This Policy sets out the retention periods applied by AIAH Health Limited to personal and business records, in compliance with UK GDPR (storage limitation principle), the Data Protection Act 2018, and applicable statutory retention obligations.
1. Principles
- We keep personal data only for as long as necessary for the purposes for which it was collected.
- Retention periods are based on legal, regulatory, contractual and operational requirements.
- Data is deleted or irreversibly anonymised at the end of its retention period.
- Where legal holds apply (e.g. active litigation), retention is extended for the affected records until the hold is lifted.
2. Retention schedule
Customer and member accounts
- Active account profile: for the life of the account.
- Closed accounts: base profile deleted within 30 days of a verified deletion request; a minimal suppression record (email hash, closure reason) kept indefinitely to prevent re-onboarding under legal restrictions.
Health data
- Journals, cycles, symptoms, uploaded bloodwork and biomarker data: for the life of the account; deleted within 30 days of a verified deletion request, subject to backup rotation of up to 35 days.
- Clinical correspondence: 8 years from date of the last consultation (aligned with NHS records management guidance for adults).
Research data
- Consented research datasets: as set out in the applicable Participant Information Sheet, typically pseudonymised and retained for 10 years after study close.
- Consent records: retained for the same period as the underlying research dataset.
Marketing
- Prospect and marketing subscriber data: until unsubscribe or 3 years of inactivity.
- Suppression list: retained indefinitely to honour opt-outs.
Employees, contractors and applicants
- Recruitment records for unsuccessful applicants: 12 months from the end of the process.
- Employee personnel files: for the duration of employment plus 7 years.
- Right-to-work documentation: for the duration of employment plus 2 years (UK Home Office).
- Payroll and pension records: 6 years plus the current tax year (HMRC).
Financial records
- Accounting records, invoices and receipts: 6 years after the end of the accounting period (Companies Act 2006 / HMRC).
- VAT records: 6 years (HMRC).
Website and app analytics
- Aggregated analytics: up to 26 months.
- Server and application logs: 90 days for operational logs; 12 months for security-relevant logs.
Complaints, incidents and legal
- Complaints and disputes: 6 years from resolution.
- Personal data breach register: 6 years from the incident close.
- Contracts: 7 years from expiry or termination.
3. Secure deletion procedures
- Production database records are deleted using cascading deletes; where soft-delete is used, records are hard-deleted no later than 30 days after the initial deletion event.
- Backups: encrypted and rotated on a 35-day cycle; deleted data will not be restored to production and is purged from backups on the next full-cycle rotation.
- Object storage: deleted objects are marked for permanent removal and purged within 30 days.
- Paper records: cross-cut shredded and certified destroyed by an approved contractor.
- End-of-life devices: wiped to NIST SP 800-88 standards or physically destroyed with a certificate of destruction.
4. Legal holds and exemptions
The DPO may issue a legal hold suspending the routine deletion of specific records where required by law, regulatory investigation or litigation. Holds are documented and lifted when no longer required.
5. Review
This Policy is reviewed annually and on any material change in law, ICO guidance or our processing activities.