How this schedule works
The platform keeps a retention policy for each kind of record. Every night a preview shows what is due, and a compliance officer applies it with a deliberate click. Records marked "reviewed by a person" are never deleted automatically — they are checked by hand each year because a law or contract sets their period. The table below is generated from the same rules the software enforces, so it cannot differ from what actually happens.
| Record | How long we keep it | What happens then | Why |
|---|---|---|---|
| Applications that were rejected or withdrawn without enrolment | 12 months after the decision | Anonymised automatically | Long enough to answer questions, complaints or a re-application; then name, contact details, date of birth and postcode are replaced so only anonymous counts remain. |
| Enrolled learner records: enrolment, attendance, assessments, certificates, funding evidence, placements | The funding year plus six years (seven years), reviewed by a person — never deleted automatically | Reviewed by a person | Funding contracts require evidence to be kept for audit; certificates must stay verifiable. |
| Invoices, payments, refunds and remittances | Six years after the end of the financial year they relate to, reviewed by a person | Reviewed by a person | HMRC and Companies Act record-keeping; card numbers are never held by us. |
| Staff records, pay history and payroll runs | Six years after employment ends, reviewed by a person | Reviewed by a person | HMRC and employment-law record keeping; defending claims. |
| Audit trail of who did what (references only, never form contents) | Seven years, reviewed by a person | Reviewed by a person | Evidence that records were handled correctly (funding audit, complaints, disputes). |
| Which version of our terms and policies you accepted, and when | Six years after your account closes, reviewed by a person | Reviewed by a person | Evidence of the terms that applied (the Limitation Act 1980 period for contract claims). |
| Marketing consent records and their history; unsubscribes | While you are on our records and then seven years; an unsubscribe (suppression) is kept permanently so we never contact you again by mistake | Reviewed by a person | Evidence of consent and opt-outs under PECR. |
| Who was sent each marketing email and what happened (address, outcome, unsubscribe link) | 24 months, then the address is removed and only counts remain | Anonymised automatically | Evidence of what was sent to whom and when. |
| Internal staff message threads after they are archived | 24 months, reviewed by a person | Reviewed by a person | Business records and employment disputes. |
| Contact-form messages | 12 months after the enquiry is closed | Deleted automatically | Long enough to follow up and handle a complaint about the reply. |
| Employer enquiries | 24 months after the enquiry is closed | Deleted automatically | Commercial follow-up. |
| Delivered and read notifications | 12 months | Deleted automatically | Proportionality — the underlying record is kept in its own module. |
| "Report a problem" reports and their session transcripts | 12 months | Deleted automatically | Debugging related issues and improving the service. |
| Driver check-in survey answers after a placement | 24 months | Deleted automatically | Evidence of the support given after placement. |
| Log of automated actions (record references and fixed reasons only) | 24 months | Deleted automatically | Audit of what the automation did. |
| Closed automation proposals (accepted, declined or superseded) — open ones are kept | 24 months after closing | Deleted automatically | Shows what was prepared and which person decided. |
| History of reports run by staff; scheduled report snapshots | 12 months (snapshots are cleared after 30 days) | Deleted automatically | Audit of report generation with minimal copies. |
| Expired or cancelled payment-page sessions | 90 days | Deleted automatically | Operational. |
| Processed internal system events (record references only) | 90 days | Deleted automatically | Operational. |
| Log of certificate look-ups (no personal data) | 24 months | Deleted automatically | Detecting misuse of the verification service. |
| Cookieless page-view counts (page template, referring site, device type) | 26 months | Deleted automatically | Service improvement; no identifiers are kept (the same-day hash is discarded daily). |
| Aggregate management statistics (counts only) | 6 years | Deleted automatically | Management information matching the longest funding record period. |
| Analytics processing run log | 12 months | Deleted automatically | Operational log. |
| Rate-limit counters (a salted one-way hash of the network address) | 24 hours | Deleted automatically | Security — preventing abuse of public forms. |
Other copies
- Backups of the database are kept by our hosting provider on a rolling basis and expire automatically; restored data is re-checked against this schedule.
- Error reports (Sentry), service logs (Better Stack) and optional analytics (PostHog) are kept by those processors for the period set in our account with them — [to be confirmed: processor retention settings]. Personal details are removed before error reports and logs are sent.
- Records needed for a legal claim, a funding audit, a safeguarding concern or an open complaint are kept until the matter is closed, even if the period above has passed (a legal hold).
Changes
Periods can only be changed by compliance staff, and every change is recorded. The Data Protection Lead reviews this schedule every September. Questions: [to be confirmed: privacy and data protection email address].
Change history
| Version | Date | Change | Acceptance needed again |
|---|---|---|---|
| 1.0 | First draft for legal review, written from the platform as built. | Yes — material change |