Information lifecycle and secure disposal

Data Retention
Policy.

This policy explains how long Pintop Technologies Limited retains different categories of personal data, when information should be deleted and when deletion may need to be temporarily suspended.

30D
12M
2Y
6Y
Collect
Retain
Delete

Keep information only while there is a reason to keep it.

The purpose of this policy is to support the storage limitation principle by defining how retention periods are determined and how information is disposed of when it is no longer required.

It applies to relevant personal data held by Pintop in electronic or physical form when Pintop acts as a data controller.

Where Pintop processes information on behalf of a client, retention is governed by the applicable commercial agreement, Data Processing Agreement, documented client instructions and relevant service configuration.

How retention periods are
determined.

A retention period should reflect the purpose of the information, applicable obligations and the risks connected to keeping or deleting it.

Processing purpose

Information is retained while it is reasonably required for the purpose for which it was collected.

Legal obligations

Applicable tax, employment, contractual, regulatory and record-keeping requirements are considered.

Claims and accountability

Records may be retained where they are reasonably required to establish, exercise or defend legal claims.

Secure disposal

Information that is no longer required is securely deleted, destroyed or anonymised using a method appropriate to the storage medium.

Retention schedule by
information category.

The periods below describe the expected retention approach for the listed categories, subject to applicable holds, contractual instructions and legal requirements.

Client and commercial records

Three categories
01

Client contracts

Agreements, order forms, service-level agreements, DPAs, NDAs, renewal records, termination records and related correspondence.

Relationship + 6 years
02

Billing and payment records

Invoices, receipts, payment confirmations, account statements and payment-dispute records.

6 years
03

Client business contacts

Names, roles, business contact details, correspondence and relationship history.

Relationship + 2 years

Prospects, marketing and website activity

Three categories
04

Prospect and lead information

Enquiries, demo requests, event contacts and related business-development correspondence.

2 years after last contact
05

Marketing and CRM information

Mailing-list records, communication choices, consent records and engagement history.

2 years after last engagement
06

Website analytics

Analytics identifiers, page activity and website-session information collected through approved analytics technology.

26 months

Workforce and recruitment records

Three categories
07

Employment records

Employment agreements, role records, performance information, leave records, training records and exit documentation.

Employment + 6 years
08

Payroll and statutory records

Payroll registers, payslips, PAYE records, pension records and applicable statutory contribution records.

6 years
09

Unsuccessful recruitment candidates

Applications, CVs, interview notes and recruitment correspondence for a completed recruitment exercise.

12 months

Operational and supplier records

Two categories
10

CCTV footage

Security-camera footage from Pintop-controlled premises where CCTV is installed and operating.

30 days
11

Supplier information

Supplier contacts, agreements, bank details, invoices and relationship-administration records.

Relationship + 6 years
Product-specific processing

MeVerify data follows a
limited handling model.

The retention approach for identity-verification information reflects the service architecture, contracted processing relationship and configuration applying to the implementation.

Verification requests
Identity attributes are transmitted to the relevant verification service for processing.
Verification results
The applicable result is returned to the client according to the service flow and agreement.
Technical request logs
Relevant operational logs may be retained for up to 90 days for support, troubleshooting and billing purposes.
Client-specific terms
The applicable DPA, service agreement and deployment configuration remain authoritative.
Secure disposal

Deletion should match the storage medium.

When a retention period expires, information is securely deleted, destroyed or anonymised using a method appropriate to the system, device or record involved.

Servers and cloud systems

Use approved deletion, purge, overwrite or cryptographic-erasure processes supported by the relevant platform.

Backup media

Allow information to expire through the approved backup lifecycle or use the provider’s documented deletion process where earlier deletion is supported.

Paper documents

Use cross-cut shredding or an approved secure document-destruction service.

Email and collaboration systems

Remove records from active mailboxes and apply the relevant archive, retention and deletion controls available in the service.

Computers and portable devices

Use secure device erasure, approved reformatting, cryptographic reset or physical destruction where reuse is not appropriate.

Temporary retention holds

Deletion may be paused where information must remain available.

A scheduled deletion may be suspended where the information is relevant to an active request, investigation, claim or other documented obligation.

A relevant data-subject request is still being handled.
Legal proceedings are anticipated, active or reasonably connected to the information.
A regulatory, compliance or law-enforcement investigation requires preservation.
An internal investigation requires the relevant records to remain available.

Retention requires
ongoing oversight.

Retention periods and disposal processes are reviewed as systems, contracts, legal obligations and business activities change.

Periodic review

Retention categories and periods are reviewed on a planned basis to confirm that they remain appropriate.

Legal and regulatory change

The schedule may be updated where applicable record-keeping or data-protection requirements change.

Operational change

New products, systems, processors, integrations or business processes may require updated retention and deletion arrangements.

Retention and deletion enquiries

Questions about how long information is retained?

Share the relevant account, product, relationship or information category so Pintop can route the enquiry appropriately.