Skip to main content

    Data Retention & Right to Erasure Policy

    MySafeTherapy Ltd
    Effective Date: 8 December 2025 | Last Reviewed: 18 December 2025

    1. Purpose

    This policy defines how MySafeTherapy Ltd ("MySafeTherapy", "we", "our") retains, manages, and securely deletes personal and special category data, including mental health data, in compliance with:

    • UK GDPR
    • EU GDPR
    • UK Data Protection Act 2018
    • ICO guidance on health data
    • International best practices for digital health platforms

    This policy applies to all users, including clients, therapists, coaches, corporate users, and platform administrators.

    2. Retention Principles

    MySafeTherapy applies the following binding retention principles:

    • Data minimisation: Only data strictly necessary is retained
    • Purpose limitation: Data is retained only for defined, lawful purposes
    • Storage limitation: Data is not retained indefinitely
    • Security by design: All retained data is encrypted and access-restricted
    • Safeguarding priority: Retention may be extended where there is risk of harm

    Data is retained solely for:

    • Delivery of therapeutic, coaching, and wellbeing services
    • Compliance with legal, regulatory, and safeguarding obligations
    • Fraud prevention, billing, and financial reconciliation
    • Defence of legal claims
    • Legitimate business operations (strictly limited)

    3. Retention Periods

    Retention periods are defined based on risk, legal obligation, and data sensitivity.

    Data TypeRetention Period
    Active client recordsDuration of active account
    Archived client records42 days post account closure
    Therapy session content (notes, chat, journals)Deleted or anonymised at account closure unless safeguarding applies
    Session metadata (timestamps, therapist ID, billing reference – no content)As required for billing, audit, and regulatory defence
    Therapist profiles & credentialsDuration of engagement + statutory obligations
    Safeguarding recordsRetained securely in restricted access where legally required
    Audit logs & security logsRetained as required for security and compliance
    BackupsEncrypted, time-bound, automatically expired

    Key Clarifications

    • Therapy content is treated as special category health data and is never retained longer than necessary.
    • Backups are not live systems and are purged automatically within defined retention cycles.
    • No data is retained "just in case".

    4. Safeguarding & Legal Overrides

    In certain circumstances, data cannot be immediately erased, including where retention is required for:

    • Safeguarding of the client or others
    • Ongoing risk of serious harm or self-harm
    • Legal claims, complaints, or regulatory investigations
    • Statutory retention requirements

    In such cases:

    • Data is restricted, not actively processed
    • Access is limited to authorised safeguarding personnel
    • Data is retained only for the minimum legally required period

    5. Right to Erasure (Right to Be Forgotten)

    Individuals have the right to request deletion of their personal data under Article 17 of GDPR, subject to lawful exemptions.

    Who Can Request Erasure

    • Clients
    • Therapists
    • Coaches
    • Platform users

    What Happens When an Erasure Request Is Submitted

    1. Immediate account deactivation
    2. Personal identifiers deleted or irreversibly anonymised
    3. Therapy content removed unless safeguarding applies
    4. Linked records pseudonymised or cascaded
    5. Audit logs retained only where legally required and non-identifiable

    What Is Not Deleted

    • Financial records required by law
    • Security logs required for fraud prevention
    • Safeguarding records where risk remains

    These are retained in restricted, encrypted form.

    6. How to Request Erasure

    Requests may be submitted via:

    • Account settings (self-service where applicable)
    • Email to the Data Protection Officer (DPO)
    • Written request via official contact channels

    Verification

    We may request identity verification to prevent unauthorised deletion.

    Timeframes

    • Requests are fulfilled within one calendar month
    • Extensions (up to two months) may apply for complex requests, with written notification

    7. Internal Enforcement & Accountability

    • All erasure actions are logged and auditable
    • Only authorised administrators can approve deletions
    • Automated deletion routines are reviewed regularly
    • Staff and contractors are trained on retention obligations

    Failure to comply with this policy may result in disciplinary action.

    8. Data Residency & International Compliance

    • All personal and health data is stored and processed within the EU
    • No data is transferred outside the EU
    • All processors operate under valid Data Processing Agreements (DPAs)

    This policy aligns with:

    • UK ICO expectations
    • EU supervisory authority guidance
    • SOC 2-aligned operational practices

    9. Policy Review

    This policy is reviewed:

    • Annually
    • After major platform changes
    • After regulatory updates
    • Following security incidents (if any)

    Related Policies

    Contact Us

    For data retention or erasure queries:

    📧 privacy@mysafetherapy.com

    📧 support@mysafetherapy.com

    MySafeTherapy

    Important: MySafeTherapy is not a crisis or emergency service. If you are in immediate danger or thinking of harming yourself, please contact your local emergency services or a crisis helpline in your country.

    We value your privacy

    We use cookies to enhance your browsing experience and analyze our traffic. By clicking "Accept", you consent to our use of cookies. Learn more about our cookie and privacy policy