Data Retention Policy
Comprehensive data management procedures for storage, archiving, and secure deletion in compliance with applicable regulations
Last Updated: September 2026
Policy Overview
POPS.GG (operated by CASH.BH LTD) maintains this Data Retention Policy to ensure compliance with applicable laws and regulations, including UK GDPR, the UK Data Protection Act 2018, and financial record-keeping requirements. We do not store payment card data; card payments are handled by our payment providers. This policy establishes clear procedures for the retention, archiving, and secure deletion of all data collected and processed during our business operations.
Policy Objectives
- Legal Compliance: Meet all regulatory retention requirements for business records
- Data Minimization: Retain only data necessary for legitimate business purposes
- Privacy Protection: Implement secure deletion to protect individual privacy rights
- Business Continuity: Maintain records necessary for operations and dispute resolution
- Cost Efficiency: Optimize storage costs through appropriate retention schedules
- Security: Apply appropriate security controls throughout data lifecycle
Legal & Regulatory Framework
UK & EU Regulations
- GDPR (General Data Protection Regulation): Personal data retention limited to necessary period for processing purposes
- UK Data Protection Act 2018: UK-specific data protection requirements
- ePrivacy Directive: Electronic communications data retention requirements
- Companies Act 2006: 6-year retention for accounting records and supporting documents
- VAT Regulations: 6-year retention for VAT records
Payment Industry Standards
- Payment Card Data: We do not store payment card data; card payments are handled by our payment providers.
- Anti-Money Laundering Regulations: Customer due diligence records retained 5 years from the end of the relationship
Industry Best Practices
- ISO 27001 information security management standards
- NIST guidelines for data lifecycle management
- ICO (Information Commissioner's Office) guidance on data retention
Data Retention Schedule
Customer Account Data
Account Information (Active Accounts)
Duration of business relationship + 7 years
Closed/Inactive Accounts
7 years from account closure
KYC/Verification Documents
5 years from the end of the relationship (AML requirement)
Marketing Consent Records
Duration of consent + 3 years
Legal Basis: Contract performance, legal obligation (AML), legitimate interests
Transaction & Financial Data
Payment Transaction Records
7 years (financial records requirement)
Invoices & Billing Records
7 years (accounting requirement)
Payment Card Data (PAN)
Not stored; card payments are handled by our payment providers
Chargeback/Dispute Records
7 years from resolution
Tax Records (VAT, etc.)
6 years (HMRC requirement)
Ad Campaign Financial Data
7 years from campaign end
Legal Basis: Legal obligation (financial regulations), contract performance
Advertising & Campaign Data
Ad Campaign Data
3 years from campaign end
Click/Impression Data
90 days (operational), 2 years (aggregated)
Ad Performance Metrics
3 years from campaign end
Publisher Feed Data
Current feed + 90 days
Legal Basis: Contract performance, legitimate interests (fraud prevention)
Technical & Security Data
System Logs
90 days (operational), 1 year (security events)
Security Incident Records
7 years from incident resolution
Audit Logs
7 years (compliance requirement)
Backup Data
Per original retention period
IP Addresses (Security)
90 days (operational), 2 years (fraud investigation)
Access Control Records
3 years from access termination
Legal Basis: Legal obligation (security), legitimate interests (system security)
Communication Records
Email Communications
3 years from last communication
Support Tickets
3 years from ticket closure
Contract Negotiations
Duration of contract + 7 years
Chat Logs
1 year from conversation
Legal Basis: Contract performance, legal obligation (dispute resolution)
Employee & HR Data
Personnel Files (Current)
Duration of employment + 6 years
Payroll Records
6 years (HMRC requirement)
Training Records
Duration of employment + 3 years
Unsuccessful Applications
1 year from application
Legal Basis: Legal obligation (employment law), contract performance
Legal & Compliance Data
Contracts & Agreements
Duration of contract + 7 years
Legal Claims/Litigation
7 years from resolution + limitation period
Compliance Reports
7 years from report date
Insurance Records
Duration of policy + 7 years
Legal Basis: Legal obligation, legitimate interests (legal claims)
Storage & Security Procedures
Active Data Storage
- Location: Primary storage is on servers located in the United States, with UK GDPR transfer safeguards
- Encryption: AES-256 encryption at rest, TLS 1.3 for data in transit
- Access Controls: Role-based access control (RBAC) with least privilege principle
- Backups: Daily full encrypted backups (AES-256) pushed off-site
- Monitoring: Automated alerting
Database Security
- Access: The database accepts local connections only; server access is by SSH key; backups are encrypted
- Access Logging: Server and database access is logged
- Separation: Production and development environments strictly separated
Data Classification
Highly Sensitive
Payment data, authentication credentials, personal identification documents
Additional encryption, minimal access, enhanced monitoring
Sensitive
Customer personal data, financial records, transaction history
Encryption required, restricted access, audit logging
Internal
Business records, internal communications, operational data
Access controls, standard security measures
Public
Marketing materials, public website content
Basic integrity controls
Archiving Procedures
Archive Criteria
Data is moved to archive storage when:
- No longer required for active business operations
- Retention period requires long-term storage (7+ years)
- Data access frequency below defined threshold (less than once per quarter)
- System capacity optimization required
- Legal hold requires preservation beyond normal retention
Archive Storage
- Location: Archived data is kept as encrypted backup files off-site
- Encryption: AES-256 encryption maintained in archive
- Indexing: Searchable metadata for retrieval without full data access
- Integrity: Annual integrity verification and format migration as needed
- Access: Restricted access with management approval and audit trail
Archive Retrieval
- Request Process: Formal request with business justification required
- Approval: Company director approval for archive access
- Timeline: Standard retrieval within 24-72 hours
- Documentation: All retrievals logged with purpose and accessing party
- Temporary Access: Retrieved data returned to archive after use
Legal Hold Procedures
- Immediate Suspension: Deletion suspended for data subject to legal hold
- Preservation: Data isolated and preserved in immutable format
- Documentation: Legal hold register maintained with scope and duration
- Notification: IT and compliance teams notified of all legal holds
- Release: Data returned to normal retention schedule upon hold release
Secure Deletion Procedures
Automated Deletion Process
- Scheduled Reviews: Retention is reviewed periodically and expired data deleted
- Verification: Check that no legal holds apply before deletion
- Execution: Secure deletion executed during maintenance windows
- Confirmation: Deletion completion verified and documented
Deletion Methods
Electronic Data:
- Database Records: Data is deleted from the database and expired backups removed
- Storage Media: The hosting provider is responsible for media sanitisation
Physical Media:
- Hard Drives: Server storage is provided by our hosting provider, which is responsible for media sanitisation
- Paper Records: Cross-cut shredding
Deletion Verification
- Automated Verification: Scheduled scans to confirm deletion completion
- Backup Validation: Verification data removed from all backup systems
- Audit Trail: Complete log of what was deleted, when, and by whom
- Sample Testing: Periodic sample testing to verify deletion effectiveness
- Documentation: Deletion records maintained
Exceptions to Deletion
- Legal Hold: Active litigation or regulatory investigation
- Active Disputes: Ongoing chargebacks, complaints, or claims
- Regulatory Review: Data subject to pending regulatory audit
- Security Investigation: Data required for ongoing security incident investigation
- Extended Retention: Data subject extended retention notice (e.g., statute of limitations)
Data Subject Rights (GDPR)
Individual Rights
Right to Erasure ("Right to be Forgotten")
Individuals may request deletion of their personal data. We respond within 30 days, subject to legal retention requirements.
Right to Access
Individuals can request copies of their personal data. We provide access within 30 days.
Right to Rectification
Individuals can request correction of inaccurate personal data.
Right to Restriction
Individuals can request we limit processing of their personal data.
Right to Data Portability
Individuals can request their data in machine-readable format.
Request Processing
- Submission: Requests by email to info@pops.gg
- Verification: Identity verification required before processing
- Timeline: Response within 30 days (extendable to 60 days for complex requests)
- Documentation: All requests logged and documented
- Exceptions: Clear explanation provided if request cannot be fulfilled
Policy Governance
Roles & Responsibilities
- Data protection lead (the company director): Overall policy oversight and UK GDPR compliance
- IT Operations: Implementation of retention and deletion procedures
- Compliance Team: Monitoring adherence to retention schedules
- Legal Counsel: Review of retention periods and legal requirements
- Department Heads: Ensuring team compliance with policy
Policy Review & Updates
- Annual comprehensive policy review
- Updates triggered by regulatory changes within 30 days
- Periodic review of retention schedule effectiveness
- Version control maintained for all policy versions
- All material changes communicated to stakeholders
Training & Awareness
- Annual data retention training for all staff
- Specialized training for IT and compliance teams
- New hire training during onboarding
- Regular communications about retention requirements
Monitoring & Auditing
- Periodic compliance checks
- Annual internal review by the director
- Non-compliance issues escalated and remediated promptly
Contact Information
Data Protection Inquiries
Data protection lead (the company director)
CASH.BH LTD
71–75 Shelton Street, Covent Garden
London, WC2H 9JQ, United Kingdom
Email: info@pops.gg
Data Subject Requests
To exercise your data subject rights (access, erasure, etc.):
Email: info@pops.gg
Requests by email to info@pops.gg
Supervisory Authority: Information Commissioner's Office (ICO)
If you are not satisfied with our response to your data protection concerns, you have the right to lodge a complaint with the ICO at ico.org.uk