Personal information retention and deletion schedule
About this document
| Field | Value |
|---|---|
| Version | 1.0 |
| Effective date | 1 August 2026 |
| Publication date | 1 August 2026 |
| Last reviewed | 18 July 2026 |
| Status | Approved public document |
Version history
| Version | Effective date | Change summary | How this version applies |
|---|---|---|---|
1.0 | 1 August 2026 | Initial public version | Applies with the Privacy Notice; no separate acceptance is required |
1. Principles
Alessia keeps personal information only for as long as reasonably necessary for the purposes described in our Privacy Notice, to provide the Service, meet legal and regulatory duties, resolve disputes and enforce agreements. When the applicable period ends, we delete the information, irreversibly anonymise it where appropriate, or restrict and isolate it while a documented legal hold applies.
Backup copies expire through their separate rotation cycle. If a backup is restored, applicable deletion instructions are reapplied before normal use.
The periods in section 2 reflect, among other things: the six-year limitation period for contract and most civil claims and the twelve-year period for deeds (Limitation Act 1980, sections 2, 5 and 8); company and tax record-keeping duties (Companies Act 2006 and HMRC requirements, generally six years from the end of the relevant financial year; seven years from year end is Alessia's chosen policy buffer, not a statutory requirement); and regulatory expectations for evidencing consent, rights requests and complaints handling. Where no statutory period applies, the period reflects a documented business need.
2. Retention periods
| Record/category | Controller/context | Standard retention period | End action |
|---|---|---|---|
| Active individual account and portfolio | Individual professional normally controller and Alessia processor for User Content; Alessia controller for account/operational records | While the account remains active or its trial, subscription or paid service period remains current | Continue retaining the account and portfolio to provide the Service under the applicable role |
| Portfolio entry pending re-identification review, including a suspected direct identifier | Controller depends on the account | No separate automatic-deletion period applies merely because the entry is pending. It follows the active/expired account or Institution Customer Data period, an earlier valid deletion instruction, or a documented incident restriction or legal hold | Keep the entry access-controlled and marked for review; show a persistent in-app review indicator; do not send reminder emails solely because it remains pending. An elevated combination may be acknowledged or remediated as permitted by the workflow. A suspected direct identifier must be removed and re-evaluated and cannot be cleared by acknowledgement alone. Delete the entry under the ordinary account, Institution or incident rule |
| Expired individual account and portfolio | Individual professional normally controller and Alessia processor for User Content; Alessia controller for account/operational records | Read-only/export for exactly 90 days from trial/subscription expiry, including non-converting trials that contain portfolio data | Delete from live Service at day 90 unless renewed or subject to a documented legal hold/retention duty |
| User-requested account deletion | Individual professional instruction for User Content; Alessia controller for account/operational records | Access is revoked immediately and confirmation is sent. Live-database deletion is completed within 3 days, subject to identity verification and applicable legal, security or dispute-related exceptions | Delete/anonymise the live account and portfolio; retain only required records and expire backups under their separate cycle |
| Institution Customer Data | Institution controller; Alessia processor | Contract term plus negotiated read-only/export period in Order Document; default 90 days | Return/delete on instruction; deletion default after exit period |
| Departed Institution member | Institution controller | Institution-configured/contracted period; account may become read-only without transfer to individual account | Institution-directed restriction/deletion |
| Live deleted entries/files | Controller depends on account | Remove access immediately; complete the ordinary public-product live deletion job within 3 days | Delete from live database/object storage and derived indexes |
| Consumer rolling backups and replicas | Individual professional normally controller and Alessia processor for User Content; Alessia controller for its own records | Up to 35 days after live deletion | Expire by rotation; restore procedure re-applies deletion |
| Institution rolling backups and replicas | Institution controller; Alessia processor | Contracted period from 35 days to 7 years depending on the Institution's lawful preference and deployment | Expire by rotation; restore procedure re-applies deletion |
| Account-export ZIP file/link | Controller depends on account | 3 days after generation | Delete generated export and revoke token; underlying entries follow account rule |
| PDF/report response | Controller depends on account | Generated inline for the owning authenticated user; no persistent Alessia sharing link or stored report by design | Response completes; underlying entries follow account rule |
| Audio selected for transcription | Controller depends on account | User-kept source follows portfolio retention. The temporary transcription job and provider file copy follow the deletion and expiry period published in the Subprocessor List | Delete or expire the temporary provider copy; an approved transcript saved by the user follows portfolio retention |
| AI prompt/request and returned draft | Controller depends on account | Provider-side inputs and outputs follow the current period published in the Subprocessor List; an approved output saved by the user follows portfolio retention | Provider deletion or expiry; retain in Alessia only content the user chooses to save |
| Product analytics events | Alessia controller or Institution processor as configured | Maximum 365 days from event while identifiable | Delete or approved aggregation/anonymisation |
| Public application/security logs | Alessia controller | 90 days; longer only under a documented active investigation/legal hold | Delete/aggregate |
| Institution portfolio audit log | Institution controller | 365 days by default; Order Document may specify another supported period | Return/delete with Customer Data unless legally required |
| Shared operational logs | Alessia controller/processor | 90 days by default; longer only under a documented active investigation/legal hold | Delete/aggregate |
| Supervisor, assessor or colleague transparency email, notice evidence and no-contact suppression | Individual professional or Institution controller and Alessia processor for portfolio/notice records; Alessia controller for minimum service-wide individual-account suppression/abuse prevention | Processor-held raw professional email: until successful notice delivery or no more than 30 days after first attempted delivery for retries and bounce handling. The email provider's delivery copy follows the current period in the Subprocessor List. Minimum protected notice evidence: 3 years after successful delivery or the final attempt, subject to a shorter controller instruction or documented legal requirement. Upheld no-contact suppression: while the relevant account or relationship remains active or until the objection is withdrawn | Never include the email in portfolio reports. Remove the raw address from the portfolio and notification system when delivery/retry use ends. At evidence expiry, delete the protected recipient identifier, controller, notice version, date and delivery result. Apply the minimum Alessia-controlled suppression across individual-account controllers. Scope Institution-controlled suppression separately for each Institution and follow its instructions. The suppression record contains only a protected email identifier and scope and is deleted when its purpose ends |
| Identity, authentication and access-provider records | Alessia controller/processor | Identity records are retained for the account life; provider authentication and access logs follow the current period published in the Subprocessor List | Delete the identity/provider mapping and revoke linked access on account deletion |
| Push-notification token and delivery events | Alessia controller/processor | Device and push tokens are retained while notifications and the account remain enabled. Delivery-event records follow the current period published in the Subprocessor List | Unlink or delete the token when notifications are disabled, on logout where applicable, or when the account is deleted; delivery records then expire under the published provider period |
| Subscription, entitlement and transaction-provider events | Alessia controller | Subscription and entitlement records are retained while needed to manage the subscription. Alessia's required transaction, accounting and tax records follow the seven-year financial-record period. Service-provider and app-store records follow the periods and independent legal duties described in the Subprocessor List and the provider's applicable terms | For requested account deletion, cancel direct-web renewal and delete the subscription-management provider's customer profile within the three-day live-deletion target. Retain only required cancellation, transaction, accounting and tax records. A later store-entitlement restoration does not restore deleted account or portfolio data |
| Subscription, invoices, tax and accounting | Alessia controller | 7 years from the end of the relevant financial year; longer only where required by law, an audit/enquiry, a transaction spanning periods or documented legal hold | Delete/minimise at expiry |
| Direct web payment tokens/references | Alessia controller; approved merchant of record handles card data | While needed for the subscription; required transaction records follow the seven-year financial/tax period | Delete provider token where the account/payment relationship ends |
| App-store transaction records | Alessia, store and subscription-provider respective roles | Provider rules; Alessia's required transaction records follow the seven-year financial/tax period | Delete/minimise Alessia copy |
| Support and ordinary enquiry records | Alessia controller | 24 months after closure; a documented legal hold may extend only the necessary material | Delete/minimise the ticket; delete screenshots, diagnostic exports and other attachments as soon as no longer needed and no later than 90 days after closure |
| Complaint, dispute and legal-claim file | Alessia controller | 6 years after final closure. Retain necessary material longer only while proceedings, an appeal, regulator enquiry, insurer requirement, longer applicable limitation period or documented legal hold remains active; formally review a hold at least every 6 months | Delete/minimise when the period and any hold end; anonymous trends may be retained while useful |
| Privacy rights request and identity-verification evidence | Alessia controller/processor | Minimised case record: 3 years after completion. Identity-document copies: delete promptly and no later than 30 days after verification. Generated disclosure/response bundles and temporary exports: delete within 30 days after confirmed delivery. Documented legal hold/regulator need may extend only necessary evidence | Delete/minimise at expiry; retain only justified method, outcome, search/action and response evidence |
| Minimised security/privacy/clinical-safety incident file | Alessia controller/processor | 6 years after closure; longer only for a documented investigation, insurer/regulator requirement or legal hold | Delete/minimise at expiry |
| Raw incident logs, screenshots, exports and affected content | Role assessed per incident | Delete as soon as no longer necessary and no later than 90 days after closure; longer only for a documented investigation, insurer/regulator requirement or legal hold | Securely delete and record confirmation in the incident file |
| Suspected prohibited patient data | Role assessed per incident | Quarantined only for the shortest period reasonably necessary to contain and investigate the incident, meet any notification or evidence-preservation duty, and securely delete the information. The exact period depends on the incident | Delete the patient information as soon as permitted. Retain only a minimised non-content incident record where necessary under the separate incident-record period |
| Marketing prospect/contact | Alessia controller | Active account: while the single marketing choice remains valid. Newsletter-only lead or former user: until withdrawal/objection/unsubscribe, bounce/invalid address, or 24 months without a marketing-link click, reply, enquiry, purchase, preference update or renewed opt-in. Email opens and product use alone do not refresh the period | Stop promptly; delete/anonymise the marketing profile or retain only the minimum suppression record |
| Marketing suppression record | Alessia controller | As long as reasonably needed to honour an unsubscribe, withdrawal or objection and prevent accidental recontact | Retain only email address or hash, opt-out date, scope and source |
| Cookie, analytics and marketing-choice evidence | Alessia controller | Keep the current minimal evidence while processing relies on the choice, then 3 years after withdrawal, supersession or the related processing ends. Keep master wording, banner/configuration and notice versions for 7 years | Automatically delete individual evidence at expiry; preserve a separate minimum marketing-suppression record where applicable |
| Executed customer, Institution and supplier contracts | Alessia controller | Contract term plus 7 years after termination or expiry | Delete/minimise at expiry |
| Contracts executed as deeds | Alessia controller | 12 years after termination or expiry, or longer where applicable | Delete/minimise at expiry |
| Supplier security and privacy due diligence | Alessia controller | Active supplier relationship plus 7 years | Delete/minimise at expiry |
| Unsuccessful proposals and procurement records | Alessia controller | 2 years after the opportunity or procurement closes | Delete/minimise at expiry |
| Routine non-marketing business contacts | Alessia controller | Active relationship plus 2 years | Delete/minimise at expiry |
| Constitutional and statutory company records | Alessia controller | Permanently or for the period required by applicable company law | Preserve in controlled corporate record storage; review copies and superseded working material |
| Genuinely anonymous information, aggregate statistics and approved model artefacts derived only from them | Not personal information after approved anonymisation and model-risk assessment | May be retained while useful, including after deletion of the source account or content | Review periodically; delete when obsolete |
3. Deletion workflow
When the applicable retention period ends, or we receive a valid deletion request or Institution instruction, we delete or irreversibly anonymise the information and require relevant service providers to do the same.
Backup copies are removed through their normal rotation cycle. We may retain a minimal record where necessary to show that the deletion request or instruction was completed.
4. Legal holds and exceptions
We may retain necessary information beyond the standard period where required for tax or accounting duties, legal proceedings, a regulatory request, a security or fraud investigation, insurance requirements, or the establishment, exercise or defence of legal claims.
While that exception applies, access and use are restricted to the relevant purpose. When the reason for extended retention ends, the normal deletion or anonymisation process resumes.
5. Institution configuration
Retention for Institution-controlled information is set by the Institution's Order Document and instructions. This may include member and leaver access, the post-termination export period, backup and audit-log periods, deletion timing and any agreed assistance.
If an Institution requests a period that is not legally or technically available, Alessia and the Institution must agree a supported alternative before the relevant service begins.
6. Review and evidence
We review this schedule at least annually and whenever a material change to our services, information handling or legal obligations may affect a retention period. Material updates are dated and recorded in the version history above.
