Data Retention and Automated Deletion Policy
Steleo Publishing Limited
Effective Date: 1st August 2025
Last Updated: 24/07/2026
Document Version: 1.0
Policy Reference: DRP-001
⚠️ CRITICAL DATA RETENTION NOTICE
YOUR DATA WILL BE AUTOMATICALLY AND PERMANENTLY DELETED UNDER SPECIFIC CONDITIONS.Please read this policy carefully to understand when and how your data may be deleted.Data deletion is irreversible and no recovery will be possible once deletion occurs.
1. Policy Overview and Scope
1.1 Purpose
This Data Retention and Automated Deletion Policy ("Policy") establishes the framework for how Steleo Publishing Limited ("Steleo," "we," "us," or "our") retains, manages, and automatically deletes user data in the BundleCreator.co service ("Service"). This Policy is guided by our Data Principles, particularly our commitments to data minimization and storage limitation. This Policy is designed to:
- Ensure compliance with data protection regulations including GDPR and UK DPA 2018;
- Minimise data retention to necessary business purposes;
- Provide clear guidelines for automated data deletion;
- Protect user privacy while maintaining service functionality;
- Establish accountability and transparency in data management practices.
1.2 Scope of Application
This Policy applies to:
- All personal data processed through the BundleCreator.co service;
- User-generated content including documents, bundles, and metadata;
- Account information and authentication data;
- Usage analytics and service interaction data;
- Support communications and feedback;
- Billing and payment information;
- All data categories defined in our Privacy Policy.
1.3 Integration with Legal Framework
This Policy operates in conjunction with and is referenced by ourTerms of Service, Privacy Policy, and Software License Agreement. In case of conflict, the terms of this Policy shall take precedence regarding data retention and deletion matters.
2. Data Categories and Classification
2.1 User Account Data
Definition: Information necessary for account creation, authentication, and service access.
Includes:
- Email addresses and authentication credentials
- User profile information (name, organisation details)
- Account preferences and settings
- Subscription and billing information
- Two-factor authentication data
2.2 User Content Data
Definition: All content created, uploaded, or processed by users through the Service.
Includes:
- Legal documents and court bundles
- Document metadata (titles, dates, descriptions)
- Bundle organisation and structure data
- Tiptap editor content and formatting
- Comments, annotations, and collaboration data
- Export history and generated PDFs
2.3 System and Usage Data
Definition: Technical and behavioural data generated through service usage.
Includes:
- Access logs and session information
- Feature usage analytics and performance metrics
- Error logs and debugging information
- Device and browser information
- API access patterns and audit trails
2.4 Communication Data
Definition: Records of interactions between users and Steleo.
Includes:
- Customer support tickets and communications
- Feedback and feature requests
- Marketing communications and preferences
- Legal notices and policy acknowledgments
3. Automated Deletion Triggers and Timelines
3.1 Inactive Account Deletion (90-Day Rule)
⚠️ CRITICAL WARNING: AUTOMATIC DATA DELETION
All user data will be PERMANENTLY AND IRREVERSIBLY deleted if your account remains inactive for ninety (90) consecutive days. NO RECOVERY IS POSSIBLE after deletion occurs.
We will send warning emails at 75, 83, and 89 days of inactivity. It is YOUR RESPONSIBILITY to maintain regular backups of important data.
Inactivity Definition: An account is considered "inactive" when:
- No user login or authentication occurs for 90 consecutive days;
- No API access or service interaction is recorded;
- No document uploads, edits, or bundle modifications occur;
- No customer support interactions are initiated by the user.
Deletion Timeline:
- Day 83: First warning email sent to registered email address
- Day 87: Final warning email sent with deletion countdown
- Day 90: Automatic and permanent deletion of all user data
- Day 91+: Data is irrecoverably deleted from all systems including backups
3.2 Trial Period and Grace Period Deletion (44-Day Rule)
⚠️ TRIAL USER WARNING: ACCOUNT DELETION AFTER 44 DAYS
In compliance with UK GDPR and the Data Protection Act 2018, ALL DATA will be PERMANENTLY DELETED if you do not upgrade to a paid subscription within 37 days of account creation (7-day trial + 30-day grace period). This deletion is AUTOMATIC and CANNOT BE REVERSED.
During the 30-day grace period after your trial ends, you can still use the service but exports will include a watermark. You have the right to download all your data before deletion (UK GDPR Article 20). Export your data before day 44 if you need to preserve it.
Trial and Grace Period Timeline:
- Days 0-14 (Reverse Trial): Full premium access with clean, court-ready exports - no watermarks;
- Days 14-44 (Grace Period): Continued access but exports include "NOT COURT READY" watermark. Warning emails sent throughout this period;
- Day 44+: Automatic permanent deletion of all account data if no subscription activated.
Trial User Definition: Users who:
- Access the Service using the 7-day free trial;
- Have not provided valid payment information;
- Have not activated any paid subscription plan;
- Have not purchased Pay-As-You-Go bundle access;
- Are utilising service features without commercial commitment.
UK GDPR Compliance Notice: Under UK data protection law (Article 5(1)(e) - storage limitation), we are required to delete personal data when it is no longer necessary for the purposes for which it was collected. Trial data that is not converted to a paid subscription is deleted 30 days after the trial ends to ensure compliance with data minimisation principles whilst providing adequate notice.
Warning Email Schedule:
- Day 16: Grace period notification - trial ended, 28 days until deletion
- Day 24: First reminder - 20 days until deletion
- Day 34: Second reminder - 10 days until deletion
- Day 41: Urgent warning - 3 days until deletion
- Day 43: Final warning - 24 hours until deletion
- Day 44: Automatic permanent deletion of all user data
- Day 45+: Data permanently removed from all systems including backups
Your Right to Data Export (UK GDPR Article 20):
Before deletion, you have the right to download all your personal data in a portable format. Each warning email includes a link to export your data. You can also export at any time via Settings → Export My Data.
3.3 Anonymous User Data Disclaimer
NO LIABILITY FOR ANONYMOUS USERS: Steleo accepts no responsibility or liability for data loss, corruption, or deletion for users who have not completed full account registration and subscription signup.
Anonymous User Definition:
- Users who access the Service without creating verified accounts;
- Users who provide incomplete or invalid registration information;
- Users who have not accepted the complete Terms & Conditions, Privacy Policy, and License Agreement;
- Users accessing the Service through temporary or guest access methods.
Disclaimer Terms:
- Anonymous users use the Service entirely at their own risk;
- No data protection guarantees apply to anonymous usage;
- No notification will be provided before data deletion;
- No data recovery assistance will be provided;
- Steleo bears no liability for any losses incurred by anonymous users.
4. Deletion Notification Procedures
4.1 Registered User Notifications
For users with verified email addresses and active accounts:
First Warning (7 days before deletion):
- Email notification to registered email address;
- In-app notification banner when user next accesses Service;
- Clear explanation of deletion timeline and data affected;
- Instructions for preventing deletion by logging in or upgrading;
- Link to this Data Retention Policy for full details.
Final Warning (3 days before deletion):
- Urgent email notification with countdown timer;
- Push notification if mobile app is installed;
- Prominent in-app alert with deletion countdown;
- Final opportunity to export data or upgrade account;
- Confirmation that deletion is irreversible.
4.2 Trial User Notifications
For trial users approaching the 7-day limit:
Upgrade Reminders:
- Daily reminders starting from Day 10;
- Clear pricing information and upgrade options;
- One-click upgrade functionality;
- Warning that trial data will be permanently deleted;
- Option to export data before deletion.
4.3 Notification Delivery
Notifications will be delivered through multiple channels:
- Email: Primary notification method to registered email address;
- In-App: Dashboard alerts and banner notifications;
- API: Webhooks for enterprise users with integrations;
- SMS: Optional for users who have provided phone numbers (premium feature).
4.4 Delivery Confirmation
Steleo will make reasonable efforts to deliver notifications but:
- Users are responsible for maintaining current contact information;
- Email delivery failures will not prevent automatic deletion;
- Users should regularly check spam/junk folders;
- Alternative notification methods may be used if primary methods fail.
5. Data Deletion Scope and Technical Implementation
5.1 Complete Data Deletion
When automatic deletion is triggered, the following data is permanently removed:
Primary User Data:
- All user-created documents and bundles;
- Document metadata, titles, descriptions, and dates;
- Bundle organisation structures and section arrangements;
- Tiptap editor content and formatting data;
- File uploads stored in secure cloud storage;
- Generated PDF exports and download history.
Account and Profile Data:
- User account information and authentication credentials;
- Profile settings and preferences;
- Subscription information and billing history;
- Two-factor authentication settings;
- API keys and access tokens;
- Collaboration permissions and sharing settings.
System and Analytics Data:
- User activity logs and session histories;
- Feature usage analytics and behaviour patterns;
- Error logs and debugging information related to user;
- Performance metrics and system interaction data;
- Audit trails for user-specific actions.
5.2 Data Deletion Process
Automated Deletion Pipeline:
- Trigger Detection: Automated systems identify accounts meeting deletion criteria;
- Data Identification: Comprehensive scan identifies all user-associated data across systems;
- Backup Removal: Data marked for deletion in all backup systems and archives;
- Primary Deletion: Data removed from production databases and storage systems;
- Cache Clearing: All cached data and temporary files permanently removed;
- Verification: Automated verification confirms complete data removal;
- Audit Logging: Deletion activities logged for compliance and accountability.
5.3 Technical Safeguards
To ensure secure and complete deletion:
- Cryptographic Deletion: Encryption keys destroyed making data unrecoverable;
- Multi-System Coordination: Deletion commands propagated across all data storage systems;
- Backup Integration: Automatic deletion from all backup and archive systems;
- CDN Purging: Content delivery network caches cleared of user data;
- Database Cleanup: Foreign key relationships properly handled during deletion;
- File System Cleanup: Direct file storage systems purged of user files.
5.4 Deletion Verification and Confirmation
Post-deletion verification includes:
- Automated scans confirming no residual data remains;
- Database integrity checks ensuring clean deletion;
- Storage system verification of file removal;
- Backup system confirmation of data purging;
- Compliance reporting for audit purposes.
6. Data Retention for Business Purposes
6.1 Legitimate Business Retention
Certain data may be retained beyond deletion triggers for legitimate business purposes:
Legal and Compliance Data (7 years):
- Financial records and billing information for tax compliance;
- Fraud prevention and security incident records;
- Legal proceeding documentation and evidence;
- Regulatory compliance audit trails;
- Anti-money laundering and know-your-customer records.
Aggregated Analytics Data (3 years):
- Anonymized usage statistics and service improvement metrics;
- Performance monitoring and system optimisation data;
- Security monitoring and threat detection patterns;
- Product development and feature usage analytics;
- Market research and business intelligence (anonymized only).
6.2 Anonymization and Pseudonymization
Data retained for business purposes undergoes:
- Complete Anonymization: All personally identifiable information removed;
- Statistical Aggregation: Individual records combined into statistical datasets;
- Data Minimization: Only essential business-relevant data retained;
- Access Restriction: Limited access on need-to-know basis for authorised personnel;
- Regular Review: Quarterly assessment of continued business necessity.
6.3 Retention Limits and Review
All retained data is subject to:
- Maximum retention periods as specified above;
- Annual review of business necessity and legal requirements;
- Automatic deletion when retention periods expire;
- User rights to request deletion where legally permissible;
- Data protection impact assessments for continued processing.
7. User Rights and Data Export
7.1 Data Export Before Deletion
Users approaching deletion deadlines can:
- Self-Service Export: Download all bundles and documents in standard formats;
- Bulk Export: Request complete account data export in machine-readable format;
- Selective Export: Choose specific bundles or documents for export;
- Format Options: Export as PDF, JSON, or original file formats;
- Metadata Inclusion: Export includes all document metadata and organisation structure.
7.2 Right to Erasure (Right to be Forgotten)
Users may request immediate deletion of their data by:
- Submitting formal erasure request through account settings;
- Contacting privacy@bundlecreator.co with deletion request;
- Providing identity verification to prevent unauthorised deletion;
- Confirming understanding that deletion is irreversible.
Limitations on Right to Erasure:
- Legal obligations requiring data retention (e.g., financial records);
- Ongoing legal proceedings or investigations;
- Legitimate interests for fraud prevention or security;
- Public interest or scientific/historical research purposes (anonymized data only).
7.3 Data Portability Rights
Users have the right to:
- Receive personal data in structured, commonly used format;
- Transmit data directly to another service provider where technically feasible;
- Request data export without hindrance from Steleo;
- Receive data export within 30 days of request.
7.4 Account Reactivation
Prevention of automatic deletion:
- Login Activity: Any successful login resets inactivity timer;
- API Access: Authenticated API calls prevent deletion;
- Subscription Upgrade: Activating paid plan prevents trial deletion;
- Data Interaction: Creating, editing, or viewing content resets timers;
- Support Contact: Verified support requests can extend deletion deadlines.
8. Legal Compliance and Regulatory Framework
8.1 GDPR Compliance
This Policy is designed to support compliance with EU General Data Protection Regulation. Users must ensure their own compliance:
- Lawful Basis: Data processing based on contract performance and legitimate interests;
- Data Minimization: Only necessary data retained for specified purposes;
- Storage Limitation: Data retained only as long as necessary for identified purposes;
- Accountability: Comprehensive documentation of data processing activities;
- Transparency: Clear information provided to data subjects about processing.
8.2 UK DPA 2018 Compliance
Alignment with UK Data Protection Act 2018:
- Compliance with UK GDPR requirements post-Brexit;
- Recognition of UK data subject rights;
- Cooperation with UK Information Commissioner's Office (ICO);
- Adherence to UK data transfer restrictions and adequacy decisions.
8.3 Sector-Specific Compliance
Additional compliance considerations for legal sector:
- Legal Professional Privilege: Respect for legal professional privilege in data handling;
- Court Requirements: Retention periods aligned with legal proceeding timelines;
- Bar Council Guidelines: Compliance with UK legal profession data handling standards;
- Family Court Requirements: Special consideration for sensitive family law data.
8.4 International Data Transfers
Cross-border data transfer safeguards:
- Standard Contractual Clauses for EU-UK data transfers;
- Adequacy decisions where applicable;
- Additional safeguards for transfers to third countries;
- Data localization options for sensitive legal data.
9. Monitoring, Auditing, and Reporting
9.1 Automated Monitoring Systems
Continuous monitoring includes:
- Deletion Schedule Tracking: Automated identification of accounts approaching deletion deadlines;
- Notification Delivery Monitoring: Verification of successful warning email delivery;
- System Health Checks: Regular validation of deletion system functionality;
- Data Integrity Monitoring: Continuous verification of data consistency and completeness;
- Compliance Dashboards: Real-time visibility into policy compliance metrics.
9.2 Audit Trail Requirements
Comprehensive audit logging captures:
- All automated deletion activities with timestamps and affected data;
- User notification delivery attempts and outcomes;
- Data export requests and completion status;
- Manual intervention or exception handling;
- System configuration changes affecting retention policies;
- Data access and processing activities by authorised personnel.
9.3 Regular Policy Review
Ongoing policy maintenance includes:
- Quarterly Reviews: Assessment of deletion timelines and business requirements;
- Annual Legal Review: Comprehensive legal compliance assessment;
- Regulatory Updates: Monitoring and incorporation of new legal requirements;
- User Feedback Integration: Consideration of user concerns and suggestions;
- Technology Updates: Adaptation to new data processing technologies and capabilities.
9.4 Compliance Reporting
Regular reporting includes:
- Monthly deletion statistics and compliance metrics;
- Quarterly data retention policy effectiveness assessment;
- Annual compliance certification and audit reports;
- Incident reports for any policy violations or system failures;
- Regulatory reporting as required by applicable laws.
10. Contact Information and Support
10.1 Data Protection Inquiries
For questions regarding this Data Retention Policy:
Data Protection Officer: dpo@bundlecreator.co
Privacy Team: privacy@bundlecreator.co
General Data Inquiries: data@bundlecreator.co
Response Time: Within 5 business days
10.2 Emergency Data Recovery
For urgent data recovery requests (where legally permissible):
Emergency Contact: emergency@bundlecreator.co
Emergency Support: AI-powered assistance available through our help system
Recovery Limitations: Subject to technical feasibility and legal compliance
Fees May Apply: Emergency recovery services may incur additional costs
10.3 Regulatory Complaints
Users may lodge complaints with relevant authorities:
UK: Information Commissioner's Office (ICO) - ico.org.uk
EU: Relevant national data protection authority
Internal Escalation: legal@bundlecreator.co
10.4 Policy Updates Notification
Users will be notified of policy changes through:
- Email notifications to registered users;
- In-app notifications and policy update banners;
- Website publication of updated policy;
- 30-day advance notice for material changes affecting deletion timelines.
Document Information:
Effective Date: 1st August 2025
Last Updated: 24/07/2026
Document Version: 1.0
Policy Reference: DRP-001
Review Date: 1st February 2026
Governing Law: England and Wales
Company: Steleo Publishing Limited (Company Number: 11891029)
Registration: 167-169 Great Portland Street, London W1W 5PJ
ISO 27001:2022 & SOC 2 Type II Compliance Programme
This Data Retention and Automated Deletion Policy is part of BundleCreator's comprehensive ISO 27001:2022 and SOC 2 Type II compliance programme. The policy specifically addresses:
- ISO 27001 A.5.34 - Privacy and protection of personally identifiable information
- ISO 27001 A.8.10 - Information deletion requirements
- SOC 2 CC6.5 - Logical and physical access controls
- SOC 2 CC6.2 - Prior to issuing system credentials
Compliance Status: As of November 2025, BundleCreator.co is implementing comprehensive ISO 27001:2022 controls and SOC 2 Trust Services Criteria, working towards certification.
Related Documents: This Data Retention Policy should be read in conjunction with ourPrivacy Policy, Terms of Service, and Software License Agreement. For the most current version of this policy, please visit bundlecreator.co/data-retention-policy.