Data Retention Policy
Last Updated: September 21, 2025
This Data Retention Policy describes how Plrintex collects, stores, and manages personal data and other information gathered through the use of our platform and services available at secarey.com. This policy applies to all users, visitors, and registered participants of our platform.
We are committed to handling your data responsibly, retaining it only for as long as necessary, and ensuring its secure deletion or anonymisation once it is no longer required for the purposes for which it was collected.
1. Purpose of This Policy
The purpose of this policy is to establish clear and consistent standards for how long we retain different categories of data, why we retain it, and how we manage its secure disposal. Retaining data longer than necessary creates unnecessary risk and administrative burden. This policy ensures we meet our obligations to users and maintain sound data governance practices.
This policy supports our broader commitment to privacy and data protection by ensuring that:
- Data is not kept for longer than is necessary for its intended purpose
- Retention periods are defined, documented, and consistently applied
- Data is securely disposed of at the end of its retention period
- Users can understand how long their information is held and why
2. Scope
This policy applies to all personal data and non-personal data processed by Plrintex, including data collected through:
- Account registration and profile management
- Course enrolment and participation in masterclasses
- Payment and billing transactions
- Communications with our support team
- Use of interactive features such as quizzes, assessments, and feedback forms
- Newsletter subscriptions and marketing communications
- Technical usage data collected through cookies and similar technologies
This policy applies to data stored in all formats and on all systems operated by or on behalf of Plrintex, including cloud-based infrastructure, third-party processors, and internal databases.
3. Categories of Data We Retain
3.1 Account and Identity Data
This includes information provided when creating and maintaining a user account, such as name, email address, username, password credentials, and profile preferences. This data is retained for the duration of the active account and for a defined period following account closure or deletion.
3.2 Learning and Engagement Data
This includes records of course enrolments, progress tracking, completion certificates, quiz and assessment results, and participation history. This data is retained to provide continuity of service, allow users to access their learning history, and support the integrity of issued credentials.
3.3 Payment and Transaction Data
This includes billing records, transaction identifiers, payment method details processed through secure third-party payment providers, and invoices. Financial records are retained in accordance with standard accounting and audit requirements applicable to online service providers.
3.4 Communication Data
This includes records of support requests, feedback submissions, email correspondence, and any other communications sent to or received from users. This data is retained to maintain a record of interactions, resolve disputes, and improve service quality.
3.5 Technical and Usage Data
This includes log files, IP addresses, browser and device information, session data, and analytics information collected automatically during use of the platform. This data is used for security monitoring, performance optimisation, and service improvement.
3.6 Marketing and Preference Data
This includes records of consent for marketing communications, subscription preferences, and engagement data related to emails or notifications sent to users. This data is retained for as long as a user maintains an active subscription or until consent is withdrawn.
4. Retention Periods
We apply the following general retention periods to the categories of data described above. These periods may be adjusted in specific circumstances as described in Section 5.
- Account and Identity Data: Retained for the duration of the active account, plus a period of up to 2 years following account closure to allow for reactivation requests, dispute resolution, and fraud prevention.
- Learning and Engagement Data: Retained for the duration of the active account and for up to 5 years following account closure to support the validity of issued certificates and credentials.
- Payment and Transaction Data: Retained for a minimum of 7 years from the date of the transaction to meet standard financial record-keeping requirements.
- Communication Data: Retained for up to 3 years from the date of the most recent communication, unless the communication relates to an ongoing dispute or legal matter.
- Technical and Usage Data: Retained for up to 12 months from the date of collection, after which it is deleted or anonymised.
- Marketing and Preference Data: Retained for as long as the user maintains an active marketing subscription or until consent is withdrawn, plus a short administrative period of up to 6 months.
5. Extended Retention
In certain circumstances, we may be required or permitted to retain data beyond the standard retention periods described above. These circumstances include:
- Legal obligations: Where we are required by applicable law, regulation, or regulatory guidance to retain data for a specified period.
- Legal proceedings: Where data is relevant to an actual or anticipated legal claim, investigation, or dispute, we will retain it for as long as necessary to resolve the matter.
- Contractual requirements: Where our agreements with third parties or service providers require specific retention practices.
- Legitimate interests: Where we have a documented legitimate interest in retaining data beyond the standard period, provided that interest is not overridden by the rights of the data subject.
When extended retention applies, we document the reason and review the data regularly to determine whether continued retention remains justified.
6. Data Minimisation and Review
We are committed to collecting only the data we need and retaining it only for as long as necessary. To support this commitment, we undertake the following practices:
- Regular internal reviews of data categories and retention schedules to ensure they remain appropriate and up to date
- Assessment of new data collection activities to determine appropriate retention periods before collection begins
- Identification and deletion or anonymisation of data that has exceeded its retention period
- Training of relevant personnel on data minimisation and retention obligations
7. Secure Disposal
When data reaches the end of its retention period and no extended retention justification applies, we ensure it is disposed of securely. Our disposal practices include:
- Permanent deletion from active systems and databases
- Secure erasure from backup systems within standard backup rotation cycles
- Anonymisation where deletion is not technically feasible, ensuring the data can no longer be linked to an identifiable individual
- Secure physical destruction of any physical media containing personal data, where applicable
We work with our third-party data processors to ensure that equivalent disposal standards are applied to any data held on our behalf.
8. Third-Party Processors
We engage third-party service providers to assist in delivering our platform, including payment processors, cloud infrastructure providers, email delivery services, and analytics platforms. Where these providers process personal data on our behalf, we require them to maintain appropriate retention and disposal practices consistent with this policy and with applicable data protection standards.
We review our agreements with third-party processors periodically to ensure their data retention practices remain aligned with our requirements.
9. User Rights
Users have rights in relation to the personal data we hold about them, which may include the right to access, correct, or request deletion of their data. Requests for data deletion will be processed in accordance with this policy, and data will be removed where no legal or contractual obligation requires its continued retention.
To exercise any rights in relation to your personal data, please contact us using the details provided below.
10. Cookies and Tracking Technologies
Data collected through cookies and similar tracking technologies is subject to the retention periods described in our Cookie Policy, which should be read alongside this document. Technical usage data derived from cookies is generally retained for no longer than 12 months, though specific cookie lifespans vary and are detailed in the Cookie Policy.
11. Changes to This Policy
We may update this Data Retention Policy from time to time to reflect changes in our practices, applicable requirements, or the services we offer. When we make material changes, we will update the date shown at the top of this policy and, where appropriate, notify users through the platform or by email.
We encourage you to review this policy periodically to stay informed about how we manage your data.
12. Contact Us
If you have any questions about this Data Retention Policy or wish to exercise your rights in relation to your personal data, please contact us:
Plrintex
Gallanes, Clonakilty, Co. Cork, P85 XD37, Ireland
Email: contact@secarey.com
Phone: +353 1 874 7331
Website: secarey.com