Data Retention Policy

Comprehensive data management procedures for storage, archiving, and secure deletion in compliance with applicable regulations

Last Updated: September 2026

Policy Overview

POPS.GG (operated by CASH.BH LTD) maintains this Data Retention Policy to ensure compliance with applicable laws and regulations, including UK GDPR, the UK Data Protection Act 2018, and financial record-keeping requirements. We do not store payment card data; card payments are handled by our payment providers. This policy establishes clear procedures for the retention, archiving, and secure deletion of all data collected and processed during our business operations.

Policy Objectives

  • Legal Compliance: Meet all regulatory retention requirements for business records
  • Data Minimization: Retain only data necessary for legitimate business purposes
  • Privacy Protection: Implement secure deletion to protect individual privacy rights
  • Business Continuity: Maintain records necessary for operations and dispute resolution
  • Cost Efficiency: Optimize storage costs through appropriate retention schedules
  • Security: Apply appropriate security controls throughout data lifecycle

Legal & Regulatory Framework

UK & EU Regulations

  • GDPR (General Data Protection Regulation): Personal data retention limited to necessary period for processing purposes
  • UK Data Protection Act 2018: UK-specific data protection requirements
  • ePrivacy Directive: Electronic communications data retention requirements
  • Companies Act 2006: 6-year retention for accounting records and supporting documents
  • VAT Regulations: 6-year retention for VAT records

Payment Industry Standards

  • Payment Card Data: We do not store payment card data; card payments are handled by our payment providers.
  • Anti-Money Laundering Regulations: Customer due diligence records retained 5 years from the end of the relationship

Industry Best Practices

  • ISO 27001 information security management standards
  • NIST guidelines for data lifecycle management
  • ICO (Information Commissioner's Office) guidance on data retention

Data Retention Schedule

Customer Account Data

Account Information (Active Accounts)

Duration of business relationship + 7 years

Closed/Inactive Accounts

7 years from account closure

KYC/Verification Documents

5 years from the end of the relationship (AML requirement)

Marketing Consent Records

Duration of consent + 3 years

Legal Basis: Contract performance, legal obligation (AML), legitimate interests

Transaction & Financial Data

Payment Transaction Records

7 years (financial records requirement)

Invoices & Billing Records

7 years (accounting requirement)

Payment Card Data (PAN)

Not stored; card payments are handled by our payment providers

Chargeback/Dispute Records

7 years from resolution

Tax Records (VAT, etc.)

6 years (HMRC requirement)

Ad Campaign Financial Data

7 years from campaign end

Legal Basis: Legal obligation (financial regulations), contract performance

Advertising & Campaign Data

Ad Campaign Data

3 years from campaign end

Click/Impression Data

90 days (operational), 2 years (aggregated)

Ad Performance Metrics

3 years from campaign end

Publisher Feed Data

Current feed + 90 days

Legal Basis: Contract performance, legitimate interests (fraud prevention)

Technical & Security Data

System Logs

90 days (operational), 1 year (security events)

Security Incident Records

7 years from incident resolution

Audit Logs

7 years (compliance requirement)

Backup Data

Per original retention period

IP Addresses (Security)

90 days (operational), 2 years (fraud investigation)

Access Control Records

3 years from access termination

Legal Basis: Legal obligation (security), legitimate interests (system security)

Communication Records

Email Communications

3 years from last communication

Support Tickets

3 years from ticket closure

Contract Negotiations

Duration of contract + 7 years

Chat Logs

1 year from conversation

Legal Basis: Contract performance, legal obligation (dispute resolution)

Employee & HR Data

Personnel Files (Current)

Duration of employment + 6 years

Payroll Records

6 years (HMRC requirement)

Training Records

Duration of employment + 3 years

Unsuccessful Applications

1 year from application

Legal Basis: Legal obligation (employment law), contract performance

Legal & Compliance Data

Contracts & Agreements

Duration of contract + 7 years

Legal Claims/Litigation

7 years from resolution + limitation period

Compliance Reports

7 years from report date

Insurance Records

Duration of policy + 7 years

Legal Basis: Legal obligation, legitimate interests (legal claims)

Storage & Security Procedures

Active Data Storage

  • Location: Primary storage is on servers located in the United States, with UK GDPR transfer safeguards
  • Encryption: AES-256 encryption at rest, TLS 1.3 for data in transit
  • Access Controls: Role-based access control (RBAC) with least privilege principle
  • Backups: Daily full encrypted backups (AES-256) pushed off-site
  • Monitoring: Automated alerting

Database Security

  • Access: The database accepts local connections only; server access is by SSH key; backups are encrypted
  • Access Logging: Server and database access is logged
  • Separation: Production and development environments strictly separated

Data Classification

Highly Sensitive

Payment data, authentication credentials, personal identification documents

Additional encryption, minimal access, enhanced monitoring

Sensitive

Customer personal data, financial records, transaction history

Encryption required, restricted access, audit logging

Internal

Business records, internal communications, operational data

Access controls, standard security measures

Public

Marketing materials, public website content

Basic integrity controls

Archiving Procedures

Archive Criteria

Data is moved to archive storage when:

  • No longer required for active business operations
  • Retention period requires long-term storage (7+ years)
  • Data access frequency below defined threshold (less than once per quarter)
  • System capacity optimization required
  • Legal hold requires preservation beyond normal retention

Archive Storage

  • Location: Archived data is kept as encrypted backup files off-site
  • Encryption: AES-256 encryption maintained in archive
  • Indexing: Searchable metadata for retrieval without full data access
  • Integrity: Annual integrity verification and format migration as needed
  • Access: Restricted access with management approval and audit trail

Archive Retrieval

  • Request Process: Formal request with business justification required
  • Approval: Company director approval for archive access
  • Timeline: Standard retrieval within 24-72 hours
  • Documentation: All retrievals logged with purpose and accessing party
  • Temporary Access: Retrieved data returned to archive after use

Legal Hold Procedures

  • Immediate Suspension: Deletion suspended for data subject to legal hold
  • Preservation: Data isolated and preserved in immutable format
  • Documentation: Legal hold register maintained with scope and duration
  • Notification: IT and compliance teams notified of all legal holds
  • Release: Data returned to normal retention schedule upon hold release

Secure Deletion Procedures

Automated Deletion Process

  • Scheduled Reviews: Retention is reviewed periodically and expired data deleted
  • Verification: Check that no legal holds apply before deletion
  • Execution: Secure deletion executed during maintenance windows
  • Confirmation: Deletion completion verified and documented

Deletion Methods

Electronic Data:

  • Database Records: Data is deleted from the database and expired backups removed
  • Storage Media: The hosting provider is responsible for media sanitisation

Physical Media:

  • Hard Drives: Server storage is provided by our hosting provider, which is responsible for media sanitisation
  • Paper Records: Cross-cut shredding

Deletion Verification

  • Automated Verification: Scheduled scans to confirm deletion completion
  • Backup Validation: Verification data removed from all backup systems
  • Audit Trail: Complete log of what was deleted, when, and by whom
  • Sample Testing: Periodic sample testing to verify deletion effectiveness
  • Documentation: Deletion records maintained

Exceptions to Deletion

  • Legal Hold: Active litigation or regulatory investigation
  • Active Disputes: Ongoing chargebacks, complaints, or claims
  • Regulatory Review: Data subject to pending regulatory audit
  • Security Investigation: Data required for ongoing security incident investigation
  • Extended Retention: Data subject extended retention notice (e.g., statute of limitations)

Data Subject Rights (GDPR)

Individual Rights

Right to Erasure ("Right to be Forgotten")

Individuals may request deletion of their personal data. We respond within 30 days, subject to legal retention requirements.

Right to Access

Individuals can request copies of their personal data. We provide access within 30 days.

Right to Rectification

Individuals can request correction of inaccurate personal data.

Right to Restriction

Individuals can request we limit processing of their personal data.

Right to Data Portability

Individuals can request their data in machine-readable format.

Request Processing

  • Submission: Requests by email to info@pops.gg
  • Verification: Identity verification required before processing
  • Timeline: Response within 30 days (extendable to 60 days for complex requests)
  • Documentation: All requests logged and documented
  • Exceptions: Clear explanation provided if request cannot be fulfilled

Policy Governance

Roles & Responsibilities

  • Data protection lead (the company director): Overall policy oversight and UK GDPR compliance
  • IT Operations: Implementation of retention and deletion procedures
  • Compliance Team: Monitoring adherence to retention schedules
  • Legal Counsel: Review of retention periods and legal requirements
  • Department Heads: Ensuring team compliance with policy

Policy Review & Updates

  • Annual comprehensive policy review
  • Updates triggered by regulatory changes within 30 days
  • Periodic review of retention schedule effectiveness
  • Version control maintained for all policy versions
  • All material changes communicated to stakeholders

Training & Awareness

  • Annual data retention training for all staff
  • Specialized training for IT and compliance teams
  • New hire training during onboarding
  • Regular communications about retention requirements

Monitoring & Auditing

  • Periodic compliance checks
  • Annual internal review by the director
  • Non-compliance issues escalated and remediated promptly

Contact Information

Data Protection Inquiries

Data protection lead (the company director)

CASH.BH LTD

71–75 Shelton Street, Covent Garden
London, WC2H 9JQ, United Kingdom

Email: info@pops.gg

Data Subject Requests

To exercise your data subject rights (access, erasure, etc.):

Email: info@pops.gg

Requests by email to info@pops.gg

Supervisory Authority: Information Commissioner's Office (ICO)
If you are not satisfied with our response to your data protection concerns, you have the right to lodge a complaint with the ICO at ico.org.uk