Little Haven logo

Little Haven

Blockchain & AI — tested, not just taught

Data Retention Policy

Last Updated: November 6, 2024


1. Purpose and Scope

This Data Retention Policy describes how Little Haven collects, retains, archives, and deletes personal and operational data generated through the use of our platform at littlehaven.eu. This policy applies to all users, including registered learners, instructors, administrators, and visitors who interact with our services.

The purpose of this policy is to ensure that data is kept only for as long as necessary to fulfil the purposes for which it was collected, to comply with applicable legal obligations, and to protect the rights of individuals whose data we process.


2. Categories of Data We Retain

2.1 Account and Identity Data

This includes information provided during registration and account management, such as name, email address, contact details, and authentication credentials.

2.2 Learning and Assessment Data

This includes quiz results, test scores, progress records, completion certificates, performance history, and any responses submitted through interactive learning activities.

2.3 Usage and Technical Data

This includes log files, session identifiers, IP addresses, device and browser information, page interaction data, and platform analytics used to maintain and improve service quality.

2.4 Communication Data

This includes messages sent through platform contact forms, support tickets, email correspondence, and feedback submissions.

2.5 Payment and Billing Data

This includes transaction records, billing history, and related financial identifiers where applicable to paid services or subscriptions.

2.6 Content and Submissions

This includes user-generated content such as forum posts, uploaded files, assignment submissions, and any material contributed to the platform environment.


3. Retention Periods

Data Category Retention Period Basis for Retention
Account and identity data Duration of account plus 2 years after closure Service delivery, legal obligation
Learning and assessment data Duration of account plus 5 years after closure Educational record integrity, user access
Usage and technical data Up to 12 months from collection Security, performance monitoring
Communication data 3 years from last interaction Support continuity, dispute resolution
Payment and billing data 7 years from transaction date Financial compliance, audit requirements
Content and submissions Duration of account plus 1 year after closure Platform integrity, user recovery window
Anonymised and aggregated data Indefinite Research, analytics, service improvement

Retention periods begin from the date of collection unless otherwise specified. Where a range of purposes applies to the same data, the longest applicable retention period governs.


4. Criteria Used to Determine Retention Periods

Where specific periods are not defined by legal requirement, we determine appropriate retention durations based on the following criteria:


5. Account Closure and Data Deletion

5.1 Voluntary Account Closure

When a user requests account closure or deletion, we will initiate the deactivation of the account promptly. Personal data will be scheduled for deletion in accordance with the retention periods specified in Section 3. During any applicable retention window following closure, data will not be used for marketing or active service delivery.

5.2 Inactive Accounts

Accounts that have shown no activity for a continuous period of 36 months may be flagged for review. Users associated with such accounts will be notified via their registered email address prior to any deletion action. If no response is received within 30 days of notification, the account and associated data may be deleted in accordance with this policy.

5.3 Deletion Process

Deletion involves the permanent removal or irreversible anonymisation of personal data from active systems, backups, and archives within a technically reasonable timeframe. Residual copies held in backup systems will be deleted in the ordinary course of backup rotation cycles.


6. Data Archiving

Certain categories of data may be transferred to secure archival storage before final deletion. Archived data is isolated from active systems, access-restricted, and not used for operational purposes. Archiving is used where a legal hold, ongoing dispute, regulatory inquiry, or compliance obligation requires data to be preserved beyond standard retention periods.

Archived data is subject to the same security standards as active data and will be deleted as soon as the basis for archiving no longer applies.


7. Legal Holds and Extended Retention

In circumstances involving actual or anticipated legal proceedings, regulatory investigation, audit, or enforcement action, we may apply a legal hold to relevant data. A legal hold suspends the normal deletion schedule for the duration of the hold. Data subject to a legal hold will be retained until the matter is resolved and the hold is formally lifted, after which standard retention timelines will resume or deletion will proceed as appropriate.


8. Third-Party and Processor Data

Where personal data is processed by third-party service providers acting on our behalf, those providers are required to retain and delete data in accordance with our instructions and this policy. We maintain data processing agreements with such providers to ensure compliance. Third parties are not permitted to retain personal data beyond the periods specified in this policy unless separately required by their own legal obligations, in which case we require notification of such retention.


9. Anonymisation and Aggregation

Data that has been fully anonymised or aggregated such that no individual can be identified, directly or indirectly, is no longer considered personal data and falls outside the scope of this retention policy. Such data may be retained indefinitely for research, statistical analysis, platform improvement, and reporting purposes. We apply technical and organisational measures to ensure that anonymisation is robust and irreversible.


10. Security During Retention

All data retained under this policy is protected by appropriate technical and organisational security measures throughout its lifecycle. These measures include encryption at rest and in transit, access controls based on the principle of least privilege, regular security assessments, and audit logging of access to sensitive data categories. Security standards are maintained consistently whether data is held in active systems, backup environments, or archival storage.


11. Your Rights Regarding Retained Data

Subject to applicable law and any overriding retention obligations, individuals have the right to:

To exercise any of these rights, users may contact us using the details provided in Section 13. We will respond to requests within a reasonable timeframe and in accordance with our obligations. Where a request cannot be fulfilled due to a lawful retention requirement, we will explain the basis for continued retention.


12. Policy Review and Updates

This Data Retention Policy is reviewed periodically to ensure it remains accurate, current, and aligned with our operational practices and any changes in applicable requirements. Material changes to this policy will be communicated to registered users via email or platform notification prior to the changes taking effect. Continued use of the platform following such notification constitutes acceptance of the updated policy. The date at the top of this document reflects the most recent revision.


13. Contact Information

For questions, concerns, or requests relating to this Data Retention Policy or the handling of your personal data, please contact us through any of the following channels:


We use cookies to keep this platform running.

Little Haven collects usage data to improve quiz performance and learning paths. You control what we store — decline to limit data collection to essentials only.

Opt out of data sharing with third parties
See our cookie & data retention policy