Closing your account
When you can close an account, what happens immediately, how the deletion deadline starts, and how to request a return or withdraw the closure.
You close your account under “Organization”, in the “Close account” section.
When it is possible
Only the “Owner” of your own organization can close it, and only while no subscription is running. If one is still running, cancel it first: Cancel contracts here. Only once it has ended, on the free plan, can you close the account here.
What happens immediately
Closing ends every member's session at once and nobody can sign in again; scheduled scans stop, and API access and webhook endpoints end. The owner and the administrators receive an email right away with the next steps and the two links described below.
The deadline
The 90-day deletion deadline only starts once that notice email has actually been delivered – not already when the account is closed. If sending fails, no deadline is running and nothing is deleted: the daily run reports the failed notice to us, a person sends it again, and only once that one arrives does the deadline start. If you do nothing before the deadline ends, we delete your data – that is your choice under Art. 28(3)(g) GDPR: deletion or return.
Requesting a return
The "Request return" link in the notice email holds off deletion: we prepare your data for handover instead of deleting it. This is only possible until the deadline ends. Once requested, a return holds off deletion even past the deadline, until the handover is completed.
Withdrawing the closure
The "Withdraw closure" link in the same email reopens your account – even after you requested a return. This, too, is only possible until the deadline ends. API tokens, schedules and webhook endpoints do not come back on their own; you set them up again after withdrawing.
One rare edge case: if you withdraw the closure at the very moment deletion is running, it can cost the screenshots attached to findings and cached PDF reports. Your account stays, and the reports themselves stay readable – only the images that went with them are gone.
What stays
Statements that were already published stay reachable at their address, as a PDF and in the embed, even past deletion – § 8 of the terms and conditions and § 8 of the data processing agreement expressly exclude them. The same applies to unpublished drafts on a website that also has a published statement; websites with no published statement at all are deleted together with their drafts. We keep orders and invoice details as long as the law requires it.
Last checked against the product on September 20, 2026. As Markdown
Related articles
-
Team and roles
Who may do what in an organization – owner, administration, editing, read only – and how to invite more people.
-
Plans, subscription and cancellation
What the plans include, what happens to websites and statements when you move to a smaller plan, and where to cancel or withdraw.
Still have a question?
Tell us which question is still open. Questions we hear more than once become new help articles.