Data Retention & Right to Erasure Policy
MySafeTherapy Ltd
Effective Date: 8 December 2025 | Last Reviewed: 18 December 2025
1. Purpose
This policy defines how MySafeTherapy Ltd ("MySafeTherapy", "we", "our") retains, manages, and securely deletes personal and special category data, including mental health data, in compliance with:
- UK GDPR
- EU GDPR
- UK Data Protection Act 2018
- ICO guidance on health data
- International best practices for digital health platforms
This policy applies to all users, including clients, therapists, coaches, corporate users, and platform administrators.
2. Retention Principles
MySafeTherapy applies the following binding retention principles:
- Data minimisation: Only data strictly necessary is retained
- Purpose limitation: Data is retained only for defined, lawful purposes
- Storage limitation: Data is not retained indefinitely
- Security by design: All retained data is encrypted and access-restricted
- Safeguarding priority: Retention may be extended where there is risk of harm
Data is retained solely for:
- Delivery of therapeutic, coaching, and wellbeing services
- Compliance with legal, regulatory, and safeguarding obligations
- Fraud prevention, billing, and financial reconciliation
- Defence of legal claims
- Legitimate business operations (strictly limited)
3. Retention Periods
Retention periods are defined based on risk, legal obligation, and data sensitivity.
| Data Type | Retention Period |
|---|---|
| Active client records | Duration of active account |
| Archived client records | 42 days post account closure |
| Therapy session content (notes, chat, journals) | Deleted or anonymised at account closure unless safeguarding applies |
| Session metadata (timestamps, therapist ID, billing reference – no content) | As required for billing, audit, and regulatory defence |
| Therapist profiles & credentials | Duration of engagement + statutory obligations |
| Safeguarding records | Retained securely in restricted access where legally required |
| Audit logs & security logs | Retained as required for security and compliance |
| Backups | Encrypted, time-bound, automatically expired |
Key Clarifications
- Therapy content is treated as special category health data and is never retained longer than necessary.
- Backups are not live systems and are purged automatically within defined retention cycles.
- No data is retained "just in case".
4. Safeguarding & Legal Overrides
In certain circumstances, data cannot be immediately erased, including where retention is required for:
- Safeguarding of the client or others
- Ongoing risk of serious harm or self-harm
- Legal claims, complaints, or regulatory investigations
- Statutory retention requirements
In such cases:
- Data is restricted, not actively processed
- Access is limited to authorised safeguarding personnel
- Data is retained only for the minimum legally required period
5. Right to Erasure (Right to Be Forgotten)
Individuals have the right to request deletion of their personal data under Article 17 of GDPR, subject to lawful exemptions.
Who Can Request Erasure
- Clients
- Therapists
- Coaches
- Platform users
What Happens When an Erasure Request Is Submitted
- Immediate account deactivation
- Personal identifiers deleted or irreversibly anonymised
- Therapy content removed unless safeguarding applies
- Linked records pseudonymised or cascaded
- Audit logs retained only where legally required and non-identifiable
What Is Not Deleted
- Financial records required by law
- Security logs required for fraud prevention
- Safeguarding records where risk remains
These are retained in restricted, encrypted form.
6. How to Request Erasure
Requests may be submitted via:
- Account settings (self-service where applicable)
- Email to the Data Protection Officer (DPO)
- Written request via official contact channels
Verification
We may request identity verification to prevent unauthorised deletion.
Timeframes
- Requests are fulfilled within one calendar month
- Extensions (up to two months) may apply for complex requests, with written notification
7. Internal Enforcement & Accountability
- All erasure actions are logged and auditable
- Only authorised administrators can approve deletions
- Automated deletion routines are reviewed regularly
- Staff and contractors are trained on retention obligations
Failure to comply with this policy may result in disciplinary action.
8. Data Residency & International Compliance
- All personal and health data is stored and processed within the EU
- No data is transferred outside the EU
- All processors operate under valid Data Processing Agreements (DPAs)
This policy aligns with:
- UK ICO expectations
- EU supervisory authority guidance
- SOC 2-aligned operational practices
9. Policy Review
This policy is reviewed:
- Annually
- After major platform changes
- After regulatory updates
- Following security incidents (if any)
Related Policies
Contact Us
For data retention or erasure queries:
