Overview
At Aevum News, your privacy isn't an afterthought — it's embedded into how we operate. This Data Retention Policy explains how long we keep the information you share with us, why we retain it for those specific periods, and what we do with your data once it's no longer needed.
We believe in data minimization. We only collect what we need, keep it only as long as necessary, and dispose of it securely when retention purposes expire. This policy works in conjunction with our Privacy Policy and together they form the foundation of our data protection commitments.
Key principle: We never retain personal data for longer than necessary to fulfill the purpose for which it was collected, unless legally required or with your explicit consent.
This policy applies to all data collected through the Aevum News website, mobile applications, newsletter subscriptions, account registration, customer support interactions, and any other services we provide.
Scope & Guiding Principles
Our data retention practices are guided by six core principles that align with international data protection standards including GDPR, CCPA, and other applicable frameworks.
Our Six Retention Principles
- Purpose-Limited: Data is retained only as long as needed to achieve the specific, explicit purpose for which it was collected.
- Minimization: We collect the minimum amount of data necessary and retain the minimum duration required.
- Proactive Deletion: Automated systems flag and securely delete data when retention periods expire — no manual intervention required.
- Transparency: We clearly communicate what data we hold, why, and for how long. No hidden practices.
- User Control: You can request deletion, export, or restriction of your data at any time, regardless of standard retention periods.
- Legal Compliance: Where law requires longer retention, we comply but implement access controls and anonymization where possible.
Scope note: This policy applies to all individuals whose data Aevum News processes, including readers, subscribers, registered users, newsletter recipients, and support contacts. It covers data collected in the EU, US, UK, and globally.
Data We Collect & Why
Understanding what we collect is essential to understanding our retention practices. Below is a comprehensive breakdown of data categories and the purposes they serve.
| Data Category | Examples | Collection Purpose | When Collected |
|---|---|---|---|
| Account Data | Name, email, password hash, profile preferences | Manage user accounts, authentication | Registration |
| Newsletter Data | Email address, subscription preferences | Deliver newsletter, manage preferences | Newsletter signup | d>
| Usage Data | Pages visited, time on site, click patterns, device info | Improve experience, analytics, personalization | Site browsing |
| Communication Data | Emails, support tickets, feedback, comments | Respond to inquiries, provide support | User contact |
| Payment Data | Transaction records, billing address, payment method tokens | Process subscriptions, billing, refunds | Premium subscription |
| Technical Logs | IP addresses, server logs, error reports, cookies | Security, performance monitoring, debugging | Automatically |
| Content Interaction | Articles read, saved bookmarks, reading history, ratings | Content recommendations, personalized experience | Content engagement |
| Marketing Data | Email open rates, campaign interactions, ad preferences | Improve communications, measure effectiveness | Marketing communications |
Important: We do not sell your personal data to third parties. Payment processing is handled by PCI-compliant partners who retain only the data necessary for transaction processing, governed by their own retention policies.
Retention Periods
Each category of data has a defined retention period. Once this period expires, data is automatically and securely deleted unless a legal obligation or your active account status requires continued retention.
| Data Type | Retention Period | Basis |
|---|---|---|
| Active Account Data | Duration of Account | Service provision; deleted upon account closure + 30 days grace |
| Inactive Accounts | 12 months | After 12 months of inactivity, data is anonymized or deleted |
| Newsletter Subscriptions | Until Unsubscribed | Retained while subscribed; deleted within 7 days of unsubscribe |
| Browsing/Usage Data | 14 days | Anonymized analytics retained up to 13 months for trend analysis |
| Server & Security Logs | 90 days | Active security monitoring; older logs are anonymized |
| Support Communications | 24 months | Quality improvement, training, and legal compliance |
| Payment/Transaction Records | 7 years | Tax and accounting legal requirements |
| Comments & User Content | Indefinite | Retained with attribution unless deleted by user or for moderation |
| Marketing Interaction Data | 24 months | Campaign analysis and improvement |
| Consent Records | Duration + 5 years | Proof of lawful processing; retained after deletion for audit |
| Cookie Data | 7–30 days | Session cookies expire at session end; persistent per cookie type |
Grace period: When you delete your account, we retain minimal data for 30 days to allow account recovery if the deletion was accidental. After 30 days, all personally identifiable data is permanently erased.
Storage & Security Measures
How we store your data is just as important as how long we keep it. We implement enterprise-grade security across our entire data infrastructure.
Infrastructure
- Data is hosted in SOC 2 Type II certified data centers with 24/7 physical and electronic surveillance
- All data at rest is encrypted using AES-256 encryption
- Data in transit is protected via TLS 1.3 across all connections
- Our cloud infrastructure is distributed across geographically redundant regions to ensure availability while maintaining data sovereignty
Access Controls
- Access to personal data follows the principle of least privilege — only team members who need it for their specific role can access it
- Multi-factor authentication (MFA) is required for all administrative access to data systems
- Every access to personal data is logged and auditable
- Regular access reviews (quarterly) ensure permissions remain appropriate
Secure Deletion
When retention periods expire, we don't simply "delete" data. We follow industry-standard secure erasure procedures:
- Digital data: Overwritten multiple times using NIST SP 800-88 compliant methods
- Database records: Permanently removed from primary and backup systems within 30 days
- Physical media: Degaussed or shredded when end-of-life is reached
- Cloud storage: Cryptographic erasure — deletion of encryption keys renders data irretrievable
Backup caveat: Data may persist in backup systems for up to 30 days after primary deletion. This is a technical necessity and we treat backed-up personal data with the same protection level as live data.
Data Lifecycle
Understanding what happens to your data from collection to deletion helps build trust. Here's the complete lifecycle of personal data at Aevum News.
Consent-based or necessary
AES-256 at rest
Access-controlled
Automated tracking
Still needed?
NIST-compliant
Automated Retention Management
We don't rely on manual processes to manage data retention. Our automated systems ensure that every data element is tagged with its creation date, purpose, and expiration date. When the clock runs out, deletion happens without human intervention.
- Data classification applied at point of collection
- Retention timers start immediately upon data entry
- Automated notifications sent 30 days before scheduled deletion
- Deletion executed and logged for audit purposes
- Quarterly audits verify system compliance
Your Rights Over Your Data
No matter our standard retention periods, you have the right to exercise control over your personal data at any time. Here's what you can do:
| Right | Description | How to Exercise |
|---|---|---|
| Access | Request a copy of all personal data we hold about you | Submit request via account settings or privacy dashboard |
| Correction | Update or correct inaccurate personal information | Edit directly in account settings or contact support |
| Deletion | Request permanent erasure of your data before its scheduled retention expiry | Account deletion in settings or formal request via email |
| Portability | Download your data in a machine-readable, common format (JSON, CSV) | Data export tool in privacy dashboard |
| Restriction | Limit how we process your data while a dispute is resolved | Submit restriction request through privacy form |
| Objection | Object to processing based on legitimate interest or direct marketing | Opt-out links in emails or privacy settings |
| Complaint | Lodge a complaint with a supervisory authority | EU: your local DPA | UK: ICO | US: state attorney general |
Response time: We respond to all data rights requests within 30 days (extendable to 60 days for complex requests). You'll receive confirmation within 48 hours of submitting your request. There is no fee for exercising any of these rights.
Legal Basis for Retention
Under data protection law, every retention period must have a legal justification. Here are the legal bases that govern our data retention practices:
International Data Transfers
As a global news organization, some of our data processing involves cross-border transfers. We ensure these transfers meet the highest protection standards.
All international transfers of personal data are governed by:
- EU Standard Contractual Clauses (SCCs) for transfers from the European Economic Area
- UK International Data Transfer Addendum for transfers from the United Kingdom
- Supplementary safeguards including encryption, access controls, and contractual obligations
- Regular Transfer Impact Assessments (TIAs) to evaluate destination country risks
Our primary data processing occurs in the United States, United Kingdom, and European Union (Ireland). Third-party service providers may process data in additional jurisdictions, and we require contractual protections for all such transfers.
EU readers: If you are located in the EEA and your data is transferred outside the EU, we rely on the European Commission's adequacy decisions or Standard Contractual Clauses to ensure an equivalent level of data protection.
Special Circumstances
There are situations where standard retention periods may be extended. We document and justify every exception.
Extended Retention Triggers
- Legal disputes: If data is relevant to ongoing or anticipated legal proceedings, litigation holds may extend retention until the matter is resolved
- Regulatory investigations: Data may be preserved at the request of regulatory bodies or law enforcement
- Fraud prevention: Data related to suspected or confirmed fraud may be retained for investigation and prevention purposes
- Security incidents: Logs and related data from security incidents are preserved for forensic analysis
- Archive purposes: User-generated content (comments, submissions) may be retained indefinitely for journalistic archive purposes, with the option to request removal
Transparency commitment: If we extend the retention of your personal data beyond standard periods for any of the above reasons, and you request information about your data, we will inform you of the reason for the extension and the expected duration.
Data Breach Protocol
In the event of a data breach affecting retained personal data:
- Our security team will contain and assess the breach within 24 hours of detection
- Affected individuals will be notified within 72 hours where required by law
- Appropriate data protection authorities will be notified as mandated
- A post-incident review will identify and remediate root causes
- Compromised data will be secured or permanently deleted as appropriate
Frequently Asked Questions
Questions? Contact Our Data Protection Team
If you have questions about this policy, want to exercise your rights, or need clarification about how your data is handled, our Data Protection Officer (DPO) and privacy team are here to help.
🔒 Data Protection Office
We aim to respond to all inquiries within 48 hours. For formal data rights requests, the full response timeline is 30 days.
EU residents: You have the right to lodge a complaint with your local supervisory authority. Find your authority at edpb.europa.eu.