Data Retention Policy
Last updated: November 17, 2024
This Data Retention Policy describes how Core One collects, stores, and removes personal and operational data generated through the use of our services. By using our services, you acknowledge the practices described in this document.
1. Purpose and Scope
This policy applies to all data collected and processed by Core One in connection with the delivery of its online services. It covers data held in digital systems, databases, backup archives, and any third-party infrastructure used to support service delivery.
The purpose of this policy is to ensure that data is retained only for as long as necessary to fulfil the purposes for which it was collected, to meet applicable legal and contractual obligations, and to support the legitimate interests of our clients and our organisation.
2. Types of Data We Retain
2.1 Account and Identity Data
Information provided during registration or onboarding, including name, email address, contact details, and account credentials. This data is retained for the duration of the active account relationship and for a defined period following account closure.
2.2 Service Usage Data
Records of interactions with our platform, including session logs, feature usage, and activity histories generated during the delivery of personalised services. This data supports service continuity and quality improvement.
2.3 Communication Records
Correspondence exchanged between clients and specialists through our platform, including messages, session notes, and feedback submissions. These records are retained to support ongoing service delivery and dispute resolution.
2.4 Billing and Transaction Data
Financial records associated with service purchases, invoices, payment confirmations, and refund histories. Billing data is subject to extended retention periods to meet financial recordkeeping requirements.
2.5 Technical and Diagnostic Data
System-generated data including error logs, performance metrics, IP addresses, and device information collected for security monitoring and platform maintenance purposes.
3. Retention Periods
Retention periods are determined by the nature and purpose of the data. The table below provides a general overview of standard retention timeframes applied across data categories.
| Data Category | Retention Period | Basis for Retention |
|---|---|---|
| Account and Identity Data | Duration of account plus 3 years | Contractual obligation and legitimate interest |
| Service Usage Data | 2 years from date of activity | Service improvement and continuity |
| Communication Records | Duration of account plus 2 years | Contractual obligation and dispute resolution |
| Billing and Transaction Data | 7 years from transaction date | Financial recordkeeping requirements |
| Technical and Diagnostic Data | 12 months from collection | Security monitoring and platform integrity |
| Marketing Preferences | Until withdrawal of consent | Consent-based processing |
| Support and Enquiry Records | 3 years from case closure | Legitimate interest and quality assurance |
These periods represent standard practice. In specific circumstances, data may be retained beyond these periods where required by a legal obligation, regulatory authority, or ongoing legal proceedings.
4. Data Storage and Security
All retained data is stored using industry-standard security measures, including encryption at rest and in transit, access controls, and regular security assessments. Access to retained data is restricted to authorised personnel who require it to perform their role.
Backup copies of data may exist within our infrastructure for a period beyond the primary retention window. Such backups are subject to scheduled deletion cycles and are not accessible for operational use once the primary data has been marked for deletion.
5. Data Deletion and Anonymisation
Upon expiry of the applicable retention period, data is either permanently deleted or anonymised so that it can no longer be associated with an identifiable individual. The method applied depends on the technical nature of the data and the systems in which it is held.
Anonymised data that cannot be re-linked to an individual may be retained indefinitely for aggregated analytical purposes, including service development and statistical reporting.
5.1 Deletion Requests
Individuals may request the deletion of their personal data prior to the expiry of the standard retention period. Such requests will be assessed in accordance with applicable rights and any overriding legal or contractual obligations that require continued retention. Where deletion cannot be completed in full, we will communicate the reasons clearly.
5.2 Account Closure
Upon closure of an account, data associated with that account enters a post-closure retention phase as described in Section 3. During this phase, data is not accessible for active use but is preserved for the purposes outlined in this policy. Following the post-closure period, deletion or anonymisation is applied.
6. Third-Party Data Processors
Core One engages third-party service providers to support platform operations, including hosting, payment processing, and communication infrastructure. These providers process data on our behalf and are contractually required to retain and delete data in accordance with standards consistent with this policy.
We do not authorise third-party processors to retain data beyond the periods necessary to fulfil their designated function, and we conduct periodic reviews of processor compliance.
7. Cross-Border Data Transfers
As an online service operating across multiple regions, data processed by Core One may be transferred to and stored in locations outside the country in which a client resides. Where such transfers occur, appropriate safeguards are applied to ensure that data receives a level of protection consistent with this policy regardless of geographic location.
8. Review and Updates to This Policy
This policy is reviewed periodically to reflect changes in our services, technology, and applicable standards. Where material changes are made, affected users will be notified through the platform or by direct communication. The date at the top of this document reflects the most recent revision.
Continued use of our services following notification of changes constitutes acceptance of the updated policy.
9. Contact Us
If you have questions about this policy, wish to exercise a data-related right, or need to report a concern regarding data retention practices, please contact us using the details below.