Governing policy · POL-10

Data Retention & Deletion Policy

Version 1.0 · effective 13 July 2026 · owner: Jonny Allum

OwnerJonny Allum (Data Protection Lead)
Version1.0 · Effective 13/07/2026 · Review annually (July)
Applies toAll data held by JonnyAI as controller and processor

1. Retention schedule

DataRetentionRationale
Tenant workspace data (processor)Life of subscription + 90 days grace after termination, then deleted (SOP-10). Export offered before deletion.Room to reactivate or export; then the processor duty to delete
Platform account data (controller)Life of account + 90 daysContract
Billing/invoice records6 years from end of financial yearUK tax law (HMRC company records)
Contracts, DPAs, engagement records6 years after terminationLimitation period
Prospect/CRM data2 years from last meaningful contact, then delete or re-permissionLegitimate interests, kept honest
Marketing consent records + unsubscribesLife of the list; suppression entries kept indefinitelyProof of consent; honouring opt-outs forever
Platform audit logs (C05) & operational eventsLife of tenancy (they belong to the tenant's record)Tenants' own compliance evidence
Server logs (Caddy/PM2)90 days rollingSecurity investigation window
Incident records6 yearsInsurance, diligence
BackupsProvider cycle (see SOP-06); deleted data ages out of backups within that cycleRestore capability without indefinite ghosts

The platform's own retention features (e.g. X10's 2-year waste-transfer retention, H10's 6-year HMRC vault suggestion) implement each tenant's retention duties inside their workspace — this policy governs JonnyAI's own copies and infrastructure.

2. Deletion standards

  • Deletion means removal from live systems within 30 days of the trigger, with backup copies expiring on the normal backup cycle.
  • Erasure requests (POL-02 §4) targeting specific individuals inside a tenant workspace are executed on the tenant's instruction, using targeted deletes, and confirmed in writing.
  • Decommissioned hardware is wiped (full-disk encryption + key destruction is sufficient).

3. The "keep less" rule

New features default to storing the minimum: derived values are computed at read time rather than duplicated (the platform's house pattern), and any new long-lived personal data field must justify itself in the feature's DPIA note (POL-02 §6).

← All documents & policiesQuestions? hello@jonnyai.co.uk