Fyfikoy logo
Fyfikoy Budget Strategies

Data Retention Policy

Last Updated: February 20, 2024

This Data Retention Policy describes how Fyfikoy collects, stores, and deletes personal and operational data across its platform. It applies to all users, including learners, instructors, and administrative contacts, who interact with services provided through fyfikoy.com.

1. Purpose and Scope

This policy establishes the principles and procedures governing the retention and disposal of data processed by Fyfikoy. It applies to all data held in digital form, including personal data, account records, session logs, communications, and platform usage data.

The purpose of this policy is to ensure that data is:

  • Retained only for as long as necessary to fulfil the purpose for which it was collected
  • Stored securely and protected against unauthorised access during its retention period
  • Disposed of in a secure and irreversible manner once the retention period expires
  • Managed in accordance with applicable data protection obligations and best practices

2. Categories of Data We Retain

Fyfikoy processes and retains data across several categories depending on the nature of the user relationship and the services used.

2.1 Account and Identity Data

This includes information provided during registration or profile setup, such as name, email address, contact details, and authentication credentials. This data is retained for the duration of an active account and for a defined period following account closure.

2.2 Learning and Session Data

This includes records of course enrolments, session attendance, progress tracking, assessment results, certificates, and instructor feedback. This data supports the delivery of personalised learning paths and may be retained beyond account closure to preserve academic records.

2.3 Communication Records

This includes messages exchanged through the platform's internal messaging system, support tickets, and email correspondence with Fyfikoy staff. These records are retained to maintain continuity of service and to resolve disputes.

2.4 Financial and Billing Data

This includes transaction records, invoices, payment confirmations, and subscription history. Financial records are retained for the period required to satisfy accounting obligations and to handle refund or dispute requests.

2.5 Technical and Log Data

This includes IP addresses, device identifiers, browser types, session timestamps, access logs, and error reports. This data is used for security monitoring, fraud prevention, and platform performance analysis.

2.6 Marketing and Consent Data

This includes records of consent to receive marketing communications, preferences, and opt-out requests. Consent records are retained to demonstrate compliance and to honour user preferences.

3. Retention Periods

The table below outlines the standard retention periods applied to each data category. These periods begin from the last relevant activity or event unless otherwise stated.

Data Category Retention Period Basis for Retention
Account and identity data Duration of account plus 3 years after closure Contractual obligation and legitimate interest
Learning and session records Duration of account plus 5 years after closure Service delivery and academic record integrity
Communication records 3 years from date of communication Dispute resolution and service continuity
Financial and billing data 7 years from transaction date Legal and accounting obligation
Technical and log data 12 months from date of capture Security monitoring and fraud prevention
Marketing and consent records 3 years from last interaction or opt-out Consent management and compliance

Retention periods may be extended where data is subject to an ongoing legal claim, regulatory inquiry, or internal investigation. In such cases, the data will be preserved until the matter is resolved and any applicable appeal period has passed.

4. Data Minimisation and Storage Limitation

Fyfikoy applies the principle of data minimisation across all data collection activities. We collect only the data that is necessary for a defined and legitimate purpose. Where data is no longer required for its original purpose, it is either deleted, anonymised, or aggregated so that it can no longer be attributed to an individual.

Aggregated and anonymised data derived from user activity may be retained indefinitely for statistical and analytical purposes, provided it cannot be used to re-identify any individual.

5. Deletion and Disposal Procedures

At the end of a defined retention period, data is subject to a scheduled deletion or disposal process. The following procedures apply:

5.1 Automated Deletion

Where technically feasible, deletion is performed automatically through scheduled system processes. Records flagged for deletion are removed from active databases and backup systems within a defined cycle following the expiry of the retention period.

5.2 Manual Review

Certain categories of data, particularly those linked to financial records or active disputes, are subject to manual review before deletion to confirm that no legal hold or exceptional circumstance applies.

5.3 Backup Purging

Data held in backup systems is purged in accordance with the backup rotation schedule. Backup purging may occur on a delayed basis relative to primary system deletion, but deleted data will not be restored from backup once the retention period has expired unless required by a legal obligation.

5.4 Secure Disposal

All deletion processes are designed to render data unrecoverable. Physical media containing personal data, where applicable, is disposed of using methods that prevent reconstruction of the original data.

6. User Rights and Data Requests

Users have the right to request access to their personal data, request correction of inaccurate records, or request deletion of data where no overriding legal basis for retention exists. Such requests may be submitted by contacting Fyfikoy using the details provided at the end of this policy.

Where a deletion request is received, Fyfikoy will review the request against current retention obligations. Data that is subject to a legal hold, financial record requirement, or active dispute cannot be deleted until the relevant obligation has been satisfied.

Responses to data requests will be provided within a reasonable timeframe. Where a request cannot be fulfilled in full, Fyfikoy will explain the reason and indicate when deletion may become possible.

7. Third-Party Data Processors

Fyfikoy engages third-party service providers to support platform operations, including hosting, payment processing, communication tools, and analytics. These providers process data on behalf of Fyfikoy under contractual terms that require them to apply equivalent data retention and deletion standards.

Where a third-party processor retains data independently, their own retention policies apply to that data. Fyfikoy takes reasonable steps to ensure that such providers are instructed to delete data once it is no longer required for the purposes for which it was shared.

8. Data Security During Retention

All data retained by Fyfikoy is stored using appropriate technical and organisational security measures. These include:

  • Encryption of data at rest and in transit
  • Access controls limiting data access to authorised personnel only
  • Regular security assessments and vulnerability monitoring
  • Audit logging of access to sensitive data categories
  • Incident response procedures to address potential data breaches

Security measures are reviewed and updated periodically to reflect changes in technology and risk environment.

9. Policy Review and Updates

This policy is reviewed at least annually or whenever significant changes occur in the services offered, the data processed, or the applicable regulatory environment. Updates to this policy will be reflected in a revised version published on fyfikoy.com with an updated effective date.

Continued use of the platform following the publication of an updated policy constitutes acceptance of the revised terms. Users are encouraged to review this policy periodically to remain informed of how their data is managed.

10. Contact Information

Questions, requests, or concerns relating to this Data Retention Policy may be directed to Fyfikoy using the following contact details: