Seraya Psikologi — Documentation

Booking and payment MVP · Implementation baseline · 96 ADR

87. Redact Direct Client Identifiers and Preserve Minimal Pseudonymous Links

Status

Accepted for launch planning.

Context

Client/contact data reaches a 12-month retention window, but Booking/Appointment/Payment/Refund/audit integrity may still require a historical reference. Hard-deleting the entire Client graph would either destroy integrity or force unsafe exceptions.

Decision

After Client/contact retention eligibility is reached:

The pseudonymous reference must not be a reversible copy of the original contact value and must not be exposed through ClientAccess or public UI. Active dependencies, disputes, applicable audit/legal policy, or PrivacyRequest exceptions may delay or alter the category-specific action; the exception is recorded rather than silently skipped.

Consequences

Positive:

Costs and constraints:

Open follow-up

Define field-level redaction map, pseudonym generation/storage, exception precedence, job/manual trigger, verification evidence, and client-facing PrivacyRequest behavior.