In this article, you will learn how archiving and anonymization differ, how to bring an archived member or prospect back with the Restore member action, which two permissions are involved and why the archiving configuration only shows you the facilities you are whitelisted for, what a restore cannot bring back, how to keep a member out of automatic archiving, and which data is permanently gone once a record has been anonymized.
Contents
- Archiving and anonymization are two separate steps
- Recovering archived members and prospects
- If you archived a record by mistake
- Data protection and anonymization
- Prospects and their own archiving settings
- Conditions that block archiving
- Related articles
Quick Guide
- Archiving and anonymization are two separate steps. Archiving can be undone, anonymization cannot.
- Archived records keep their personal data and stay visible under Members / Archived members.
- To bring a record back, open Members / Archived members, open the context menu of the row and select Restore member.
- You need the role permission Manage archived members for the restore. Changing the rules for automatic archiving is a different permission, Manage automatic archiving and anonymization.
- Only anonymization deletes the personal data irreversibly. It runs either through the separate Anonymize member action or, if configured, automatically some time after archiving.
- Archiving can delete data on its own. Four separate settings, Delete address data, Delete contact data, Delete documents and Delete photo, decide what goes. Whatever was switched on at the moment of archiving is gone, and a restore does not bring it back.
- A member whose member code is listed under Exclude the following member codes from automatic archiving is skipped by automatic archiving.
Archiving and anonymization are two separate steps
Archiving and anonymization are two different operations. They have their own permissions, their own settings and very different consequences. Only anonymization is final.
Archiving takes a member or prospect out of your day to day views. The record leaves the member list and the search results and moves to the archived members list. The personal data of the record stays in place unless you have configured deletions for the archiving step.
Anonymization overwrites the personal data of an archived record. After that the record no longer identifies a person and it cannot be restored.
| Archiving | Anonymization | |
|---|---|---|
| Effect on the record | Removed from all overviews and searches, listed under Members / Archived members | Personal data is overwritten, the record is removed from all overviews and searches |
| Personal data | Stays intact, except for the items that the four deletion settings remove at archiving time | Permanently deleted |
| Can it be undone | Yes, with the Restore member action | No, the process cannot be undone |
| How it is triggered | Manually, or by the automatic archiving configuration | By the Anonymize member action, or by automatic anonymization if it is configured |
| Permission for the manual action | Restoring a record needs Manage archived members | Single member anonymization or Bulk member anonymization |
| Permission to configure the automatic run | Manage automatic archiving and anonymization, plus a whitelist for the facility | Manage automatic archiving and anonymization, plus a whitelist for the facility |
The software states the same distinction when you activate automatic archiving: archived records can be viewed and restored with the appropriate permission, while the automatic anonymization irreversibly deletes all personal data and cannot be undone.
Four separate settings decide what archiving deletes
Archiving can still remove individual pieces of data, depending on how your configuration is set, and this is where a restore reaches its limit. Deletion at archiving time is not one switch. In the archiving configuration under Settings / Studio / Privacy policy, on the tab Archiving and anonymization, there is a block headed Delete this member information irretrievably when archiving: with exactly four checkboxes, and each of them is set on its own. In the order they appear on screen:
- Delete address data removes the address data of the record.
- Delete contact data removes the contact data of the record.
- Delete documents removes the documents stored on the record.
- Delete photo removes the photo stored on the record.
These four are the complete list. There is no single setting that covers all of them, and there is no further deletion setting beyond them. Because each one stands on its own, every combination is possible. A studio can lose the contact data of its archived records and keep their documents, or keep the contact data and lose the photos.
What a restore cannot bring back therefore depends on which of the four were active at the moment the record was archived, not on how the configuration looks today. Data that a setting removed back then stays gone even if that setting has been switched off since. Data that was kept back then is still there even if the setting has been switched on since.
Which of the four are switched on is decided per configuration, so it differs from studio to studio and there is no state you can assume. Before you promise a member that a restore returns everything, open Settings / Studio / Privacy policy, switch to the tab Archiving and anonymization and read the four checkboxes in your own configuration.
Recovering archived members and prospects
Archived members and prospects are not deleted. You can restore them individually at any time, as long as they have not been anonymized yet. The archived members list says so on the page itself.
Prerequisites
Two role permissions come up around archiving, and they do two different jobs. One lets you restore a record, the other lets you change the rules for automatic archiving. Neither one includes the other.
| Role permission | What it lets you do |
|---|---|
| Manage archived members | Search and view archived members, and restore individual records. This is the permission for the restore action. Without it you will not see the archived members list at all. |
| Manage automatic archiving and anonymization | View and change the configuration of automatic archiving and automatic anonymization, meaning the periods, the four deletion settings and the list of excluded member codes. It does not allow you to restore a record. |
Ask your studio admin to grant the one you are missing. If the archived members list or the restore action is not visible for you, the permission you need is Manage archived members, not the configuration permission.
The archiving configuration is whitelisted per facility on top of that. You see and edit only the configurations of the facilities you are whitelisted for, and that applies to reading a configuration as well as to creating, changing and deleting one. In an organization with several facilities this has a practical consequence: an admin can be unable to find out why a member was archived, because the configuration that governs that member belongs to a facility the admin is not whitelisted for. In that case ask a colleague who is whitelisted for that facility, or have your own whitelisting extended.
Here is how to restore a record:
- Go to Members / Archived members. You see an overview of all archived members.
- Find the record you want to bring back.
- Open the context menu of the row and select Restore member.
- Confirm the question whether you really want to restore the member.
- In the dialog you can additionally decide whether to Assign member codes and whether to Exclude from automatic archiving. If you enable the exclusion, the record is skipped by automatic archiving from now on, while manual archiving stays possible at any time.
Result: the record is active again and appears in the member list and in the search results as before. Anything that was deleted at archiving time because of the four deletion settings is not brought back and has to be entered again. Which items those are depends on which of the four were active when this record was archived.
[Screenshot: Members / Archived members list with the row context menu open showing "Restore member"]
If you archived a record by mistake
Archiving by mistake is not a data loss. Do the following:
- Go to Members / Archived members and restore the record with Restore member, as described above.
- Do not use Anonymize member on the record and do not include it in a bulk anonymization. That step is the one that cannot be reversed.
- If automatic anonymization is active in your configuration, restore the record as early as you can. Automatic anonymization only picks up records that have been archived for a while, so there is a time window, but you should not rely on it.
- Check which of the four deletion settings were active when the record was archived, and enter the address data, contact data, documents or photo again where they are missing.
- If the record keeps being picked up by automatic archiving, exclude it, either through the option in the restore dialog or through the member codes that the archiving configuration excludes.
If the record has already been anonymized, it cannot be recovered. In that case you have to create the member or prospect again from scratch.
Data protection and anonymization
Anonymization removes all personal data from an archived record and cannot be undone. The record stays in the system without personal data, so it can no longer be traced back to an individual.
There are three ways a record gets anonymized:
- Anonymize member as a single action on a row in the archived members list. Permission: Single member anonymization. You have to type the confirmation word into the dialog before it runs.
- Anonymize members as a bulk action in the archived members list, for the locations and the minimum archiving period you select. Permission: Bulk member anonymization.
- Automatic anonymization of archived records, if the switch Automatically anonymize members and leads is on in your archiving configuration. It is a separate switch from automatic archiving, with its own period, and it can be off entirely. Switching it on or off and changing its period needs the permission Manage automatic archiving and anonymization and a whitelist for the facility, not one of the two anonymization permissions above.
Automatic anonymization never runs immediately after archiving. A record becomes eligible at the earliest 93 days after it was archived, and beyond that the period configured in your own settings applies. Until a record is actually anonymized, Restore member keeps working. As of: 2026-08-17.
Automatic anonymization stays off until someone switches it on
In the archiving configuration under Settings / Studio / Privacy policy, on the tab Archiving and anonymization, the automatic anonymization consists of two elements that belong together:
- the switch Automatically anonymize members and leads, which turns the automatic run on and off, and
- the period field below it. Its label reads Period from the archiving to automatic anonymization: You enter a number there and pick the unit from the dropdown next to it, which offers Day(s), Week(s), Month(s) and Year(s).
The period field stays disabled as long as the switch is off, and it carries no prefilled value. There is therefore no default waiting time you could rely on. Automatic anonymization only ever runs with a period that someone has entered in your configuration, so read both elements there when you need to know whether it is active for your studio and after how long it takes effect.
Prospects and their own archiving settings
Prospects are archived and restored exactly like members, through the same archived members list and the same Restore member action.
Their automatic archiving is configured separately, though. In the archiving configuration prospects appear as leads and have their own area Archiving of leads with its own period, labelled Automatic archiving of leads after. That period counts from the creation date of the prospect, not from a contract end date, and it can be active or inactive independently of the archiving of former members.
Prospects are not archived automatically while they still have open appointments, active tasks, recent check-ins or unused benefits and passes.
Conditions that block archiving
Active contracts and outstanding receivables are the best known reasons why a record cannot be archived, but they are not the only ones. The software validates a longer list before it archives a member. Archiving is also blocked by, among others:
- open studio tasks for the member
- an active check-in
- appointments in the future
- an active dunning level or a transfer to debt collection
- the member still being referenced as a payer for someone else
- links as a legal representative
- entrance locks
- open vouchers or contingents
For automatic archiving, the period for former members starts after the end date of the last contract. The complete list of exclusion criteria is documented in the article on automatic archiving linked below.
Keeping a member out of automatic archiving
Those conditions are checked by the software. Beyond them you have two ways to protect a record yourself:
- Per record. Set the option Exclude from automatic archiving in the restore dialog, as described above. The record is then skipped by automatic archiving, while manual archiving stays possible at any time.
- Per member code. The archiving configuration holds the field Exclude the following member codes from automatic archiving. It is a multi-select, and the options it offers are the member codes configured in your own studio. Every member carrying one of the member codes listed there is left out of automatic archiving, which is the way to protect a whole group of members at once instead of one record at a time. Changing that list needs the permission Manage automatic archiving and anonymization and a whitelist for the facility.
You find that field in the configuration under Settings / Studio / Privacy policy, on the tab Archiving and anonymization, below the two period fields Automatic archiving of former members after and Automatic archiving of leads after and above the block of deletion settings.