Data Retention Policy

Version 1.1 — Last updated: 15 July 2026

1. Purpose and Scope

CareLedgerPro currently supports retention through documented policy and manual administrator action. It does not yet run an automated retention or deletion scheduler. Controllers are responsible for setting retention periods and initiating deletion in line with their own policy.

This policy explains how long CareLedgerPro retains personal, financial, and operational data processed on behalf of customers acting as controllers, and the principles governing secure deletion once retention periods end.

It applies to data stored or processed within the CareLedgerPro platform, including:

  • service-user financial records;
  • transaction histories;
  • audit logs;
  • staff accounts;
  • communication attachments;
  • billing metadata; and
  • security and incident records.

CareLedgerPro acts as a data processor. Controllers remain responsible for their own retention obligations under UK GDPR, CQC expectations, HMRC requirements, and applicable social-care records guidance.

2. Retention Principles

1. Data is retained only for as long as necessary to provide the Service, meet applicable legal or contractual requirements, or follow documented controller instructions.

2. Retention periods are determined by legal, regulatory, contractual, and operational requirements.

3. When a retention period expires, data is securely deleted or anonymised unless a legal hold applies.

4. Controllers may request earlier deletion where legally and operationally possible, subject to any overriding legal, regulatory, or contractual obligations.

5. Backups are managed so that expired data is not routinely reintroduced after deletion, subject to disaster recovery and technical constraints.

3. Retention Periods

Data categoryRetention periodBasis
Financial transaction records7 years from transaction dateTax, accounting, and financial record-keeping requirements.
Petty-cash and float records7 years from reconciliation dateFinancial accountability and audit support.
Receipt images and attachments7 years from upload dateEvidence of expenditure.
Service-user profiles and care-related notesDuration of active support + 8 yearsApplicable records management guidance and controller retention rules.
Audit logs (access, changes, corrections)7 years from log dateSafeguarding, investigation, and audit evidence.
Staff account and role records7 years after account closureAccess governance and accountability.
Communication centre messagesDuration of active support + 8 yearsCare record continuity.
Security incident and breach records7 years after incident closureAudit, compliance, and investigation evidence.
Billing and payment records7 years from transaction dateTax and accounting requirements.

4. Hosting Region and Data Location

Production data is hosted in UK/EU-aligned cloud regions to support UK GDPR data-location expectations. Backups and replicas remain in the same region unless a documented business continuity requirement requires otherwise.

Where any international transfer occurs, appropriate safeguards are applied, which may include the UK International Data Transfer Addendum or Standard Contractual Clauses, together with additional technical and organisational measures where required.

5. Review and Secure Destruction

CareLedgerPro ensures that:

  • retention schedules are reviewed at least annually;
  • expired data is deleted using secure deletion methods appropriate to the relevant storage system;
  • deletion events are logged for audit purposes; and
  • backups are managed to reduce the risk of expired data being reintroduced after deletion.

6. Exceptions and Legal Holds

Retention periods may be extended where required by:

  • law;
  • regulator direction;
  • litigation hold;
  • safeguarding investigation; or
  • other documented legal or operational obligations.

When a legal hold ends, data is destroyed in accordance with this policy and any applicable controller instruction.

7. Controller Responsibilities

Controllers are responsible for:

  • deciding when service-user records should be marked inactive;
  • applying their own retention policies;
  • requesting export or deletion of data where appropriate; and
  • ensuring their operational retention rules align with statutory and regulatory requirements.

CareLedgerPro provides export, deletion, and account-closure tools to support these duties.

8. Related Policies

Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.