Legal document
Data Retention Policy
How long Desklly retains different categories of data, and how data is securely deleted at the end of its retention period.
1. Principles
We retain personal data for no longer than is necessary for the purposes for which it was collected, or as required by law. Retention periods are configurable by the practice within the limits below.
2. Call audio recordings
Default retention: 90 days. Configurable: 0–2555 days (7 years) to align with NHS dental records retention. Recordings are automatically purged at the end of the configured period.
3. Call transcripts
Default retention: 12 months. Configurable to match the practice's dental record retention policy.
4. Appointment and messaging data
Retained for the duration of the customer relationship plus 12 months, unless the practice requests earlier deletion. Appointment data written into the practice management system remains under the practice's control.
5. Account and billing data
Retained for the duration of the customer relationship plus 7 years to meet UK tax and accounting requirements (Companies Act 2006, HMRC).
6. Support tickets and correspondence
Retained for 3 years from the last interaction.
7. System and security logs
Retained for at least 12 months for security, incident, and audit purposes.
8. Backups
Encrypted backups are retained for 35 days on a rolling basis. Deleted data will therefore persist in backups for up to 35 days before being irrecoverably purged.
9. Secure deletion
Data is deleted using cryptographic erasure or logical deletion followed by backup rotation. Physical media disposal by cloud providers follows NIST SP 800-88 standards.
10. Legal hold
Where data is subject to a legal hold, litigation, or regulatory investigation, deletion is suspended for the affected records until the hold is lifted.
