top of page

Data Retention Policy

Effective Date: 13 July 2026

1. Purpose

Boundary Review is committed to retaining personal information only for as long as necessary to provide our services, comply with legal obligations and support the legitimate interests of our customers.

This Data Retention Policy explains how long different categories of information are retained, how they are protected and how they are securely deleted when no longer required.

This policy supports compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

 

2. Scope

This policy applies to all information processed by Boundary Review, including:

  • Customer account information.

  • School data.

  • Pupil assessment data.

  • Customer communications.

  • Website enquiries.

  • Marketing information.

  • Audit logs.

  • Backup copies.

  • System-generated records.

 

3. Retention Principles

Boundary Review follows the following principles when retaining information:

  • Personal data will only be retained where there is a legitimate business, contractual or legal reason.

  • Information will not be retained indefinitely.

  • Data will be securely deleted when no longer required.

  • Retention periods will be reviewed periodically.

  • Customers may request deletion of their information where appropriate and where no legal obligation requires continued retention.

  • Backup copies are maintained solely to support business continuity and disaster recovery.

 

4. Retention Schedule

Data CategoryRetention Period

Website contact enquiriesUp to 24 months after the enquiry is resolved

Marketing contactsUntil consent is withdrawn or the individual unsubscribes

Customer account informationDuration of the subscription and up to 12 months after account closure

School configuration informationDuration of the subscription and up to 12 months after termination unless earlier deletion is requested

Pupil assessment and examination dataDuration of the subscription and up to 90 days after termination unless otherwise agreed with the customer

Support correspondenceUp to 24 months after the support request is resolved

Audit logs and user activity recordsUp to 24 months

Automated backup copiesRolling retention of the most recent 12 monthly backups

Financial and accounting recordsSeven years where required by UK law

Where legal obligations or ongoing disputes require it, information may be retained for longer.

 

5. Customer Data

Schools remain the Data Controller for all pupil and staff information uploaded to Boundary Review.

Boundary Review acts solely as the Data Processor and processes customer information only for the purpose of delivering the agreed service.

Upon termination of the service, customers may request either:

  • Secure deletion of their information; or

  • Return of their information in an agreed electronic format.

Unless otherwise agreed in writing or required by law, customer information will normally be securely deleted within 90 days of termination of the service.

 

6. Backup Retention

Boundary Review maintains automated monthly backups of customer spreadsheets using Google Apps Script.

These backups are designed solely to support business continuity and recovery from accidental deletion, corruption or other data loss events.

Backup copies are:

  • Created automatically once each month.

  • Saved with a timestamp to enable version identification.

  • Stored securely within a dedicated, access-controlled backup location in Boundary Review's Google Workspace environment.

  • Protected by Google Workspace security controls, including encryption in transit and at rest.

  • Accessible only to authorised Boundary Review administrators.

  • Retained on a rolling basis, with the 12 most recent monthly backups being preserved.

  • Automatically deleted once they exceed the 12-month retention period.

Backup copies are not used for any purpose other than disaster recovery or restoring customer information where appropriate.

 

7. Secure Deletion

When information reaches the end of its retention period, Boundary Review will securely delete or anonymise it where appropriate.

Deletion activities may include:

  • Permanent removal from Google Drive.

  • Deletion of Google Sheets and associated files.

  • Removal of user accounts.

  • Deletion of audit records where no longer required.

  • Automatic removal of expired backup copies.

  • Secure deletion of customer communications where retention is no longer necessary.

Google Drive version history and backup copies are managed in accordance with this policy and are not retained indefinitely.

 

8. Legal and Regulatory Requirements

Boundary Review may retain certain information beyond the periods set out in this policy where necessary to:

  • Comply with applicable legislation.

  • Meet accounting or taxation requirements.

  • Resolve disputes.

  • Exercise or defend legal claims.

  • Enforce contractual obligations.

Only the minimum information necessary will be retained for these purposes.

 

9. Policy Review

Boundary Review reviews this policy periodically to ensure it remains accurate, effective and compliant with changes in legislation, operational practices and technology.

Any material updates will be published on our website.

 

10. Contact

If you have any questions regarding this Data Retention Policy or would like to request the deletion or return of your organisation's information, please contact:

Boundary Review

Email: info@boundaryreview.co.uk

bottom of page