Data Retention Policy
How long we keep data, and what happens when it is deleted.
This Policy supplements our Privacy Policy.
1. Principles
- Purpose limitation. We keep personal data only as long as it is needed for the purpose it was collected for.
- Legal minimums. Where law requires a minimum retention period — tax and accounting records in particular — that period governs.
- Legal holds. Where data is relevant to actual or reasonably anticipated litigation, a regulatory investigation, or a law-enforcement request, we suspend deletion until the matter concludes. A legal hold overrides every schedule below.
- Deletion is real. When a retention period expires, data is deleted or irreversibly anonymised. Anonymised data may be kept indefinitely for statistical purposes.
- Backups lag. Data deleted from live systems persists in encrypted backups until those backups rotate out. It is not restored or used.
2. Account and service data
| Category | Retention | Reason |
|---|---|---|
| Account data (email, username, name, profile, credentials) | Life of the account, then 30 days | Contract; recovery from accidental deletion |
| Your content (posts, drafts, media, categories, settings) | Life of the account, then 30 days | Contract; export window |
| Content revision history | Life of the parent content | Contract |
| Comments and reader submissions | Until deleted by the site operator, or with the parent site | Processed on the customer's instructions |
| Contact-form submissions / leads | 24 months, or until deleted by the site operator | Processed on the customer's instructions |
| Team and role assignments | Life of the account, then 30 days | Contract; audit |
| Support tickets and correspondence | 24 months from resolution | Service quality; defence of claims |
| Third-party connection credentials you supply | Duration of the connection; deleted when you disconnect or the account closes | Contract |
3. Billing and transactional data
| Category | Retention | Reason |
|---|---|---|
| Invoices, receipts, transaction records | 7–8 years from the end of the relevant financial year, or longer where local tax law requires | Legal obligation |
| Subscription and plan history | 7 years | Legal obligation; dispute resolution |
| Refund and chargeback records | 7 years | Legal obligation; dispute resolution |
| Saved payment method descriptors | Until you remove the card, or 30 days after account closure | Contract; recurring billing |
| Full card numbers, CVV, PIN | Never stored by us | Handled entirely by the payment provider |
Billing records are retained even after account deletion, because tax law requires it. They are kept in a restricted form and are not used for any other purpose. This is an exception to the erasure right that GDPR Article 17(3)(b) expressly permits.
4. Technical and security data
| Category | Retention | Reason |
|---|---|---|
| Application and access logs (IP address, request metadata, timestamps) | 30–90 days | Security, abuse detection, fault diagnosis |
| Authentication events | 90 days | Security; account-takeover investigation |
| Rate-limiting and abuse-prevention records | 30 days | Abuse prevention |
| Error and diagnostic records | 30–90 days | Reliability |
| Session tokens | Expire automatically; invalidated on logout, password change, or session revocation | Security |
| Usage measurements (for plan limits) | Current billing cycle plus 12 months of aggregated history | Billing accuracy; capacity planning |
| Security incident records | 3 years from closure, or longer under legal hold | Legal obligation; defence of claims |
5. What happens when you delete
5.1 Deleting individual content
Deleting a post, media item or comment removes it from your Site immediately. It is purged from live systems within 30 days and disappears from backups on the cycle in section 6.
5.2 Cancelling a subscription
Cancellation is not deletion. Your data is retained through the paid period and then enters the closure sequence below. See our Refund & Cancellation Policy.
5.3 Account closure sequence
| Stage | Timing | What happens |
|---|---|---|
| Access ends | End of paid period | Sites stop being served; dashboard access ends or becomes read-only |
| Grace / export window | 30 days | Content retained; you may reactivate and recover it, or request an export |
| Deletion | After 30 days | Account and content permanently deleted from live systems |
| Backup expiry | Up to 35 days later | Data ages out of encrypted backups |
| Retained | Per section 3 | Billing records only, in restricted form |
Export before the window closes
After deletion, recovery is impossible — not difficult, impossible. We cannot restore a deleted account as a goodwill gesture, because the data no longer exists.
5.4 Non-payment
Where a subscription lapses for non-payment, we apply a recovery and grace period before closure begins, and notify you during it. Your content is not deleted while the grace period is running.
5.5 Termination for breach
Where we terminate for breach of our Acceptable Use Policy, we may shorten or withhold the export window if providing it would perpetuate unlawful activity or destroy evidence. Content relevant to a legal or law-enforcement matter is preserved under a legal hold.
6. Backups
- Backups are encrypted and access-controlled.
- Backup retention: 35 days, on a rolling cycle.
- Backups exist for disaster recovery. They are not searched, mined, or used to reconstruct deleted records.
- Backups are ours, not a customer service. We do not undertake to restore an individual item on request. Export your content regularly.
7. Data we process for customers
For data we process as a processor on a customer’s instructions — comments, leads, reader accounts on their Sites — retention is set by that customer, within the outer bounds of this Policy. On termination we return or delete that data in accordance with our Data Processing Addendum, at the customer’s election.
If you are a customer: you are the controller of your Visitors’ data. Setting an appropriate retention period for it, and honouring your Visitors’ deletion requests, is your obligation.
8. Requesting deletion or export
Email privacy@postlyo.com, or use the controls in your account settings where available.
- We respond within 30 days, or your local statutory period.
- We verify identity in proportion to the sensitivity of the request.
- Where we cannot delete — because a legal obligation or legal hold requires retention — we will tell you which data is retained and why, and restrict its processing to that purpose alone.
9. Review
We review this Policy and the retention periods in it at least annually, and whenever we add a data category or a new legal obligation applies.
10. Contact
This document is provided in English. If we publish a translation and there is a conflict, the English version governs unless local law requires otherwise.