Activity Log and Data Retention
Please note: This article summarises legal requirements for orientation purposes only. It is not legal advice. If you need advice on your individual obligations, we recommend consulting a lawyer.
Why logging matters
The receipt of a withdrawal must be confirmed with its content, date and time (section 356a paragraph 4 BGB) Beyond this confirmation, a complete, timestamped history of the case protects you in case of disputes: it shows when the declaration arrived, how it was evaluated, who decided what, and what the customer was told.
returns.cloud produces this documentation automatically as a byproduct of the normal workflow. Your team does not need to maintain any separate records.
What the activity log contains
Every withdrawal case carries its own activity log. It records:
- Every status change (received, assigned, rejected, completed) with date, time and actor. The actor is either the system (for automatic decisions such as auto-matching, duplicate rejection or period-expired rejection) or the user who performed the action in the Management Portal.
- The rejection reason and the optional internal note for every rejection, so the reasoning is preserved beyond the email that the customer received.
- The email communication of the case, so your team can always verify what the customer received and when. See "Email Communication and Templates".
- The link to the withdrawal return once it has been created, in both directions. See "Processing Withdrawal Cases".
For manually created cases (for example after a phone withdrawal), the log shows who recorded the case and when, which keeps offline declarations just as traceable as widget submissions.
Data retention
Withdrawal cases and their logs are retained according to a retention period that is configured per widget, analogous to the retention of returns and order records in returns.cloud. Within the configured period, the full case history remains available in the Management Portal.
When defining the retention period, consider two directions:
- Long enough: The extended withdrawal period can reach 12 months and 14 days, and disputes can arise after that. Statutory retention obligations for business records may also apply to your organisation.
- Not longer than necessary: Withdrawal cases contain personal data (name, email address), so data protection principles such as storage limitation apply.
Behaviour on module deactivation
If the Withdrawal Management module is deactivated for your instance, existing cases, logs and configurations are retained and become accessible again after reactivation. Deactivation does not delete any data; deletion is governed solely by the retention period.