This policy sets out how Sprint Enterprise Technology Ltd ("Sprint") retains and disposes of personal data and business records in accordance with applicable UK data protection and privacy legislation, including the UK GDPR, the Data Protection Act 2018, PECR and the Data (Use and Access) Act 2025, as amended from time to time.
This policy applies to all personal data and business records processed by Sprint in any format, including electronic, paper and other media. It applies both where Sprint acts as a data controller and where Sprint acts as a data processor on behalf of its customers. Where Sprint acts as a data processor, the applicable customer contract, data processing agreement and documented controller instructions will take precedence over the default retention periods set out in this policy to the extent of any inconsistency.
This policy operates alongside Sprint's internal data protection and information security policies, which govern access control, asset management and secure disposal in more detail.
Sprint does not keep personal data for longer than necessary. Data is deleted or anonymised when it is no longer required, and holdings are reviewed regularly.
Retention periods are determined by legal obligations, legitimate business interests, and the principle of data minimisation.
All personal data is securely destroyed when its retention period expires, in line with Sprint's asset management and disposal procedures.
Sprint maintains appropriate records of retention decisions, approved extensions, legal holds, data disposal activities and compliance reviews to demonstrate compliance with applicable data protection and privacy laws. Such records must be accurate, retained securely and made available to authorised personnel for audit, regulatory or compliance purposes where required.
| Data category | Retention period | Legal basis | Disposal method |
|---|---|---|---|
| Active customer data & usage | Duration of contract + 60 days | Contract performance | Secure deletion from all systems |
| Customer instance data | 60 days post-contract end | Contract performance | Secure deletion (all systems & backups) |
| Customer contracts | 6 years after contract end | Limitation Act 1980 | Secure deletion |
| Customer invoices & payment records | 7 years after transaction | HMRC requirements | Secure deletion |
| Customer support communications | Duration of contract + 5 years | Legitimate interests | Secure deletion |
| Customer contact (active) | Duration of contract | Legitimate interests (CRM) | Updated or deleted within 30 days of notification that the individual has left or that the contact details are inaccurate |
| Customer contact (former staff) | 30 days from notification or contract end (whichever is sooner) | Data minimisation | Secure deletion |
| Anonymised statistical data | Indefinite | Legitimate interests | N/A - anonymised |
Contract termination. All external logins are disabled on the contract expiry date, and all customer instance data is deleted within 60 days.
When a customer's employee leaves. System access is disabled immediately; login credentials are deleted within 14 days; contact details are updated or deleted within 30 days; and support history is retained for the duration of the contract plus 5 years.
| Data category | Retention period | Legal basis |
|---|---|---|
| Employment contracts & HR records | 7 years after employment ends | Legal obligation |
| Payroll & tax records (P45, P60, P11D) | 7 years after tax year end | HMRC requirements |
| Right to work documents | 2 years after employment ends | UK immigration law |
| Recruitment records (unsuccessful applicants) | 6 months after decision | Legitimate interests |
Disposal is by secure shredding or deletion, in line with Sprint's asset management and disposal procedures.
| Data category | Retention period | Legal basis |
|---|---|---|
| Annual accounts | Permanent (company lifetime + 6 years) | Companies Act 2006 |
| Bank statements & invoices | 7 years | HMRC requirements |
| VAT & tax records | 6 years from accounting period end | HMRC requirements |
| Data category | Retention period |
|---|---|
| Supplier contracts | Duration + 6 years |
| Data processing agreements | Duration + 6 years |
| Professional indemnity insurance | Permanent |
| IP records & shareholder agreements | Permanent |
| Board minutes | Permanent |
Certain corporate governance, ownership and professional indemnity records are retained permanently because they may be required to evidence Sprint's legal existence, ownership, governance, intellectual property rights, insurance history and compliance with legal obligations. These categories are therefore exempt from the standard retention periods that apply to operational records.
| Data category | Retention period |
|---|---|
| Marketing consent records | Duration of consent + 2 years |
| Marketing suppression lists | Indefinite |
| Consented email lists | Until consent withdrawn + 30 days |
| Prospect data (no consent) | 2 years from last contact |
| Data category | Retention period |
|---|---|
| Access & authentication logs | 12 months |
| Security incident logs | 7 years |
| System backup data | 30 days (rolling) |
| Vulnerability & penetration test records | 3 years |
| Data breach records | 7 years |
Technical security controls are governed by Sprint's internal information security policies.
For the Fastrak and Finio platforms, Sprint acts as a data processor on behalf of its customers, who are the data controllers. Sprint acts only on the documented instruction of the data controller.
Where Sprint processes personal data as a processor, the applicable customer contract, data processing agreement and documented controller instructions take precedence over the default retention periods set out in this policy to the extent of any inconsistency. Sprint will not retain controller data for its own purposes unless it has separately identified and documented a lawful basis for doing so in its capacity as a controller.
The retention periods set out in section 3.1 are intended to describe Sprint's standard operational practices and do not limit any obligation to return, delete or retain personal data in accordance with a customer contract, data processing agreement, documented controller instruction or applicable law.
| Scenario | Data subject | Retention / action | Who can instruct |
|---|---|---|---|
| Platform access termination | Platform end-users | Access ceases immediately; logs retained 12 months | Data controller only |
| Individual firm data feed | Firm's clients | Feed ceases immediately | Controller or authorised third-party service provider |
| Individual end-user deletion | Individual investor | Request forwarded to controller within 48 hours; data deleted within 14 days of receiving a valid controller instruction | Data controller only |
| Customer employee contact | Platform employee | Updated or deleted within 30 days of notification | Controller or verified individual |
Key principles
Where Sprint receives a request directly from an individual end-user:
Sprint does not make deletion decisions about controller data. Only the data controller can instruct deletion.
Where legal proceedings are anticipated, deletion of the relevant data is suspended, the hold is documented, and normal retention resumes only when the hold is lifted.
Process. A written request for any retention extension must be submitted to the Data Protection Officer, together with the justification and proposed duration of the extension. The Data Protection Officer will assess the request against applicable legal, regulatory and business requirements and may approve the extension where justified. All approved extensions must be documented, assigned a review date and reassessed at least annually to confirm that the justification for continued retention remains valid. Any extension that is no longer justified will be withdrawn and the relevant data deleted in accordance with this policy.
Sprint monitors and demonstrates compliance through:
Non-compliance - retaining data for too long, or disposing of it too early - is treated as a potential data protection breach and reported to the Data Protection Officer.
This policy is reviewed annually by the Data Protection Officer and additionally following changes to applicable law, relevant ICO guidance, significant court or regulatory decisions, retention-related incidents, or significant changes to Sprint's business or processing activities.
Data Protection Officer
Email: data.protection@sprintenterprise.co.uk
Contract termination (Fastrak / Finio) Delete: instance data 60 days post-expiry. Keep: contracts (6 years), invoices (7 years), anonymised statistics. See section 5.1.
Platform access termination Delete: access ceases immediately; logs retained 12 months. Instruction: data controller only.
Individual end-user deletion request Sprint action: forward to the controller within 48 hours and await instruction. Decision-maker: the data controller. Delete if instructed: 14 days. See section 5.2.
Customer employee departure Access: disabled immediately. Credentials: deleted within 14 days. Contact details: updated or deleted within 30 days. Support history: retained for contract + 5 years.
| Data type | Period |
|---|---|
| Customer instance (active) | Contract + 60 days |
| Customer contracts | 6 years |
| Invoices | 7 years |
| Employee records | 7 years post-employment |
| Access logs | 12 months |
| Security incidents | 7 years |
| Financial records | 6-7 years |