📄 Legal Document

Data Retention Policy

Aevum News is committed to protecting personal data and ensuring transparency in how we collect, store, and manage information. This policy outlines our data retention practices in compliance with international regulations.

📅 Effective: January 15, 2025 🔄 Last Updated: June 2, 2025 📑 Version: 3.2 đŸĸ Approved by: Board of Directors

1. Policy Overview

This Data Retention Policy governs the collection, storage, retention, and disposal of all data types processed by Aevum News and its affiliated entities. Aevum News operates as a digital journalism and news distribution platform serving readers, subscribers, advertisers, and partners across more than 120 countries.

The policy ensures that Aevum News handles all data in alignment with applicable laws and regulations including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Digital Personal Data Protection Act (DPDPA), and other relevant jurisdictional requirements.

⚡
Key Principle

Aevum News adheres to the data minimization principle — we collect only data that is necessary for specified, explicit, and legitimate purposes, and retain it only for as long as needed to fulfill those purposes.

  • ✓ All data retention periods are reviewed annually by the Legal & Compliance department
  • ✓ Data is classified by type, sensitivity, and regulatory requirement before storage
  • ✓ Automated systems enforce retention schedules with no manual override
  • ✓ Users may request early deletion or export of their data at any time
  • ✓ Breach notification occurs within 72 hours as required by GDPR Article 33

2. Scope & Applicability

This policy applies to all data processed by Aevum News across every platform, service, and operational division. It covers data collected from readers, subscribers, advertisers, content contributors, employees, and third-party partners.

2.1 Applicable Data Types

The following categories of data fall under this policy:

  • ◆ Personal Identifiers — names, email addresses, phone numbers, government IDs
  • ◆ Account Data — usernames, passwords (hashed), subscription tiers, billing information
  • ◆ Behavioral Data — browsing history, article engagement, time-on-page, click patterns
  • ◆ Technical Data — IP addresses, device identifiers, browser fingerprints, cookies
  • ◆ Payment Data — credit card details, billing addresses, transaction records
  • ◆ Communication Data — newsletter responses, support tickets, survey inputs, social media interactions
  • ◆ Content Data — user-generated comments, submissions, contributed articles
  • ◆ Analytics Data — aggregated metrics, A/B test results, demographic estimates
âš ī¸
Exclusions

This policy does not cover data processed by third-party advertising partners, CDN providers, or analytics platforms operating under separate data processing agreements. Users should review each third party's own privacy policy.

3. Data Categories & Classification

Aevum News classifies all collected data into distinct categories, each with specific retention requirements based on the nature of the data and its intended use.

👤 User Account Data

18 months

Name, email, password hash, subscription status, profile settings. Retained while account is active plus 18 months for reactivation.

đŸ’ŗ Payment & Billing

7 years

Transaction records, invoice data, payment references. Retained per financial regulation requirements.

📊 Analytics & Usage

24 months

Browsing patterns, article engagement, session data, aggregated behavior metrics.

📧 Communications

24 months

Newsletter responses, support tickets, user feedback, comment threads, forum posts.

🔧 Technical & Log Data

90 days

Server logs, access logs, error reports, security audit trails, IP address metadata.

📝 Content Submissions

Indefinite*

Published articles, contributor profiles, editorial history. Retained for journalistic record integrity.

đŸĒ Cookie & Tracking

12 months

Preference cookies, advertising identifiers, consent records, pixel tracker data.

🔐 Access & Authentication

1 year

Login timestamps, MFA logs, session tokens, password reset history.

4. Retention Periods — Detailed Schedule

The following table outlines the precise retention periods for each data category. Periods are measured from the date of last activity, data collection, or account closure — whichever is later.

Data Category Retention Period Legal Basis Trigger Event
Active User Account Data Account lifetime + 18 months Contract necessity Last login or account deletion request
Subscription & Payment Records 7 years Financial regulations (IRS, HMRC) End of fiscal year of last transaction
Analytics & Usage Data 24 months Legitimate interest Date of last data collection event
Communication Records 24 months Legitimate interest + consent Date of last message exchange
Server & Access Logs 90 days Security necessity Date of log entry generation
Published Content Indefinite (archived) Journalistic integrity Publication date
Cookie & Tracking Data 12 months Consent (ePrivacy Directive) Consent expiration or opt-out
Support & Complaint Data 5 years Statute of limitations Date of complaint resolution
Employee Data 6 years post-employment Employment law Last day of employment
Ad Client Data 4 years Contract + tax requirements End of contract term
â„šī¸
Note on