- Effective
- 2 August 2026
- Version
- 2.0.0
- Scope
- Corporate records, HostedTable, support systems, security logs and managed-service data
On this page
Data Retention & Deletion Schedule
These are default operational retention positions. A contract, legal hold, client configuration, regulator, dispute, backup cycle or technical dependency may require a different period.
1. Retention principles
We aim to retain personal data only for as long as necessary for service delivery, legal obligations, security, accounting, disputes, insurance and legitimate business records. Data may be anonymised instead of deleted where the result no longer identifies an individual.
2. Corporate records
| Record | Default period |
|---|---|
| Contracts, Orders, statements of work and material correspondence | Seven years after termination or completion |
| Invoices, payment and tax records | At least six years after the relevant accounting period, normally retained for seven years operationally |
| Sales enquiries not resulting in a contract | Up to 24 months after last meaningful contact |
| Support tickets and service records | 24 months after closure, or longer where linked to a contract, incident or claim |
| Security and access logs | Normally 12 months, subject to system capability and incident need |
| Audit logs for privileged actions | Normally 24 months or the duration stated by the Service |
| Suppression records | Minimal identifying information may be retained indefinitely to honour an objection or opt-out |
3. HostedTable and venue-controlled data
The venue determines retention for booking, guest, staff and workforce data as controller. Platform defaults may be configured by product or plan. Venue data may be retained after termination for a limited export and recovery period, then deleted from active systems.
We may retain limited account, billing, audit, security, complaint and legal records independently where necessary.
4. Backups
Backups are retained on rolling cycles that vary by service, typically between 30 and 90 days unless an Order states otherwise. Deletion from active systems does not immediately remove every backup copy. Backup data is isolated, overwritten through the normal cycle and not restored solely to retrieve a deleted individual record unless legally required and technically proportionate.
5. CCTV and surveillance
The Client determines footage retention according to its documented purpose. No single period is appropriate for every system. We may retain support exports or diagnostic images only as long as necessary for the instructed task, incident or legal requirement.
6. Equipment and asset records
Asset, warranty, serial, installation and maintenance records may be retained for the asset lifecycle plus seven years where needed for contract, insurance, safety or dispute evidence.
7. Legal holds
Deletion may be suspended where information is relevant to litigation, complaint, fraud, security investigation, insurance, regulator request or anticipated legal claim. Access will be restricted to the hold purpose.
8. Termination and export
Clients must request and verify exports before the termination date. We are not required to retain data indefinitely after service cessation. Bespoke extraction, restoration or conversion is chargeable.
9. Secure deletion
Deletion methods depend on storage technology and may include logical deletion, cryptographic erasure, overwrite, supplier deletion workflow or physical destruction. Immediate bit-level erasure from all distributed systems is not always technically possible.
Legal notices
Formal notices must be sent using the notice method stated in the applicable Order or through the authenticated customer portal. Where no method is stated, notices may be delivered to the registered office above. Operational support messages are not formal legal notices unless expressly identified as such.
Contracting entity: DM Digital UK Services Ltd, company number 17166861, registered office Hoults Yard, Mailing Exchange, Walker Road, Newcastle upon Tyne, NE5 2HL, United Kingdom.
