Section 01

Overview

At Aevum News, your privacy isn't an afterthought — it's embedded into how we operate. This Data Retention Policy explains how long we keep the information you share with us, why we retain it for those specific periods, and what we do with your data once it's no longer needed.

We believe in data minimization. We only collect what we need, keep it only as long as necessary, and dispose of it securely when retention purposes expire. This policy works in conjunction with our Privacy Policy and together they form the foundation of our data protection commitments.

Key principle: We never retain personal data for longer than necessary to fulfill the purpose for which it was collected, unless legally required or with your explicit consent.

This policy applies to all data collected through the Aevum News website, mobile applications, newsletter subscriptions, account registration, customer support interactions, and any other services we provide.

Section 02

Scope & Guiding Principles

Our data retention practices are guided by six core principles that align with international data protection standards including GDPR, CCPA, and other applicable frameworks.

Our Six Retention Principles

  • Purpose-Limited: Data is retained only as long as needed to achieve the specific, explicit purpose for which it was collected.
  • Minimization: We collect the minimum amount of data necessary and retain the minimum duration required.
  • Proactive Deletion: Automated systems flag and securely delete data when retention periods expire — no manual intervention required.
  • Transparency: We clearly communicate what data we hold, why, and for how long. No hidden practices.
  • User Control: You can request deletion, export, or restriction of your data at any time, regardless of standard retention periods.
  • Legal Compliance: Where law requires longer retention, we comply but implement access controls and anonymization where possible.
ℹ️

Scope note: This policy applies to all individuals whose data Aevum News processes, including readers, subscribers, registered users, newsletter recipients, and support contacts. It covers data collected in the EU, US, UK, and globally.

Section 03

Data We Collect & Why

Understanding what we collect is essential to understanding our retention practices. Below is a comprehensive breakdown of data categories and the purposes they serve.

d>
Data Category Examples Collection Purpose When Collected
Account Data Name, email, password hash, profile preferences Manage user accounts, authentication Registration
Newsletter Data Email address, subscription preferences Deliver newsletter, manage preferences Newsletter signup
Usage Data Pages visited, time on site, click patterns, device info Improve experience, analytics, personalization Site browsing
Communication Data Emails, support tickets, feedback, comments Respond to inquiries, provide support User contact
Payment Data Transaction records, billing address, payment method tokens Process subscriptions, billing, refunds Premium subscription
Technical Logs IP addresses, server logs, error reports, cookies Security, performance monitoring, debugging Automatically
Content Interaction Articles read, saved bookmarks, reading history, ratings Content recommendations, personalized experience Content engagement
Marketing Data Email open rates, campaign interactions, ad preferences Improve communications, measure effectiveness Marketing communications
⚠️

Important: We do not sell your personal data to third parties. Payment processing is handled by PCI-compliant partners who retain only the data necessary for transaction processing, governed by their own retention policies.

Section 04

Retention Periods

Each category of data has a defined retention period. Once this period expires, data is automatically and securely deleted unless a legal obligation or your active account status requires continued retention.

Data Type Retention Period Basis
Active Account Data Duration of Account Service provision; deleted upon account closure + 30 days grace
Inactive Accounts 12 months After 12 months of inactivity, data is anonymized or deleted
Newsletter Subscriptions Until Unsubscribed Retained while subscribed; deleted within 7 days of unsubscribe
Browsing/Usage Data 14 days Anonymized analytics retained up to 13 months for trend analysis
Server & Security Logs 90 days Active security monitoring; older logs are anonymized
Support Communications 24 months Quality improvement, training, and legal compliance
Payment/Transaction Records 7 years Tax and accounting legal requirements
Comments & User Content Indefinite Retained with attribution unless deleted by user or for moderation
Marketing Interaction Data 24 months Campaign analysis and improvement
Consent Records Duration + 5 years Proof of lawful processing; retained after deletion for audit
Cookie Data 7–30 days Session cookies expire at session end; persistent per cookie type
💡

Grace period: When you delete your account, we retain minimal data for 30 days to allow account recovery if the deletion was accidental. After 30 days, all personally identifiable data is permanently erased.

Section 05

Storage & Security Measures

How we store your data is just as important as how long we keep it. We implement enterprise-grade security across our entire data infrastructure.

Infrastructure

  • Data is hosted in SOC 2 Type II certified data centers with 24/7 physical and electronic surveillance
  • All data at rest is encrypted using AES-256 encryption
  • Data in transit is protected via TLS 1.3 across all connections
  • Our cloud infrastructure is distributed across geographically redundant regions to ensure availability while maintaining data sovereignty

Access Controls

  • Access to personal data follows the principle of least privilege — only team members who need it for their specific role can access it
  • Multi-factor authentication (MFA) is required for all administrative access to data systems
  • Every access to personal data is logged and auditable
  • Regular access reviews (quarterly) ensure permissions remain appropriate

Secure Deletion

When retention periods expire, we don't simply "delete" data. We follow industry-standard secure erasure procedures:

  • Digital data: Overwritten multiple times using NIST SP 800-88 compliant methods
  • Database records: Permanently removed from primary and backup systems within 30 days
  • Physical media: Degaussed or shredded when end-of-life is reached
  • Cloud storage: Cryptographic erasure — deletion of encryption keys renders data irretrievable
ℹ️

Backup caveat: Data may persist in backup systems for up to 30 days after primary deletion. This is a technical necessity and we treat backed-up personal data with the same protection level as live data.

Section 06

Data Lifecycle

Understanding what happens to your data from collection to deletion helps build trust. Here's the complete lifecycle of personal data at Aevum News.

📥
Collection
Consent-based or necessary
🔐
Encryption
AES-256 at rest
🗄️
Secure Storage
Access-controlled
⏱️
Retention Timer
Automated tracking
📊
Review
Still needed?
🗑️
Secure Deletion
NIST-compliant

Automated Retention Management

We don't rely on manual processes to manage data retention. Our automated systems ensure that every data element is tagged with its creation date, purpose, and expiration date. When the clock runs out, deletion happens without human intervention.

  • Data classification applied at point of collection
  • Retention timers start immediately upon data entry
  • Automated notifications sent 30 days before scheduled deletion
  • Deletion executed and logged for audit purposes
  • Quarterly audits verify system compliance
Section 07

Your Rights Over Your Data

No matter our standard retention periods, you have the right to exercise control over your personal data at any time. Here's what you can do:

Right Description How to Exercise
Access Request a copy of all personal data we hold about you Submit request via account settings or privacy dashboard
Correction Update or correct inaccurate personal information Edit directly in account settings or contact support
Deletion Request permanent erasure of your data before its scheduled retention expiry Account deletion in settings or formal request via email
Portability Download your data in a machine-readable, common format (JSON, CSV) Data export tool in privacy dashboard
Restriction Limit how we process your data while a dispute is resolved Submit restriction request through privacy form
Objection Object to processing based on legitimate interest or direct marketing Opt-out links in emails or privacy settings
Complaint Lodge a complaint with a supervisory authority EU: your local DPA | UK: ICO | US: state attorney general

Response time: We respond to all data rights requests within 30 days (extendable to 60 days for complex requests). You'll receive confirmation within 48 hours of submitting your request. There is no fee for exercising any of these rights.

Section 09

International Data Transfers

As a global news organization, some of our data processing involves cross-border transfers. We ensure these transfers meet the highest protection standards.

All international transfers of personal data are governed by:

  • EU Standard Contractual Clauses (SCCs) for transfers from the European Economic Area
  • UK International Data Transfer Addendum for transfers from the United Kingdom
  • Supplementary safeguards including encryption, access controls, and contractual obligations
  • Regular Transfer Impact Assessments (TIAs) to evaluate destination country risks

Our primary data processing occurs in the United States, United Kingdom, and European Union (Ireland). Third-party service providers may process data in additional jurisdictions, and we require contractual protections for all such transfers.

⚠️

EU readers: If you are located in the EEA and your data is transferred outside the EU, we rely on the European Commission's adequacy decisions or Standard Contractual Clauses to ensure an equivalent level of data protection.

Section 10

Special Circumstances

There are situations where standard retention periods may be extended. We document and justify every exception.

Extended Retention Triggers

  • Legal disputes: If data is relevant to ongoing or anticipated legal proceedings, litigation holds may extend retention until the matter is resolved
  • Regulatory investigations: Data may be preserved at the request of regulatory bodies or law enforcement
  • Fraud prevention: Data related to suspected or confirmed fraud may be retained for investigation and prevention purposes
  • Security incidents: Logs and related data from security incidents are preserved for forensic analysis
  • Archive purposes: User-generated content (comments, submissions) may be retained indefinitely for journalistic archive purposes, with the option to request removal
ℹ️

Transparency commitment: If we extend the retention of your personal data beyond standard periods for any of the above reasons, and you request information about your data, we will inform you of the reason for the extension and the expected duration.

Data Breach Protocol

In the event of a data breach affecting retained personal data:

  1. Our security team will contain and assess the breach within 24 hours of detection
  2. Affected individuals will be notified within 72 hours where required by law
  3. Appropriate data protection authorities will be notified as mandated
  4. A post-incident review will identify and remediate root causes
  5. Compromised data will be secured or permanently deleted as appropriate
Section 11

Frequently Asked Questions

How quickly is my data deleted after I close my account?
Upon account closure, your personal data enters a 30-day grace period. During this time, you can recover your account and all data remains intact. After 30 days, all personally identifiable information is permanently and securely erased from our active systems. Data in backup systems is deleted within an additional 30 days. Financial records subject to legal retention requirements are anonymized rather than deleted.
Can I get a copy of all data you have on me?
Absolutely. You can request a complete data export through your account's Privacy Dashboard, or by emailing privacy@aevumnews.com. We'll provide the data in a common, machine-readable format (JSON or CSV) within 30 days. There's no charge for this service.
Why do you keep payment data for 7 years?
Tax authorities and commercial law in multiple jurisdictions require businesses to retain financial transaction records for a minimum of 7 years. This includes records of purchases, refunds, and billing addresses. We store only the minimum data necessary — you'll never see your full card number in our systems, and we use tokenization for payment processing.
What does "anonymization" mean?
Anonymization means removing or altering personal identifiers so that the data can no longer be linked back to an individual. Once data is properly anonymized, it is no longer considered "personal data" under GDPR and similar frameworks. We may retain anonymized data for analytics, research, and trend analysis purposes without time limitation.
Do you share my data with advertising partners?
We do not sell your personal data. For advertising purposes, we may share limited, non-personally-identifiable data (such as aggregated demographics or anonymized browsing patterns) with trusted ad partners. We never share names, email addresses, or account details with third-party advertisers. You can opt out of all personalized advertising through your privacy settings.
What happens to my data if Aevum News shuts down?
In the unlikely event that Aevum News ceases operations, our data protection obligations persist. We have documented procedures for secure data deletion across all systems. If acquired by another entity, all personal data would be transferred subject to updated privacy notices and your continued consent. We would notify all users well in advance of any such transition.
Can I request deletion of my browsing history?
Yes. Browsing and usage data is already set to auto-delete after 14 days. However, if you'd like this data erased immediately, you can do so through the Privacy Dashboard in your account settings, or by sending a deletion request to our privacy team. The deletion takes effect within 72 hours.
Section 12

Questions? Contact Our Data Protection Team

If you have questions about this policy, want to exercise your rights, or need clarification about how your data is handled, our Data Protection Officer (DPO) and privacy team are here to help.

🔒 Data Protection Office

We aim to respond to all inquiries within 48 hours. For formal data rights requests, the full response timeline is 30 days.

💡

EU residents: You have the right to lodge a complaint with your local supervisory authority. Find your authority at edpb.europa.eu.