Data Retention Policy
DATA RETENTION POLICY WITH SCHEDULE
of
Now Prototype It
Introduction
As part of the day-to-day running of our business, we collect and process personal data from a variety of sources. This personal information is collated in several different formats including emails, user accounts, uploaded prototypes, employment records. The personal data is stored both as a hard copy and in electronic form.
Aims of the policy
Our business will ensure that the personal data that we hold is kept secure and that it is held for no longer than is necessary for the purposes for which it is being processed. In addition, we will retain the minimum amount of information to fulfil our statutory obligations and the provision of services – as required by data protection legislation, including the General Data Protection Regulation (GDPR).
Retention
This retention policy (along with its schedule), is a tool used to assist us in making decisions on whether a particular document should be retained or disposed of. In addition, it takes account of the context within which the personal data is being processed and our business practices.
Decisions around retention and disposal are to be taken in accordance with this policy. As and when the retention period for a specific document has expired, a review is always to be carried out prior to the disposal of the document. This does not have to be time-consuming or complex. If a decision is reached to dispose of a document, careful consideration is to be given to the method of disposal.
Responsibility
- Natalie Carey is responsible for keeping this retention schedule up to date in order to reflect changing business needs, new legislation, changing perceptions of risk management and new priorities for our business.
- Natalie Carey is responsible for determining (in accordance with this Policy) whether to retain or dispose of
- specific documents.
- Natalie Carey may delegate the operational aspect of this function to Rahel Berman.
Disposal
Our business must ensure that personal data is securely disposed of when it is no longer needed. This will reduce the risk that it will become inaccurate, out of date or irrelevant.
The methods of disposal are to be appropriate to the nature and sensitivity of the documents concerned and include:
- Non-Confidential records: place in waste paper bin for disposal
- Confidential records: shred documents
- Deletion of Computer Records
- Cloud storage
- User account details
- Uploaded prototypes
The table below contains the retention period that we have assigned to each type of record. This will be adhered to wherever possible, although it is recognised that there may be exceptional circumstances which require documents to be kept for either shorter or longer periods.
Exceptional circumstances should be reported to Natalie Carey without delay.
Date created: 23 October 2024
Date of review: 23 October 2025
Appendix 1: Document retention schedule
User accounts
User accounts are considered to be active unless the user actively closes their account.
Records for closed accounts will be removed immediately from the active database, it will take up to 1 month for database backups to "age out" and be deleted. Database backups are part of our normal practice to allow us to recover from incidents such as data corruption or loss. We will keep a long-term list of user IDs that have requested full deletion to allow us to remove them immediately if a backup needs to be restored. The user ID is not chosen by the user and is not related to any personally identifiable information the user has provided.
The act of closing a user account will also remove all uploaded prototypes associated with that account.
Uploaded prototypes
Uploaded prototypes are considered to be active unless the user actively deletes them.
We know that the history of a prototype is part of its usefulness so we keep a full history of uploaded prototypes. If a prototype is no longer needed the user can remove it. When a prototype is removed it will be removed from the active database immediately, it will take up to 1 month for database backups to "age out" and be deleted. Database backups are part of our normal practice to allow us to recover from incidents such as data corruption or loss.
If the user stops paying for prototype hosting we will remove their prototype between 2 and 4 months of the last payment.
When a prototype is deleted either manually or automatically due to lack of payment all previous versions of that prototype will be deleted on the above schedule, in the same timeframe as the latest version.
Marketing records
Marketing records are considered to be active unless the user actively unsubscribes or emails are rejected multiple times in a row. When a user unsubscribes we will remove their email address from the active database immediately, it will take up to 1 month for database backups to "age out" and be deleted. Database backups are part of our normal practice to allow us to recover from incidents such as data corruption or loss.
It may take us up to one hour to remove the email address from all marketing lists so for that hour the user may receive any marketing emails we have already scheduled. They will not receive any further emails after that hour and will not receive any additional emails in that hour except for a confirmation of unsubscribing.