Data Deletion Policy

Version 1.1 — Last updated: 15 July 2026

1. Purpose and Scope

Deletion is currently actioned by an authorised administrator through the platform. There is no automated background job that deletes records on a schedule. Controllers must trigger deletion in line with their own retention policy or in response to a valid erasure request.

This policy explains how CareLedgerPro deletes personal data when it is no longer required, when a controller requests deletion, when a data subject exercises their rights under UK GDPR, when a subscription ends, or when a retention period expires.

It applies to data processed within CareLedgerPro, including:

  • service-user financial records;
  • transactions and receipts;
  • audit logs;
  • staff accounts;
  • communication content;
  • billing metadata; and
  • security incident records.

CareLedgerPro acts as a data processor. Controllers remain responsible for deciding when data should be deleted under their own retention policies and legal obligations.

2. Deletion Triggers

Deletion may occur in the following situations:

  • Controller-initiated deletion. An authorised administrator deletes a service-user record, transaction, attachment, or message through the platform.
  • Right to erasure under UK GDPR. A data subject or their representative requests deletion. CareLedgerPro processes such requests only under the controller’s documented instructions.
  • Subscription termination. After cancellation, data is retained for a limited export period before deletion in line with the retention schedule.
  • Retention expiry. Data is deleted automatically when the retention period defined in the Data Retention Policy ends.

3. Deletion Process

When deletion is actioned:

  • the request is authenticated and authorised;
  • data is removed from active systems and marked for purge;
  • object storage, such as receipt images and attachments, is deleted when the parent record is removed;
  • audit records of the deletion action itself are retained for accountability; and
  • confirmation is provided to the requester where contact details are available.

Deletion is irreversible once completed.

4. Timelines

ScenarioTimeline
In-app deletion by administratorImmediate soft delete; hard delete within 30 days.
Data subject erasure requestAcknowledged within 72 hours; completed within one month where applicable.
Subscription cancellation30-day export window, then deletion in line with the retention policy.
Retention-period expiryDeleted at the next scheduled purge cycle.

5. Verification and Logging

CareLedgerPro logs deletion operations, including:

  • timestamp;
  • actor;
  • scope of deletion; and
  • method used.

For bulk deletions, a summary log is generated so controllers can verify completion. Audit logs are retained in line with the Data Retention Policy.

6. Exceptions

Deletion may be delayed or refused where retention is necessary:

  • to comply with a legal obligation;
  • for the establishment, exercise or defence of legal claims;
  • for safeguarding or public-interest reasons; or
  • where anonymised data is retained for lawful analytics or reporting.

Where an exception applies, the requester is informed of the reason and, where possible, the expected retention period.

7. Backups and Disaster Recovery

Backups are retained for a defined period to support disaster recovery.

When a deletion request is actioned, the deletion is included in subsequent backup cycles where practicable. Older backups expire naturally and are purged without routinely reintroducing deleted data.

Deleted data is not restored from backups once its retention period has expired, subject to technical and disaster-recovery constraints.

8. Related Policies

Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.