Data Retention Policy & Schedule

Contents

  1. Purpose and scope
  2. Principles
  3. Retention schedule
  4. Responsibilities
  5. Key procedures
  6. Secure disposal methods
  7. Exceptions and extensions
  8. Monitoring and compliance
  9. Policy review
  10. Contact

1. Purpose and scope

1.1 Purpose

This policy sets out how Sprint Enterprise Technology Ltd ("Sprint") retains and disposes of personal data and business records in accordance with applicable UK data protection and privacy legislation, including the UK GDPR, the Data Protection Act 2018, PECR and the Data (Use and Access) Act 2025, as amended from time to time.

1.2 Scope

This policy applies to all personal data and business records processed by Sprint in any format, including electronic, paper and other media. It applies both where Sprint acts as a data controller and where Sprint acts as a data processor on behalf of its customers. Where Sprint acts as a data processor, the applicable customer contract, data processing agreement and documented controller instructions will take precedence over the default retention periods set out in this policy to the extent of any inconsistency.

1.3 Related information

This policy operates alongside Sprint's internal data protection and information security policies, which govern access control, asset management and secure disposal in more detail.

2. Principles

2.1 Storage limitation

Sprint does not keep personal data for longer than necessary. Data is deleted or anonymised when it is no longer required, and holdings are reviewed regularly.

2.2 Legal and business requirements

Retention periods are determined by legal obligations, legitimate business interests, and the principle of data minimisation.

2.3 Secure disposal

All personal data is securely destroyed when its retention period expires, in line with Sprint's asset management and disposal procedures.

2.4 Accountability and record keeping

Sprint maintains appropriate records of retention decisions, approved extensions, legal holds, data disposal activities and compliance reviews to demonstrate compliance with applicable data protection and privacy laws. Such records must be accurate, retained securely and made available to authorised personnel for audit, regulatory or compliance purposes where required.

3. Retention schedule

3.1 Customer data (Fastrak and Finio)
Data category Retention period Legal basis Disposal method
Active customer data & usage Duration of contract + 60 days Contract performance Secure deletion from all systems
Customer instance data 60 days post-contract end Contract performance Secure deletion (all systems & backups)
Customer contracts 6 years after contract end Limitation Act 1980 Secure deletion
Customer invoices & payment records 7 years after transaction HMRC requirements Secure deletion
Customer support communications Duration of contract + 5 years Legitimate interests Secure deletion
Customer contact (active) Duration of contract Legitimate interests (CRM) Updated or deleted within 30 days of notification that the individual has left or that the contact details are inaccurate
Customer contact (former staff) 30 days from notification or contract end (whichever is sooner) Data minimisation Secure deletion
Anonymised statistical data Indefinite Legitimate interests N/A - anonymised

Contract termination. All external logins are disabled on the contract expiry date, and all customer instance data is deleted within 60 days.

When a customer's employee leaves. System access is disabled immediately; login credentials are deleted within 14 days; contact details are updated or deleted within 30 days; and support history is retained for the duration of the contract plus 5 years.

3.2 Employee and contractor data
Data category Retention period Legal basis
Employment contracts & HR records 7 years after employment ends Legal obligation
Payroll & tax records (P45, P60, P11D) 7 years after tax year end HMRC requirements
Right to work documents 2 years after employment ends UK immigration law
Recruitment records (unsuccessful applicants) 6 months after decision Legitimate interests

Disposal is by secure shredding or deletion, in line with Sprint's asset management and disposal procedures.

3.3 Financial and business records
Data category Retention period Legal basis
Annual accounts Permanent (company lifetime + 6 years) Companies Act 2006
Bank statements & invoices 7 years HMRC requirements
VAT & tax records 6 years from accounting period end HMRC requirements
3.4 Contracts and legal documents
Data category Retention period
Supplier contractsDuration + 6 years
Data processing agreementsDuration + 6 years
Professional indemnity insurancePermanent
IP records & shareholder agreementsPermanent
Board minutesPermanent

Certain corporate governance, ownership and professional indemnity records are retained permanently because they may be required to evidence Sprint's legal existence, ownership, governance, intellectual property rights, insurance history and compliance with legal obligations. These categories are therefore exempt from the standard retention periods that apply to operational records.

3.5 Marketing and communications
Data category Retention period
Marketing consent recordsDuration of consent + 2 years
Marketing suppression listsIndefinite
Consented email listsUntil consent withdrawn + 30 days
Prospect data (no consent)2 years from last contact
3.6 Information security and system data
Data category Retention period
Access & authentication logs12 months
Security incident logs7 years
System backup data30 days (rolling)
Vulnerability & penetration test records3 years
Data breach records7 years

Technical security controls are governed by Sprint's internal information security policies.

3.7 Sprint's role as data processor and selective retention

For the Fastrak and Finio platforms, Sprint acts as a data processor on behalf of its customers, who are the data controllers. Sprint acts only on the documented instruction of the data controller.

Where Sprint processes personal data as a processor, the applicable customer contract, data processing agreement and documented controller instructions take precedence over the default retention periods set out in this policy to the extent of any inconsistency. Sprint will not retain controller data for its own purposes unless it has separately identified and documented a lawful basis for doing so in its capacity as a controller.

The retention periods set out in section 3.1 are intended to describe Sprint's standard operational practices and do not limit any obligation to return, delete or retain personal data in accordance with a customer contract, data processing agreement, documented controller instruction or applicable law.

Scenario Data subject Retention / action Who can instruct
Platform access termination Platform end-users Access ceases immediately; logs retained 12 months Data controller only
Individual firm data feed Firm's clients Feed ceases immediately Controller or authorised third-party service provider
Individual end-user deletion Individual investor Request forwarded to controller within 48 hours; data deleted within 14 days of receiving a valid controller instruction Data controller only
Customer employee contact Platform employee Updated or deleted within 30 days of notification Controller or verified individual

Key principles

  1. As a data processor, Sprint acts only on the documented instruction of the data controller.
  2. All deletion instructions are verified before any action is taken.
  3. Deletions are logged with the date, requester, authorisation and scope.
  4. A full audit trail is maintained.

4. Responsibilities

4.1 Data Protection Officer
  • Overall oversight of retention compliance
  • Approving changes to retention periods
  • Annual review of this policy
  • Investigating retention-related concerns
4.2 All Sprint personnel
  • Comply with retention periods
  • Securely dispose of data when periods expire
  • Report concerns to the Data Protection Officer
  • Consult the Data Protection Officer before adopting new retention practices
4.3 System administrators
  • Implement automated deletion where feasible
  • Maintain secure backup and archival processes
  • Ensure deleted data is irrecoverable
  • Document disposal activities

5. Key procedures

5.1 Customer contract termination
  • On expiry. All external logins are disabled and the instance is marked for deletion.
  • During the 60-day period. The instance is inaccessible; this provides an opportunity for renewal.
  • At 60 days. All customer data is permanently deleted from production and customer-accessible systems, credentials are removed and the activity is logged. Any residual copies contained within encrypted, access-restricted backup systems will expire through the normal backup retention cycle and will not be restored except where required for disaster recovery, security or legal purposes. If restored, such data will remain subject to the original deletion instruction.
  • After deletion. Only customer contracts (6 years), invoices (7 years) and anonymised statistics are retained.
5.2 Data subject requests (Sprint as data processor)

Where Sprint receives a request directly from an individual end-user:

  1. Acknowledge within 48 hours.
  2. Identify the data controller (the platform or customer).
  3. Forward the complete request to the controller within 48 hours.
  4. Await written instruction from the controller.
  5. Act on the instruction within 14 days.
  6. Confirm completion to the controller.

Sprint does not make deletion decisions about controller data. Only the data controller can instruct deletion.

5.3 Legal hold

Where legal proceedings are anticipated, deletion of the relevant data is suspended, the hold is documented, and normal retention resumes only when the hold is lifted.

6. Secure disposal methods

  • Electronic. Secure data wiping to a recognised standard (for example, DoD 5220.22-M) or physical destruction; permanent deletion from databases; secure deletion from cloud storage with confirmation; and expiry of residual copies through the applicable backup retention process.
  • Physical. Cross-cut (P-4) shredding or incineration; physical destruction of storage media.
  • Verification. All disposals are logged, verified and auditable.

7. Exceptions and extensions

7.1 Valid reasons for an extension
  • Ongoing legal proceedings
  • An active regulatory inquiry
  • Unresolved disputes
  • Contractual obligations
  • Explicit consent from the data subject
7.2 Invalid reasons
  • "Might need it someday"
  • Convenience or habit
  • Lack of resources
  • General business practice without justification

Process. A written request for any retention extension must be submitted to the Data Protection Officer, together with the justification and proposed duration of the extension. The Data Protection Officer will assess the request against applicable legal, regulatory and business requirements and may approve the extension where justified. All approved extensions must be documented, assigned a review date and reassessed at least annually to confirm that the justification for continued retention remains valid. Any extension that is no longer justified will be withdrawn and the relevant data deleted in accordance with this policy.

8. Monitoring and compliance

Sprint monitors and demonstrates compliance through:

  • Maintenance of retention and disposal records
  • Annual data retention audits
  • Review of disposal logs
  • Spot checks of systems
  • Investigation of reported concerns

Non-compliance - retaining data for too long, or disposing of it too early - is treated as a potential data protection breach and reported to the Data Protection Officer.

9. Policy review

This policy is reviewed annually by the Data Protection Officer and additionally following changes to applicable law, relevant ICO guidance, significant court or regulatory decisions, retention-related incidents, or significant changes to Sprint's business or processing activities.

10. Contact

Data Protection Officer
Email: data.protection@sprintenterprise.co.uk

Appendix A - Quick reference: common scenarios

Contract termination (Fastrak / Finio) Delete: instance data 60 days post-expiry. Keep: contracts (6 years), invoices (7 years), anonymised statistics. See section 5.1.

Platform access termination Delete: access ceases immediately; logs retained 12 months. Instruction: data controller only.

Individual end-user deletion request Sprint action: forward to the controller within 48 hours and await instruction. Decision-maker: the data controller. Delete if instructed: 14 days. See section 5.2.

Customer employee departure Access: disabled immediately. Credentials: deleted within 14 days. Contact details: updated or deleted within 30 days. Support history: retained for contract + 5 years.

Retention period quick lookup
Data type Period
Customer instance (active)Contract + 60 days
Customer contracts6 years
Invoices7 years
Employee records7 years post-employment
Access logs12 months
Security incidents7 years
Financial records6-7 years

 

Book a call