Eurobase
Docs Pricing FAQ
Sign in Get started

Contents

  • Welcome
  • 1. Signing Up
  • 2. Creating Your First Project
  • 3. The Project Dashboard
  • 4. Building the Database
  • 5. File Storage
  • 6. Authentication Setup
  • 7. Rate Limits
  • 8. Custom SMTP
  • 9. Managing End Users
  • 10. Exploring the API
  • 11. Webhooks
  • 12. Row-Level Security
  • 13. Vault (Secrets)
  • 14. Scheduled Jobs
  • 15. Edge Functions
  • 16. Monitoring with Logs
  • 17. Compliance, Audit Log & DSAR
  • 18. Project Settings
  • 19. Team Collaboration
  • 20. CLI Tool
  • 21. Schema Migrations
  • 22. Connecting Your IDE
  • 23. MCP Server
  • 24. Your Account
  • 25. Direct Postgres connection (Team)
  • 26. Team tier — dedicated Postgres, backups, snapshots
  • 27. Organizations & SSO (OIDC)
  • 28. German legal-tech retention (Legal Team)
  • What's Next

28. German legal-tech retention (Legal Team)

Per-prefix WORM policies and row/object-scoped retention holds for tenants subject to §50 BRAO, §257 HGB, or §147 AO.

Closed beta — invite only. Legal Team is a separate SKU on top of Team; not self-serve yet. Email contact@eurobase.app with your retention basis (BRAO / HGB / AO / other) and workload. Grants are manual during the beta window.

Why this exists

German professional-services firms — law firms in particular — have to keep specific record classes for years under statute, and cannot delete them on a DSAR erasure request during that window. The three common bases:

  • §50 BRAO (Federal Lawyers' Act) — client files retained 6 years from case end.
  • §257 HGB (Commercial Code) — split by record class: books, inventories, opening balance sheets, annual accounts, and invoices (Buchungsbelege) retained 10 years; received / sent commercial letters (Handelsbriefe) retained 6 years.
  • §147 AO (Fiscal Code) — same split, mirroring §257 HGB: 10 years for books and accounting records, 6 years for other tax-relevant business correspondence.

On Free / Pro / plain Team, retention is defence-in-depth (soft delete + audit log) but not statutorily enforced. Legal Team makes retention WORM-enforced at the storage layer — even a compromised admin key can't delete a locked object before its retention date. That's what German auditors and clients subject to MaRisk AT 7.2 want to see.

What Legal Team unlocks

  • Default per-prefix policies. Every object under /invoices/* is retained 10 years under §257 HGB, WORM-enforced by S3 Object Lock. Additional prefixes (/client-files/* for §50 BRAO, /tax/* for §147 AO) configured per project.
  • Ad-hoc retention holds. When a customer cites a legal basis mid-lifetime (e.g. "this row / this object is subject to litigation hold"), the console's Retention tab lets you pin the specific row, object, or table beyond its default policy. The hold survives DSAR erasure attempts and is audited.
  • Honest DSAR erasure. When a user asks to be forgotten, held items are refused with a specific message the requester sees in their export: "retained under §257 HGB, purgeable after 2036-03-14". No silent no-op; no ambiguous "we removed everything we could". The exporter enumerates every held item + basis + earliest purge date so the user can plan a follow-up request.
  • 10-year audit-log retention (vs 90 days on standard tiers) so the audit trail itself survives the same statutory window as the data it describes.

Where to find it in the console

Project → Compliance → Retention. The tab shows every currently-held row/object with its basis + expiry, an audit-log filter for retention actions, and a link to the upgrade CTA if you're not on Legal Team yet. DSAR erasure requests fired from the DSAR tab automatically respect any active holds.

Related

  • Compliance overview → section 17 (DPA report, sub-processors, DSAR baseline).
  • Direct Postgres connection → section 25 (Legal Team includes the dedicated instance from the Team tier).
Next: What's Next →
← 27. Organizations & SSO (OIDC) What's Next →