Data Retention Policy
Last Updated: November 6, 2024
1. Purpose and Scope
This Data Retention Policy describes how Little Haven collects, retains, archives, and deletes personal and operational data generated through the use of our platform at littlehaven.eu. This policy applies to all users, including registered learners, instructors, administrators, and visitors who interact with our services.
The purpose of this policy is to ensure that data is kept only for as long as necessary to fulfil the purposes for which it was collected, to comply with applicable legal obligations, and to protect the rights of individuals whose data we process.
2. Categories of Data We Retain
2.1 Account and Identity Data
This includes information provided during registration and account management, such as name, email address, contact details, and authentication credentials.
2.2 Learning and Assessment Data
This includes quiz results, test scores, progress records, completion certificates, performance history, and any responses submitted through interactive learning activities.
2.3 Usage and Technical Data
This includes log files, session identifiers, IP addresses, device and browser information, page interaction data, and platform analytics used to maintain and improve service quality.
2.4 Communication Data
This includes messages sent through platform contact forms, support tickets, email correspondence, and feedback submissions.
2.5 Payment and Billing Data
This includes transaction records, billing history, and related financial identifiers where applicable to paid services or subscriptions.
2.6 Content and Submissions
This includes user-generated content such as forum posts, uploaded files, assignment submissions, and any material contributed to the platform environment.
3. Retention Periods
| Data Category | Retention Period | Basis for Retention |
|---|---|---|
| Account and identity data | Duration of account plus 2 years after closure | Service delivery, legal obligation |
| Learning and assessment data | Duration of account plus 5 years after closure | Educational record integrity, user access |
| Usage and technical data | Up to 12 months from collection | Security, performance monitoring |
| Communication data | 3 years from last interaction | Support continuity, dispute resolution |
| Payment and billing data | 7 years from transaction date | Financial compliance, audit requirements |
| Content and submissions | Duration of account plus 1 year after closure | Platform integrity, user recovery window |
| Anonymised and aggregated data | Indefinite | Research, analytics, service improvement |
Retention periods begin from the date of collection unless otherwise specified. Where a range of purposes applies to the same data, the longest applicable retention period governs.
4. Criteria Used to Determine Retention Periods
Where specific periods are not defined by legal requirement, we determine appropriate retention durations based on the following criteria:
- The nature and sensitivity of the personal data involved
- The purpose for which the data was originally collected
- Whether the user maintains an active relationship with the platform
- The potential risk of harm from unauthorised use or disclosure
- Applicable statutory limitation periods for legal claims
- Guidance from relevant regulatory or supervisory authorities
- Legitimate interests in maintaining accurate historical records
5. Account Closure and Data Deletion
5.1 Voluntary Account Closure
When a user requests account closure or deletion, we will initiate the deactivation of the account promptly. Personal data will be scheduled for deletion in accordance with the retention periods specified in Section 3. During any applicable retention window following closure, data will not be used for marketing or active service delivery.
5.2 Inactive Accounts
Accounts that have shown no activity for a continuous period of 36 months may be flagged for review. Users associated with such accounts will be notified via their registered email address prior to any deletion action. If no response is received within 30 days of notification, the account and associated data may be deleted in accordance with this policy.
5.3 Deletion Process
Deletion involves the permanent removal or irreversible anonymisation of personal data from active systems, backups, and archives within a technically reasonable timeframe. Residual copies held in backup systems will be deleted in the ordinary course of backup rotation cycles.
6. Data Archiving
Certain categories of data may be transferred to secure archival storage before final deletion. Archived data is isolated from active systems, access-restricted, and not used for operational purposes. Archiving is used where a legal hold, ongoing dispute, regulatory inquiry, or compliance obligation requires data to be preserved beyond standard retention periods.
Archived data is subject to the same security standards as active data and will be deleted as soon as the basis for archiving no longer applies.
7. Legal Holds and Extended Retention
In circumstances involving actual or anticipated legal proceedings, regulatory investigation, audit, or enforcement action, we may apply a legal hold to relevant data. A legal hold suspends the normal deletion schedule for the duration of the hold. Data subject to a legal hold will be retained until the matter is resolved and the hold is formally lifted, after which standard retention timelines will resume or deletion will proceed as appropriate.
8. Third-Party and Processor Data
Where personal data is processed by third-party service providers acting on our behalf, those providers are required to retain and delete data in accordance with our instructions and this policy. We maintain data processing agreements with such providers to ensure compliance. Third parties are not permitted to retain personal data beyond the periods specified in this policy unless separately required by their own legal obligations, in which case we require notification of such retention.
9. Anonymisation and Aggregation
Data that has been fully anonymised or aggregated such that no individual can be identified, directly or indirectly, is no longer considered personal data and falls outside the scope of this retention policy. Such data may be retained indefinitely for research, statistical analysis, platform improvement, and reporting purposes. We apply technical and organisational measures to ensure that anonymisation is robust and irreversible.
10. Security During Retention
All data retained under this policy is protected by appropriate technical and organisational security measures throughout its lifecycle. These measures include encryption at rest and in transit, access controls based on the principle of least privilege, regular security assessments, and audit logging of access to sensitive data categories. Security standards are maintained consistently whether data is held in active systems, backup environments, or archival storage.
11. Your Rights Regarding Retained Data
Subject to applicable law and any overriding retention obligations, individuals have the right to:
- Request confirmation of whether their personal data is being retained
- Request access to personal data held about them
- Request correction of inaccurate or incomplete data
- Request deletion of personal data where no lawful basis for continued retention exists
- Object to processing or request restriction of processing in certain circumstances
- Request a copy of their data in a portable format
To exercise any of these rights, users may contact us using the details provided in Section 13. We will respond to requests within a reasonable timeframe and in accordance with our obligations. Where a request cannot be fulfilled due to a lawful retention requirement, we will explain the basis for continued retention.
12. Policy Review and Updates
This Data Retention Policy is reviewed periodically to ensure it remains accurate, current, and aligned with our operational practices and any changes in applicable requirements. Material changes to this policy will be communicated to registered users via email or platform notification prior to the changes taking effect. Continued use of the platform following such notification constitutes acceptance of the updated policy. The date at the top of this document reflects the most recent revision.
13. Contact Information
For questions, concerns, or requests relating to this Data Retention Policy or the handling of your personal data, please contact us through any of the following channels:
- Email: contact@littlehaven.eu
- Phone: +1 519 579 2768
- Post: Little Haven, 6816 Andrew Ave, Summerland, BC V0H 1Z7, Canada
- Website: littlehaven.eu