Data Retention Policy
Last Updated: September 12, 2025
This Data Retention Policy describes how Quiteria Belgrane collects, stores, and deletes personal and operational data. It applies to all users of our platform and services. By using our services, you acknowledge that your data will be handled in accordance with this policy.
1. Purpose of This Policy
We retain data only for as long as necessary to fulfil the purposes for which it was collected, to comply with applicable legal and regulatory obligations, to resolve disputes, and to enforce our agreements. This policy establishes clear retention periods and deletion procedures to ensure responsible data stewardship.
2. Scope
This policy applies to all personal data and non-personal operational data processed by Quiteria Belgrane, including data collected through our website, consultation platform, communication tools, and any associated services. It applies to data held in digital systems, databases, cloud storage, backup systems, and archived records.
3. Categories of Data We Retain
3.1 Account and Identity Data
This includes information provided during account registration and profile setup, such as name, email address, contact details, and authentication credentials. This data is retained for the duration of the active account relationship and for a defined period following account closure.
3.2 Consultation and Session Data
Records of consultations, session notes, scheduling history, and interaction logs are retained to support service delivery, quality assurance, and continuity of care. This data is retained for the duration of the service relationship and a reasonable period thereafter.
3.3 Communication Data
Messages, support tickets, emails, and other communications exchanged through our platform are retained to maintain accurate records of service interactions and to resolve disputes or complaints.
3.4 Payment and Billing Data
Transaction records, invoices, and billing history are retained as required for financial reporting, audit purposes, and compliance with applicable accounting obligations. Payment instrument details are handled by third-party payment processors and are subject to their own retention policies.
3.5 Technical and Usage Data
Log files, access records, device identifiers, IP addresses, and usage analytics are retained for security monitoring, performance optimisation, and troubleshooting. This data is typically retained for a shorter period than account data.
3.6 Marketing and Preference Data
Communication preferences, consent records, and marketing interaction data are retained for the duration of the consent period or until a withdrawal of consent is received, whichever comes first.
4. Retention Periods
The following table outlines standard retention periods by data category. Actual retention may be extended where required by a legal obligation or ongoing dispute.
| Data Category | Standard Retention Period | Trigger for Deletion |
|---|---|---|
| Account and Identity Data | Duration of account plus 3 years | Account closure and expiry of retention window |
| Consultation and Session Data | Duration of service plus 5 years | End of service relationship and expiry of retention window |
| Communication Data | 3 years from last interaction | Expiry of retention window |
| Payment and Billing Data | 7 years from transaction date | Expiry of financial record obligation |
| Technical and Usage Data | 12 months from collection | Rolling deletion after 12 months |
| Marketing and Preference Data | Until consent is withdrawn or 2 years of inactivity | Withdrawal of consent or inactivity threshold |
| Backup and Archive Copies | Up to 90 days beyond primary deletion | Backup rotation cycle completion |
5. Legal Holds and Extended Retention
Where data is subject to a legal hold, regulatory investigation, litigation, or formal dispute resolution process, standard retention periods are suspended. Affected data will be preserved until the hold is formally lifted. Following resolution, data will be deleted in accordance with the timelines set out in this policy.
6. Data Minimisation
We collect only the minimum data necessary for each stated purpose. We periodically review the data we hold to identify and remove information that is no longer required. Data that has exceeded its retention period and is not subject to a legal hold is scheduled for deletion or anonymisation.
7. Anonymisation as an Alternative to Deletion
In some cases, rather than deleting data, we may anonymise it so that it can no longer be linked to any identifiable individual. Anonymised data may be retained indefinitely for analytical, statistical, or service improvement purposes. Once data has been genuinely anonymised, it falls outside the scope of this policy.
8. Deletion and Disposal Procedures
8.1 Secure Deletion
When data reaches the end of its retention period, it is deleted using methods appropriate to the storage medium. Digital records are overwritten or purged from databases. Backup copies are removed during the next applicable backup rotation cycle.
8.2 Third-Party Processors
Where data is processed by third-party service providers on our behalf, we require those providers to implement retention and deletion practices consistent with this policy. Deletion requests are communicated to relevant processors within a reasonable timeframe.
8.3 User-Requested Deletion
Users may request deletion of their personal data at any time, subject to applicable rights under relevant data protection frameworks. Requests will be assessed and fulfilled within a reasonable period, except where retention is required by law or legitimate business necessity. Residual copies in backup systems will be removed during the next scheduled backup cycle.
9. Backup and Recovery Systems
Data held in backup and disaster recovery systems may persist beyond the primary deletion date due to the nature of backup rotation schedules. Such copies are not actively used for any operational purpose and are subject to deletion as part of the regular backup cycle, typically within 90 days of the primary deletion event.
10. Access to Retained Data
Access to retained data is restricted to authorised personnel who require it for legitimate operational, legal, or compliance purposes. Access controls, audit logging, and role-based permissions are applied to all systems holding personal data.
11. Cookies and Tracking Technologies
Data collected through cookies and similar tracking technologies is retained in accordance with the purposes declared in our Cookie Policy. Session cookies are deleted at the end of the browser session. Persistent cookies are retained for the period specified at the time of consent, after which they expire automatically.
12. Policy Review and Updates
This policy is reviewed at least once per year and updated as necessary to reflect changes in our services, legal obligations, or data processing practices. Material changes will be communicated to users through our platform or by direct notification. Continued use of our services following notification of changes constitutes acceptance of the revised policy.
13. Contact
If you have questions about this Data Retention Policy, wish to exercise your data rights, or wish to request deletion of your personal data, please contact us using the details below.
Quiteria Belgrane
Ballywilliam, E45FP97, Co. Tipperary, Ireland
Email: support@waxydua.com
Phone: +353 1 846 0132
Website: www.waxydua.com