Draft for legal review
Data Retention Policy
Retention preferences can be configured by authorised administrators. Automatic anonymisation or deletion is not currently enabled. Data remains stored until an authorised and auditable retention process is implemented. The periods below are recommended defaults only and are not final.
Effective date: To be confirmed before public launch
Last updated: 28 July 2026
Version: Draft 0.1
Status: Draft for legal review
Operated by: Mohammad Asif, trading as PublicVoiceShield, United Kingdom
This document is provided for information only. It is not legal advice and no guarantee of compliance is given. Designed to support UK GDPR compliance, subject to organisational use, configuration and legal review.
Recommended defaults — awaiting approval
| Category | Recommended default |
|---|---|
| Active user accounts | Retained while the account is active. |
| Closed accounts | Configurable closure period, default 6 months, then removal from active systems. |
| Organisation records | Retained while the organisation is active plus the configured closure period. |
| Original posts and pasted comment threads | Configurable per organisation, default 24 months. |
| AI analyses and recommendations | Configurable per organisation, default 24 months. |
| Human decisions and audit records | Configurable, default 72 months, preserved as append-only records. |
| Authentication and security logs | Limited operational period, default 180 days. |
| Deleted organisations | Proposed: removal from active systems following an authorised human review. Not currently automated. |
| Backups | Proposed: deleted data removed from backups according to the backup lifecycle. Not currently automated. |
| Legal holds | Legal hold settings are recorded but will only be enforced once a formal retention workflow is implemented. |
Who can change these settings
Only organisation owners and administrators may change their organisation's retention settings. Ordinary team members cannot. Platform-wide policy versions are controlled by the platform owner.
Deletion and audit integrity
Automatic anonymisation or deletion is not currently enabled. Data remains stored until an authorised and auditable retention process is implemented. Human decision records are append-only so that AI advice can always be compared with the decision a person actually took.
Legal holds
Legal hold settings are recorded but will only be enforced once a formal retention workflow is implemented.
Questions
Contact [Privacy contact email — TO BE CONFIRMED].