POLICY AND TRUST

Data Retention and Deletion

How drafts, confirmed requests, files, messages, audit records, and deletion requests are handled.

Effective 24 July 2026 · Version 2.0

Retention principle

Information is kept only as long as needed for request review, service delivery, payment and dispute records, security, legal obligations, and accountable operations.

Unsubmitted drafts

Unsubmitted request drafts remain in browser storage on your device until you submit, clear the draft, or clear browser storage. They are not authoritative server records.

Request records and files

Confirmed requests, messages, audit records, and private files follow the configured retention schedule. Quarantined, rejected, duplicate, and failed-upload records should be removed earlier where they are no longer needed.

Specialist applications and identity documents

Application records are retained while a review, activation, working relationship, dispute, security investigation, or legal obligation remains active. Unsuccessful application documents should be removed on the configured recruitment-retention schedule unless a shorter or longer period is required by law.

Identity and qualification documents are private, scanner-gated files. They are not included in public pages, analytics exports, or assignment records.

Click analytics and IP addresses

First-party click events, including raw IP addresses, are retained for 90 days by default. The live retention value is enforced by the analytics store and may be shortened where operationally appropriate. Analytics exports remain admin-restricted and should be deleted when no longer needed.

Deletion requests

You may request deletion through the student workspace or approved contact channel. Identity and authority must be verified. Some information may be retained where required for legal, financial, fraud-prevention, dispute, or audit obligations.