Legal & Compliance
Data Retention Policy
How long Skoolfly keeps data and how it securely disposes of information no longer needed.
1. Policy Statement
Skoolfly retains information only for as long as reasonably necessary for the purposes for which it was collected, while meeting legal, regulatory, contractual and security requirements. This policy describes the retention schedule, legal holds and disposal arrangements.
2. Purpose
The purpose of this policy is to minimise data held, reduce the risk of misuse or breach, control storage costs, and support legal and compliance obligations by applying clear, documented retention rules.
3. Scope
This policy applies to all information stored by Skoolfly, including personal data, academic records, account data, logs, backups, and business records held in systems, third-party services or physical form.
4. Retention Principles
Retention periods are proportionate to the purpose of the data and legal requirements.
Data is deleted, anonymised or securely disposed of once it is no longer needed.
Retention decisions consider the rights of individuals and the expectations of schools.
Retention applies to primary data and, where relevant, backups and derived copies.
Where a school acts as the data controller, Skoolfly supports the school's retention instructions where lawful.
5. Retention Schedule
The following schedule provides indicative retention periods. Exact periods are confirmed in Skoolfly's documented retention schedule and may be adjusted to meet legal or contractual requirements.
6. Legal and Regulatory Holds
Where litigation, investigation, audit or other legal obligation requires information to be preserved, retention may be suspended by a legal hold. Held information is excluded from normal deletion until the hold is lifted, and access to held data is restricted to those who need it.
7. Secure Disposal
Information no longer required is disposed of securely using deletion, cryptographic erasure or shredding of physical media, as appropriate.
Deletion is confirmed where a service requires it, and disposal of sensitive media is witnessed or recorded where practical.
Disposal includes copies held in third-party services according to their terms.
8. Archival
Where information must be preserved for legal or historical reasons but is no longer actively used, it may be archived. Archived data is subject to access control and reviewed periodically to confirm its continued necessity.
9. Backups
Backups may contain data beyond primary retention periods for recovery purposes. Backups are retained for the minimum period needed for restoration, as set out in the Backup Policy, and are subject to the same security controls as primary data.
10. Roles and Responsibilities
11. Compliance and Enforcement
Compliance with this policy is monitored through reviews and audits. Non-compliance may result in corrective action, including disciplinary or contractual measures where appropriate.
12. Review
This policy and the associated retention schedule are reviewed at least annually, or when legal requirements, services or processing activities change significantly.
