Data Retention Policy
1. Purpose & Scope
WebCraft Studios is committed to transparent, secure, and compliant data management practices. This Data Retention Policy outlines how long we retain the personal and professional information we collect from clients, website visitors, contractors, and service users, and the procedures we follow to securely dispose of data once it is no longer required.
2. Data We Retain
We only retain data that is necessary for delivering our services, maintaining client relationships, fulfilling legal obligations, and ensuring platform security. Categories of retained data include:
- Client & Contract Data: Business names, contact details, project briefs, contracts, and invoicing records.
- Project Assets: Design files, source code, documentation, deployment logs, and version-controlled repositories.
- Website & Usage Data: Analytics, cookies, server logs, error reports, and performance metrics.
- Communications: Emails, meeting notes, support tickets, and collaboration platform records.
- Payment & Financial Records: Transaction histories, tax documentation, and compliance records.
3. Retention Periods
Data is retained for the shortest period necessary to fulfill its purpose, unless a longer retention period is required by law, regulation, or contractual obligation. Our standard retention schedule is as follows:
| Data Category | Retention Period | Disposal Method |
|---|---|---|
| Active Project Files | Duration of engagement + 12 months | Secure archival, then encrypted deletion |
| Client Contracts & Invoices | 7 years (tax/legal compliance) | Secure document destruction |
| Website Analytics & Cookies | 14–26 months (configurable) | Auto-expiring via analytics platform settings |
| Server & Access Logs | 90 days | Automated rotation & overwrite |
| Marketing & Inquiry Data | Until unsubscribed or 3 years of inactivity | Suppression list & secure erasure |
When retention periods expire, data is permanently deleted using industry-standard cryptographic erasure methods. Archived backups are subject to a 30-day grace period before final deletion to prevent accidental data loss.
4. Storage & Security
All retained data is protected through physical, technical, and organizational safeguards designed to prevent unauthorized access, alteration, or disclosure. Our security measures include:
- AES-256 encryption for data at rest and TLS 1.3 for data in transit
- Role-based access controls (RBAC) and multi-factor authentication (MFA) for all internal systems
- Regular penetration testing, vulnerability scanning, and third-party security audits
- Geographically redundant backups stored in SOC 2 Type II compliant data centers
- Strict data handling agreements with all subcontractors and cloud providers
5. Legal & Regulatory Basis
Our retention practices align with applicable data protection regulations, including but not limited to:
- GDPR (EU/UK): Lawful basis, storage limitation principle, and right to erasure
- CCPA/CPRA (California): Consumer rights, retention limits, and disclosure requirements
- Tax & Accounting Standards: 7-year financial record retention requirements
- Industry Best Practices: ISO 27001, NIST Cybersecurity Framework
If a legal hold applies (e.g., litigation, regulatory investigation, or pending dispute), affected data will be preserved regardless of standard retention schedules until the hold is formally lifted.
6. Your Rights & Data Deletion Requests
Under applicable privacy laws, you retain the right to:
- Access a copy of the personal data we hold about you
- Request correction of inaccurate or incomplete information
- Request deletion or anonymization of your data (where not legally restricted)
- Opt out of marketing communications at any time
- Request data portability in a machine-readable format
To submit a request, contact our Data Protection Officer at dpo@webcraft.studio or use our secure request portal. We will respond within 30 days. Requests involving legal, financial, or security exemptions may be partially fulfilled as required by law.
7. Policy Updates
This Data Retention Policy is reviewed annually and updated as necessary to reflect changes in technology, service offerings, or legal requirements. Material changes will be communicated via email to registered clients and published on this page with an updated effective date. Continued use of our services constitutes acceptance of the current policy terms.
For questions regarding this policy, data practices, or compliance matters, please reach out to our legal & compliance team at compliance@webcraft.studio.