Data Sole
Legal

Data Retention Policy

Policy Owner: Data Sole
Policy Area: Data Protection, Privacy & Information Governance
Version: 1.1
Effective Date: 27 August 2026
Review Cycle: At least annually
Jurisdiction: United Kingdom

Contents

  1. 1. Purpose
  2. 2. Scope
  3. 3. Legal and Regulatory Framework
  4. 4. Retention Principles
  5. 5. Standard Retention Schedule
  6. 6. Customer-Controlled Cloud Data
  7. 7. Account and Service Termination
  8. 8. Backups and Disaster Recovery
  9. 9. Security Logs
  10. 10. Legal Holds
  11. 11. Secure Disposal
  12. 12. Data Subject Rights
  13. 13. Third-Party Processors
  14. 14. International Processing
  15. 15. Roles and Responsibilities
  16. 16. Exceptions
  17. 17. Policy Review
  18. 18. Compliance
  19. Appendix A: Definitions
  20. Appendix B: Related Documents
  21. Appendix C: Worked Scenarios
  22. Document Control

1. Purpose

Data Sole is committed to protecting personal, customer, business and technical information throughout its lifecycle. This commitment extends from the point at which information is first collected — whether through account registration, service provisioning, support interaction or system-generated activity — through to the point at which it is securely deleted, anonymised or otherwise rendered irretrievable.

This Data Retention Policy (“the Policy”) establishes how long Data Sole retains information, the reasons for retention, and the procedures used to securely archive, anonymise and delete information when it is no longer required. It is designed to be read alongside Data Sole’s Privacy Policy, Information Security Policy, Data Processing Agreements and any service-specific terms, which together form Data Sole’s information governance framework.

Data Sole follows the principle that information must not be retained for longer than is necessary for the purpose for which it was collected, subject to applicable legal, regulatory, contractual, security and legitimate business requirements. This principle, commonly referred to as storage limitation, sits alongside the complementary principles of data minimisation and purpose limitation, and underpins every retention period set out in this Policy.

The Policy is not merely a compliance exercise. Excessive retention increases the attack surface available to malicious actors, increases the cost and complexity of responding to data subject requests, and increases the business’s exposure in the event of a breach or dispute. Conversely, premature deletion can undermine service continuity, billing accuracy, security investigations and legal defensibility. This Policy is intended to strike an appropriate, documented and defensible balance between those competing pressures.

In setting that balance, Data Sole has had regard to the nature of its business as a cloud infrastructure and hosting provider. This means that, in many cases, Data Sole holds two distinct classes of information side by side: information that Data Sole itself controls as a business (such as billing records, support tickets, employee records and its own security logs), and information that customers store within the infrastructure Data Sole provides, over which Data Sole typically acts only as a processor. This Policy addresses both classes, but the governing rules for each are not identical, and Section 6 explains the distinction in more detail.

This Policy is written to be understood by a broad audience — not only by specialists in data protection law, but by engineers designing storage systems, by support staff handling customer correspondence, and by managers approving supplier contracts. Where a term of art is used, it is defined in Appendix A.

2. Scope

This Policy applies to information processed or controlled by Data Sole across its services, systems and business operations, including but not limited to:

  • Cloud infrastructure and hosting services;
  • Virtual machines and computing environments;
  • Cloud storage, databases and backups;
  • Customer accounts and administration portals;
  • Websites, applications and APIs;
  • Billing and payment records;
  • Customer support systems;
  • Security, authentication and access logs;
  • Network and infrastructure monitoring;
  • Marketing and communications;
  • Employees, contractors and suppliers;
  • Development, testing and operational environments; and
  • Physical and electronic corporate records.

The Policy applies regardless of whether information is stored within Data Sole infrastructure or processed by an authorised third-party service provider acting on Data Sole’s behalf. It applies across all Data Sole brands and service lines, all environments (production, staging, development and test), and all media (electronic and physical).

This Policy does not, by itself, override any more specific retention obligation set out in a signed Data Processing Agreement, service-level agreement or applicable statute. Where such a document specifies a different period, that document’s terms take precedence for the information it covers, and Section 16 (Exceptions) applies.

The Policy applies to information in any format, including structured records held in databases, unstructured files held in object storage, correspondence held in email and messaging systems, machine-generated telemetry, and information recorded on physical media such as paper files or removable storage devices. Format does not determine whether the Policy applies; the nature and purpose of the information does.

2.1 What Falls Outside This Policy

This Policy does not set retention periods for information that a customer stores within their own externally hosted systems that are not provided by Data Sole, even where that information relates to a Data Sole customer relationship. Nor does it govern retention decisions made by an independent controller with whom Data Sole shares information under a separate legal basis, such as a joint marketing partner acting as an independent controller of the data it receives; any such sharing is instead governed by the relevant data-sharing agreement and Data Sole’s Privacy Policy.

3. Legal and Regulatory Framework

Where applicable, Data Sole processes and retains information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable UK legal, tax, accounting, contractual and regulatory requirements.

Data Sole applies the UK GDPR storage-limitation principle when determining appropriate retention periods for personal data. In practice, this means that for each category of information Data Sole identifies: the purpose for which the information is held; the minimum period necessary to fulfil that purpose, including any applicable statutory minimum (for example, tax and accounting legislation generally requiring records to be kept for six years); and any factors that may justify retention beyond that minimum, such as an ongoing contractual relationship, an unresolved dispute, or a security investigation.

Where Data Sole provides services to customers outside the United Kingdom, or where information is transferred internationally, additional or different legal requirements may apply. Section 14 addresses this in more detail. Where a conflict exists between this Policy and a binding legal requirement, the legal requirement takes precedence, as set out in Section 16.

3.1 Sources of Retention Obligation

Retention periods in this Policy are informed by several distinct sources of obligation, which do not always point in the same direction. Statutory minimums — such as those under the Companies Act 2006 and HM Revenue & Customs record-keeping requirements — set a floor below which certain financial and corporate records must not be deleted. Contractual obligations, such as service-level commitments to retain support history for a defined period, may set a separate floor for particular categories. Security and fraud-prevention considerations may justify retention beyond a statutory minimum, for example to preserve evidence of a pattern of abuse across multiple incidents. And the data-protection storage-limitation principle sets a ceiling, requiring that, once none of the above justifications remain, personal data is deleted or anonymised. Section 5 reflects Data Sole’s judgement of where these sources intersect for each data category.

4. Retention Principles

Data Sole shall:

  • Collect and retain only information reasonably required for legitimate purposes.
  • Establish an appropriate retention period based on the nature and purpose of the information.
  • Periodically review retained information.
  • Restrict access to archived and retained information.
  • Protect retained information using appropriate technical and organisational security measures.
  • Delete, anonymise or securely dispose of information when its retention period expires.
  • Suspend scheduled deletion where information is required for litigation, regulatory investigation, fraud investigation, security incidents or another lawful preservation requirement.

These principles apply cumulatively rather than in isolation. For example, a security log may be collected for a legitimate purpose (principle 1), assigned a 12-month standard period (principle 2), reviewed periodically to confirm it is still needed (principle 3), access-restricted to security personnel (principle 4), encrypted at rest (principle 5), and ultimately deleted on schedule (principle 6) — unless a legal hold is placed on it in connection with an active investigation (principle 7).

4.1 Data Minimisation at the Point of Collection

Retention decisions begin before information is ever stored. Where a system or process can be configured to avoid collecting a data field that is not required, Data Sole prefers that configuration over collecting the field and relying solely on later deletion. Engineering and product teams are expected to consider retention implications during design, consistent with data-protection-by-design principles.

4.2 Periodic Review

Retained information is subject to periodic review, both automated (for example, scheduled purge jobs operating against the retention schedule in Section 5) and manual (for example, an annual review by the Data Protection Lead of categories that do not lend themselves to automated deletion, such as archived governance records).

5. Standard Retention Schedule

The table below sets out Data Sole’s standard retention periods by data category. These periods represent Data Sole’s default position and are applied unless a longer or shorter period is required by law, contract, customer configuration, or a documented exception under Section 16.

Data CategoryStandard Retention Period
Active customer account informationDuration of account/service relationship
Closed customer account informationUp to 6 years after termination where reasonably required
Contracts and commercial agreementsContract duration + up to 6 years
Invoices, accounting and tax recordsGenerally 6 years or longer where legally required
Payment transaction recordsUp to 6 years, subject to applicable requirements
Customer support recordsNormally up to 3 years after case closure
Sales enquiries and prospective customer recordsNormally up to 2 years after last meaningful interaction
Marketing consent/suppression recordsFor as long as required to demonstrate consent, objection or suppression
Authentication and access logsNormally 12 months
Infrastructure and system logsNormally 12 months
Cybersecurity and security-monitoring logsNormally up to 24 months
Security incident recordsUp to 6 years after closure where appropriate
Customer cloud contentFor the duration determined by the customer/service configuration
Deleted customer cloud contentDeleted according to the applicable service deletion and backup lifecycle
Operational backupsNormally 30–90 days unless a different service-specific period applies
Employee/personnel recordsEmployment duration + normally up to 6 years
Recruitment records for unsuccessful applicantsNormally 6–12 months
Supplier and contractor recordsRelationship duration + up to 6 years
Corporate governance recordsUp to 10 years or permanently where appropriate
Legal disputes/investigationsUntil the matter and applicable limitation periods have concluded

These periods are default guidelines rather than fixed ceilings or floors in every case. A different retention period may apply where required by law, regulation, contractual obligations, customer configuration or documented operational requirements. Where this Policy is silent on a specific category of information not listed above, the Data Protection Lead shall determine an appropriate period by reference to the nearest analogous category and the principles in Section 4, and shall document that determination.

5.1 Illustrative Application

To illustrate how the schedule operates in practice: a customer support ticket relating to a billing dispute is normally retained for up to three years after the case is closed, to allow Data Sole to respond to any follow-up query or complaint. If that same ticket forms part of a payment chargeback investigation, the underlying payment transaction records associated with it may be retained for up to six years under the payment transaction records category, even though the support ticket itself is deleted on the shorter three-year cycle. Each category is therefore assessed independently, even where records relating to the same customer interaction sit in more than one system.

A second example: when a prospective customer submits a sales enquiry but does not proceed to purchase a service, that enquiry record is normally retained for up to two years after the last meaningful interaction, after which it is deleted unless the individual has separately opted in to marketing communications, in which case the marketing consent record described below governs the relevant contact preference data. A third example concerns infrastructure logs: a system log entry recording routine, non-security-relevant activity is retained for around 12 months to support troubleshooting and capacity planning, whereas a log entry flagged as part of a security-monitoring alert may be extracted and retained for up to 24 months, or longer under a legal hold, even though the surrounding routine log data is deleted on the shorter cycle.

5.2 Category Ownership

Each data category in the schedule has a designated internal owner responsible for ensuring the applicable retention period is correctly implemented in the relevant system, for responding to queries about that category, and for participating in the annual Policy review described in Section 17. Category ownership generally aligns with the functional responsibilities set out in Section 15.

6. Customer-Controlled Cloud Data

Where Data Sole acts as a data processor and provides infrastructure, hosting, storage or related cloud services, customers remain responsible for determining appropriate retention periods for personal data they control, unless otherwise specified by the service agreement. Data Sole does not independently review, and cannot be expected to review, the content that customers choose to store within their own environments.

Where technically supported, customers may configure retention, backup, archival and deletion settings through Data Sole services. Customers are encouraged to configure these settings to reflect their own regulatory obligations and internal policies, and Data Sole’s support and documentation resources are available to assist customers in understanding the options offered by each service.

Data Sole will process customer-controlled information in accordance with the applicable contractual terms and Data Processing Agreement. Where a Data Processing Agreement specifies retention or deletion terms that differ from this Policy’s general defaults, the Data Processing Agreement governs the customer content in question.

7. Account and Service Termination

When a customer terminates a Data Sole service, customer data associated with that service will enter the applicable deletion process. The precise mechanics of this process — including timing, the systems involved and any manual verification steps — vary by service and are described in the relevant service documentation or contractual terms.

Data Sole may provide a limited period during which customers can retrieve or export their information before permanent deletion. Customers are strongly encouraged to export any data they wish to retain before this period elapses, as Data Sole cannot guarantee recovery of information once the export window has closed and deletion has proceeded.

Residual copies may temporarily remain within encrypted backup systems until the relevant backup rotation expires. Backup information shall not ordinarily be restored except for legitimate disaster recovery, security, resilience or legal purposes. This means that, following termination and the expiry of any export window, a customer’s data may continue to exist in encrypted backup media for a limited period even though it is no longer accessible or restorable in the ordinary course of business.

8. Backups and Disaster Recovery

Data Sole may maintain backups to protect the availability, integrity and resilience of its services. Backups exist to support recovery from technical failure, data corruption, security incidents or catastrophic loss, not as a secondary long-term archive of customer or business information.

Backup copies shall:

  • Be appropriately secured;
  • Have access restricted to authorised personnel and systems;
  • Be subject to defined lifecycle and rotation procedures;
  • Not be retained indefinitely unless specifically required; and
  • Be securely overwritten, deleted or rendered inaccessible following expiration.

Deletion from a production system may therefore not result in immediate deletion from every backup copy. This is an inherent characteristic of backup architecture: a backup capturing a point-in-time snapshot of a system will, by design, retain a copy of data that has since been deleted from the live environment, until that backup itself is rotated out and overwritten in line with the applicable schedule set out in Section 5.

9. Security Logs

Data Sole may retain network, authentication, API, administrative and security logs for purposes including:

  • Cybersecurity monitoring;
  • Detection of unauthorised access;
  • Fraud prevention;
  • Incident investigation;
  • Service reliability;
  • Troubleshooting;
  • Audit and compliance; and
  • Protection of Data Sole and its customers.

Access to security logs shall be restricted according to operational requirements and appropriate access-control principles, including the principle of least privilege. Only personnel with a genuine operational need — typically within Security Operations, Infrastructure Engineering or, where relevant, Legal and Compliance — may access raw security and authentication logs.

Where a security log is required in connection with a specific investigation, the relevant extract may be preserved beyond the standard 12–24 month period under a legal hold, as described in Section 10, while the remainder of the log population continues to be deleted on schedule.

10. Legal Holds

Normal deletion procedures may be suspended where information is reasonably required in connection with:

  • Existing or anticipated litigation;
  • Court orders;
  • Regulatory investigations;
  • Law-enforcement requirements;
  • Internal investigations;
  • Cybersecurity incidents;
  • Fraud investigations; or
  • Other legal obligations.

Information subject to a legal hold shall be retained until authorised personnel — normally the Data Protection Lead in consultation with Legal and Compliance — determine that the hold can lawfully be removed. A legal hold takes precedence over the standard retention periods in Section 5 for the specific information it covers, and over any scheduled automated deletion job.

10.1 Administering a Legal Hold

Where a legal hold is applied, Data Sole shall record: the scope of the information covered; the reason for the hold and the person or body that requested or authorised it; the date the hold was applied; and the date, if known, on which the hold is expected to be reviewed. Legal holds are reviewed periodically to confirm they remain necessary, and are lifted promptly once the underlying matter has concluded, at which point the affected information returns to its normal retention and deletion cycle.

11. Secure Disposal

At the end of an applicable retention period, information shall be securely deleted, anonymised or otherwise rendered irretrievable where reasonably practicable. Data Sole shall use disposal methods appropriate to the sensitivity and storage medium of the information, which may include cryptographic erasure, secure overwriting, or destruction of physical media.

Physical media containing confidential or personal information shall be securely destroyed or sanitised before disposal or reuse. Where third-party disposal contractors are used for physical media destruction, Data Sole shall obtain appropriate assurance or certification of secure destruction.

Where deletion is not immediately or fully practicable — for example, because information persists within immutable backup media pending rotation — Data Sole shall restrict further use of that information and ensure it is deleted at the earliest practicable opportunity consistent with Section 8.

11.1 Disposal Method by Medium

The appropriate disposal method depends on where and how information is stored. Information held in production databases and object storage is typically deleted through the owning system’s standard deletion function, followed by removal from any associated caches or search indices. Information held in encrypted backup media is not individually purged but is rendered inaccessible when the encryption key is destroyed or when the backup set is overwritten during the normal rotation cycle described in Section 8. Information held on physical media, including decommissioned hard drives, tapes and paper records, is destroyed using a method appropriate to the medium, such as degaussing, shredding, or certified physical destruction carried out by a vetted disposal contractor. Records of disposal, including certificates of destruction where obtained from a third-party contractor, are retained for audit purposes.

12. Data Subject Rights

Where Data Sole acts as a controller, individuals may have rights under applicable data-protection legislation, including rights relating to access, rectification, erasure, restriction, objection and data portability.

A request for erasure does not necessarily require immediate deletion of every record. Data Sole may retain information where continued processing is necessary or permitted under applicable law — for example, to comply with a statutory retention obligation, to establish, exercise or defend legal claims, or where information is subject to a legal hold under Section 10. Where Data Sole is unable to fully comply with an erasure request, it shall explain to the individual which information is retained and why.

Requests relating to data subject rights should be directed to Data Sole through the contact channels published in Data Sole’s Privacy Policy, and will be handled by the Data Protection Lead in accordance with applicable statutory timeframes.

13. Third-Party Processors

Third-party providers processing information on behalf of Data Sole must be subject to appropriate contractual and data-protection requirements, including obligations relating to security, confidentiality and retention that are consistent with this Policy.

Where appropriate, Data Sole shall require processors to delete or return information following termination of their services and to apply suitable security and retention controls throughout the period they hold Data Sole information. Data Sole maintains a record of the sub-processors it engages and the categories of information each sub-processor may access.

Before engaging a new third-party processor that will handle personal data on Data Sole’s behalf, Data Sole conducts a proportionate due-diligence review of that provider’s security and data-protection practices, and incorporates appropriate retention and deletion obligations into the resulting contract. Existing processor relationships are reviewed periodically as part of the annual Policy review described in Section 17, or sooner if the nature of the processing changes materially.

14. International Processing

Where information is transferred internationally, Data Sole shall implement appropriate safeguards where required by applicable data-protection legislation, such as the UK’s International Data Transfer Agreement or Addendum, or an applicable adequacy decision.

Retention requirements continue to apply regardless of the geographical location in which authorised processing occurs. A retention period set out in Section 5 applies to the information itself, not merely to the copy of it that happens to be stored within the United Kingdom, and Data Sole’s processors and sub-processors are required to observe equivalent retention and deletion obligations wherever they process Data Sole information.

15. Roles and Responsibilities

Data owners and responsible Data Sole personnel must ensure that information under their control is appropriately classified, retained and disposed of. The table below summarises indicative responsibilities across the organisation; it does not replace more detailed role descriptions maintained separately by Data Sole.

RoleResponsibility
Board of DirectorsUltimate accountability for information governance; approves this Policy and material changes to it.
Data Protection LeadOwns this Policy; interprets retention questions; approves exceptions; liaises with the ICO where necessary; maintains the Record of Processing Activities.
Service/Infrastructure EngineeringImplements retention, archival and deletion mechanisms within cloud platforms, storage systems and backup tooling; maintains deletion logs.
Customer Support & BillingApplies retention periods to support tickets, correspondence and billing records; escalates erasure requests.
Security OperationsManages retention and secure disposal of authentication, network, API and security-monitoring logs; maintains chain of custody during incidents.
Human ResourcesApplies retention periods to personnel, recruitment and contractor records.
Legal & ComplianceAuthorises and manages legal holds; advises on statutory retention minimums; reviews Policy exceptions.
All PersonnelMust not retain information outside approved systems, must not circumvent deletion controls, and must report suspected non-compliance.

Personnel must not retain information indefinitely merely because storage capacity is available. The availability of low-cost storage is not, by itself, a legitimate basis for retaining information beyond the periods set out in this Policy.

15.1 Training and Awareness

Personnel whose roles involve regular handling of personal or confidential information receive periodic training that covers, among other things, the retention periods relevant to their function, how to recognise information that may need to be placed under a legal hold, and how to raise a query or exception request with the Data Protection Lead. New starters are introduced to this Policy as part of onboarding for relevant roles.

Unauthorised copying, personal archiving or deliberate circumvention of retention and deletion controls is prohibited. This includes, for example, exporting customer records to a personal device or unmanaged storage location outside the systems approved for that data category, and disabling or bypassing an automated deletion job without documented authorisation.

16. Exceptions

Exceptions to this Policy must have a legitimate legal, regulatory, contractual, security or business justification and should be appropriately documented and authorised, normally by the Data Protection Lead. An exception request should identify the information concerned, the proposed alternative retention period, the justification, and the date on which the exception will be reviewed.

Where legal requirements conflict with a standard retention period contained in this Policy, the applicable legal requirement takes precedence. Where a conflict arises between two applicable legal requirements — for example, an erasure request under UK GDPR and a statutory minimum retention period under tax legislation — Data Sole shall apply the requirement that permits or requires the longer retention period, and shall restrict processing of the information to the purpose for which it continues to be lawfully retained.

17. Policy Review

Data Sole shall review this Policy at least annually and following significant changes to:

  • Applicable legislation or regulatory requirements;
  • Data Sole’s services;
  • Cloud infrastructure;
  • Processing activities;
  • Security requirements; or
  • Organisational structure.

Retention periods may be amended following such reviews. Material changes to this Policy shall be approved by the Data Protection Lead and, where appropriate, communicated to affected personnel and, where required, to customers.

18. Compliance

Failure by employees, contractors or authorised personnel to comply with this Policy may result in restriction or removal of access, disciplinary action, termination of contractual arrangements or other appropriate measures.

Data Sole reserves the right to update this Policy as its services, technologies and legal obligations evolve. Questions about this Policy, or requests for an exception under Section 16, should be directed to the Data Protection Lead.

Appendix A: Definitions

  • “Anonymisation” means processing personal data so that the individual is no longer identifiable, either directly or indirectly, and the process cannot reasonably be reversed.
  • “Controller” means the entity that determines the purposes and means of processing personal data.
  • “Data Subject” means an identified or identifiable living individual to whom personal data relates.
  • “Legal Hold” means a documented instruction to suspend the routine deletion of specified information pending resolution of a legal, regulatory or investigative matter.
  • “Personal Data” means any information relating to an identified or identifiable living individual.
  • “Processor” means an entity that processes personal data on behalf of, and under the instructions of, a controller.
  • “Retention Period” means the length of time information is kept before it is deleted, anonymised or otherwise disposed of.
  • “Secure Disposal” means the deletion, destruction or anonymisation of information using a method appropriate to its sensitivity and storage medium, such that it cannot reasonably be reconstructed.

Appendix B: Related Documents

This Policy should be read alongside the following Data Sole documents, where applicable:

  • Data Sole Privacy Policy
  • Data Sole Information Security Policy
  • Data Sole Data Processing Agreement (standard terms)
  • Data Sole Incident Response Plan
  • Data Sole Acceptable Use Policy

Appendix C: Worked Scenarios

Scenario 1: Customer Closes a Hosting Account

A customer terminates their virtual machine hosting service. Data Sole notifies the customer of the applicable export window before deletion proceeds. The customer downloads the data they wish to keep. At the end of the export window, the account’s live data is deleted from production storage. Encrypted backup copies containing snapshots taken before termination persist for a limited period consistent with the operational backup rotation schedule in Section 5, after which they are overwritten and become unrecoverable. Billing records relating to the account are retained separately for up to six years to meet accounting and tax obligations, even though the hosted content itself has been deleted.

Scenario 2: Suspicious Login Activity Triggers an Investigation

Security Operations identifies anomalous authentication activity on a customer-facing portal. The relevant authentication and access logs, which would ordinarily be deleted after 12 months, are placed under a legal hold pending investigation. The scope of the hold is documented, limited to the accounts and time window relevant to the incident, and reviewed once the investigation concludes. Logs outside the scope of the hold continue to be deleted on the standard schedule. Once the investigation and any related regulatory or law-enforcement engagement has concluded, the held logs are released back into the normal retention cycle, or retained for up to six years as a security incident record if that better reflects their ongoing relevance.

Scenario 3: An Individual Requests Erasure of Their Personal Data

An individual who was formerly a customer submits an erasure request. The Data Protection Lead reviews the request against the categories of information Data Sole holds about the individual. Support correspondence within the three-year retention window is deleted. Invoices and payment records are retained for the remainder of the six-year period required for accounting purposes, with processing restricted to that purpose only. The individual is informed which categories have been deleted and which are retained, together with the reason for continued retention, in line with Section 12.

Scenario 4: A Supplier Contract Ends

A supplier relationship ends after the supplier’s services are replaced. Operational records generated during the relationship, such as service reports and correspondence, are retained for up to six years after the relationship ends, consistent with general contractual and commercial record-keeping practice, in case questions arise about work performed during the relationship. The supplier’s access credentials are revoked immediately on termination, independent of how long the underlying records are retained.

Document Control

Version 1.1 – 27 August 2026: Expanded edition, incorporating additional explanatory guidance, a roles and responsibilities table, illustrative application notes, and definitions and related-documents appendices, without altering the standard retention periods set out in Version 1.0.

Version 1.0 – 27 August 2026: Initial issue.

Contact

Skydatasol Holdings Plc., 321-323 High Road, Chadwell Heath, London RM6 6AX. Email cloud@skydatasol.com.