Legal

Data Retention Schedule

Last updated: September 2026

Renvia retains data only for as long as needed to deliver the service, comply with legal or clinical record-keeping obligations, and defend against legal claims. This schedule is a summary — specific retention periods for clinical data are governed by the Controller's own records management policy.

Retention periods

Data categoryRetention periodBasis
Patient clinical recordsDuration of care + as directed by controller (typically 8 years for adults; 25 years for maternity, per NHS Records Management Code)Controller instruction (UK GDPR Art. 28)
Patient vitals & device readingsSame as clinical recordsController instruction
Audit log entriesMinimum 7 years, immutableDCB0129 / DSP Toolkit / legal claims
Clinician & facility-admin accountsUntil membership revoked; account metadata retained for 12 months for security investigationsContract; legitimate interests
Website contact form submissions24 months, then deletedLegitimate interests
Newsletter subscribersUntil unsubscribe or 24 months of inactivityConsent
Application logs & error traces90 daysLegitimate interests (security & reliability)
Backups35 days rolling; encrypted at restLegitimate interests (business continuity)

Deletion & return at end of contract

On termination or expiry of the service agreement, Renvia will, at the Controller's option, return or securely delete all Personal Data within 30 days, subject to any legal obligation to retain records. Backups containing deleted data age out within the 35-day backup window, after which they are unrecoverable.

Individual erasure requests

Patients wishing to exercise their right to erasure should contact their healthcare provider (the Controller). Website visitors and marketing subscribers can request erasure directly at privacy@renvia.health.