Retention Schedule
Version 1.0. Published 12 August 2026.
How long we keep each category of data, and why. Referenced by our Privacy Policy, Organisation Subscription Terms and Data Processing Agreement. Reviewed annually.
| Category | Retention | Notes |
|---|---|---|
| Account and profile data | Life of the account | Deleted on account closure; handle reserved 90 days to prevent impersonation, then released |
| Club membership records | Life of the club's subscription | On offboarding: exported or returned at the club's choice, personal data deleted within 30 days |
| Consent and withdrawal records | 2 years from withdrawal | Evidence of what was agreed and when |
| Safeguarding case records and audit trail | 2 years from case closure | Longer only where a live legal obligation requires |
| Criminal records check status (level, outcome, dates, flags) | While the individual holds the role | Removed on role end or club offboarding; never aggregated; no certificate content is ever held |
| Emergency medical notes | While membership is active and consent stands | Deleted on consent withdrawal or membership end |
| Payment metadata | Life of the club's subscription | No cardholder data is ever held |
| Email delivery log | 12 months | Delivery troubleshooting and audit; reviewed annually |
| Organisation contact information (directory) | Until objection, or 12 months after last source review | Objections honoured permanently via a minimal suppression record |
| Encrypted backups | Rolling rotation, maximum 90 days | Not restored except for disaster recovery |
| Anonymised aggregated statistics | Indefinite | Contain no personal data; governed by our Statistical Disclosure Control Policy |
| Junior profiles | Per the age-18 transition | Handover window 30-90 days at 18, or locked; guardian access ends at 18 |
| Legal, tax and company records | 6 years from end of financial year | Companies Act and HMRC obligations |