Retention & Deletion Policy
How IPcom Limited reviews, retains, exports and deletes different categories of information.
Last updated: 3 October 2026
1. Principles
IPcom Limited keeps personal data only while it is needed for a documented purpose or legal obligation. Retention is reviewed when a purpose ends, during customer exit, following a valid rights request and at scheduled operational reviews. Legal holds, disputes and regulatory requirements may require a longer period, which must be recorded.
2. Retention schedule
| Record category | Normal trigger and period | Final action |
|---|---|---|
| Active customer CRM data | For the service term and documented exit window. | Return or export where requested, then delete or anonymise under the exit procedure. |
| Sales and demonstration enquiries | Review after 24 months without meaningful contact. | Delete or retain only a minimal suppression or legal record where justified. |
| Support communications | Review 24 months after closure or the end of the customer relationship, whichever is later. | Delete, anonymise or retain with a recorded legal justification. |
| Billing, invoice, payment and tax records | Normally six years from the relevant transaction or accounting period, and longer where an inquiry, claim or other legal requirement applies. | Secure deletion after the applicable obligation ends. |
| Security and administrative audit records | Review after 12 months; retain longer where needed to investigate an incident, demonstrate authorised actions or protect legal rights. | Delete or minimise identifiers when no longer required. |
| Marketing preferences and suppression records | While marketing continues and afterwards for as long as needed to respect an opt-out or demonstrate consent history. | Keep the minimum evidence needed; delete unrelated profile data. |
| Encrypted backups | Rotate under the configured backup schedule after primary deletion. Current hosting plans target 14 daily and four weekly recovery points. | Expire through controlled rotation; do not restore deleted data except for necessary disaster recovery. |
| GDPR purge certificates and essential audit evidence | Retain while needed to demonstrate fulfilment of the request and protect legal rights. | Keep only the minimum non-reversible evidence and review periodically. |
3. Secure deletion and review
Deletion must cover the live application, private files, connector copies under IPcom Limited's control and later-expiring backups. An authorised administrator records the decision, scope, exceptions and completion. Where deletion is not technically immediate, access remains restricted and the data is excluded from ordinary processing until it expires.