recovery period. The audit does not confirm active automatic final cleanup afterwards. Complete automatic erasure after exactly 30 days is therefore not promised. Shared menus, programmes and other branches’ data may still be needed.
Loyalty memberships
Ending participation and erasing personal data are separate assessments. One shared identity may have several distinct memberships. Deleting one programme must not unlawfully erase others. Automatic deletion after 24 months of inactivity and full self-service erasure are not confirmed operational. Requests may go to the privacy contact.
Menu files and AI
Original menu files have an expiry and periodic-cleanup process. Uploaded original files are deleted automatically 30 days after upload; the clean-up runs every hour. Structured drafts, results and usage metadata need separate retention. Deletion by NFCeez does not necessarily erase all provider logs simultaneously.
Business verification
Uploaded proof (register extract, trade registration, tax office letter) is deleted automatically 30 days after NFCeez's decision; if an owner submits new documents, the period runs from the new decision. Deleting the account removes proof immediately. The result, the type of proof, the dates and the review steps are kept for the life of the account and three further years to resolve disputes.
Retention criteria
Accounts: necessary contract duration and specific settlement. Bookings/feedback: necessary handling and justified merchant evidence. Loyalty: necessary membership and outstanding claims. Support/delivery/security: necessary handling, troubleshooting or abuse investigation. Billing: specific statutory duties and necessary legal defence. Backups: confirmed access-restricted backup cycle.
Specifically: account, profile and team data until the account is deleted; loyalty cards and loyalty customers 24 months after the last activity; loyalty sign-in codes after one day; verification proof 30 days after the decision; billing records up to ten years (§ 257 HGB, § 147 AO). Deletions run automatically; the operator is responsible. These criteria do not permit indefinite stockpiling. Data without a remaining purpose or basis must be erased or effectively anonymised.
Return and evidence
Return of instructed data follows the DPA and merchant instructions. Complete automated export is not confirmed. A suitable manual process, secure delivery and deadlines must be available. Completion and justified retention exceptions are documented; restorations must not permanently reverse completed erasure.