Legal
Data Retention Schedule
Last updated: September 2026
Renvia retains data only for as long as needed to deliver the service, comply with legal or clinical record-keeping obligations, and defend against legal claims. This schedule is a summary — specific retention periods for clinical data are governed by the Controller's own records management policy.
Retention periods
| Data category | Retention period | Basis |
|---|---|---|
| Patient clinical records | Duration of care + as directed by controller (typically 8 years for adults; 25 years for maternity, per NHS Records Management Code) | Controller instruction (UK GDPR Art. 28) |
| Patient vitals & device readings | Same as clinical records | Controller instruction |
| Audit log entries | Minimum 7 years, immutable | DCB0129 / DSP Toolkit / legal claims |
| Clinician & facility-admin accounts | Until membership revoked; account metadata retained for 12 months for security investigations | Contract; legitimate interests |
| Website contact form submissions | 24 months, then deleted | Legitimate interests |
| Newsletter subscribers | Until unsubscribe or 24 months of inactivity | Consent |
| Application logs & error traces | 90 days | Legitimate interests (security & reliability) |
| Backups | 35 days rolling; encrypted at rest | Legitimate interests (business continuity) |
Deletion & return at end of contract
On termination or expiry of the service agreement, Renvia will, at the Controller's option, return or securely delete all Personal Data within 30 days, subject to any legal obligation to retain records. Backups containing deleted data age out within the 35-day backup window, after which they are unrecoverable.
Individual erasure requests
Patients wishing to exercise their right to erasure should contact their healthcare provider (the Controller). Website visitors and marketing subscribers can request erasure directly at privacy@renvia.health.