This policy sets out how long Super Save Protocol keeps each category of data, the reason for each period, and what happens when a period ends. It supports the storage limitation principle: we keep data no longer than necessary, and we can say why for every category.
01 Retention schedule
| Category | Period | Reason |
|---|---|---|
| Website enquiries and correspondence | 24 months from last contact | Following up and defending claims |
| Marketing contact data | Until objection, then suppression list only | Consent / legitimate interests |
| User account data (active) | Duration of the account | Providing the service |
| User account data (closed) | 12 months after closure | Reinstatement, dispute handling |
| Authentication and session logs | 12 months | Security investigation |
| Registry records — shipments, invoices, collateral, cheques | 7 years from registration | Duplicate detection over the full life of a trade cycle; regulatory expectation |
| Document fingerprints | 7 years | Core anti-duplicate control |
| Fraud alerts and dispositions | 7 years from closure | Compliance and defence of claims |
| Audit log entries | 7 years, append-only | Integrity, accountability, regulatory inspection |
| Member KYB, sanctions and due diligence records | 5 years from end of relationship | AML and sanctions obligations |
| Contracts and membership agreements | 7 years from expiry | Limitation periods |
| Billing, invoicing and tax records | 8 years | Statutory accounting requirements |
| Backups | 35 days rolling | Disaster recovery |
| Cookie consent records | 12 months | Demonstrating consent |
02 Why registry and audit data is kept for seven years
Duplicate financing is frequently discovered long after the advance — when a facility matures, when a borrower fails, or when an auditor reconstructs a chain of transactions. A registry that discarded records after twelve months would fail at exactly the moment it is needed.
Seven years aligns with common limitation periods and with the retention expectations placed on regulated financial institutions in the markets we serve. Audit log entries are held for the same period so that any registry record can be traced to the actions that created and changed it.
03 Legal holds
Where data is relevant to an actual or reasonably anticipated legal claim, regulatory investigation or law enforcement request, we suspend deletion for the affected records until the matter closes. Holds are documented, owned by a named person, and reviewed quarterly.
04 What happens at the end of a period
- Deletion. Records are removed from live systems by an automated job and from backups as the rolling backup window expires.
- Anonymisation. Where aggregate statistics remain useful, we strip all identifiers so the data can no longer be attributed to a person, institution or transaction. Anonymised data falls outside data protection law and is not subject to this schedule.
- Certification. Where a Member requires written confirmation of deletion, we provide it on request.
05 Review and requests
This schedule is reviewed annually and whenever a new module or data category is introduced. Questions or deletion requests go to privacy@supersaveprotocol.com. Requests that conflict with a retention obligation are answered with the specific basis we rely on.
Questions about this document?
Write to legal@supersaveprotocol.com, or to Super Save Protocol Ltd, 207 Regent Street, London, W1B 3HH, United Kingdom. You can also see all our legal documents.