Sew Hot Data Retention Policy

1. Purpose and scope

Sew Hot keeps personal data only as long as it needs it for a stated purpose, then deletes or anonymises it. This policy sets out how long each type of data is kept and what happens when that period ends.

It applies to all personal data Sew Hot processes through its website, customer service, marketing, suppliers and staff administration, in any format: databases, email, spreadsheets, paper and backups. It covers everyone who handles that data, including employees, contractors and third-party processors acting for Sew Hot.

2. Legal basis and principles

This policy implements the storage limitation principle in Article 5(1)(e) of the UK GDPR: personal data must be kept in an identifiable form no longer than necessary for the purposes it was collected for. It also supports the UK Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR) for cookies and marketing. Where Sew Hot sells to customers in the EU or EEA, the EU GDPR applies to that data on the same terms.

Sew Hot follows these principles:

  • Necessity: every retention period is tied to a purpose, such as fulfilling an order, meeting a legal duty or defending a claim.
  • Minimisation: only the data needed for that purpose is collected and kept.
  • Statutory periods win: where a law sets a minimum period (for example HMRC record keeping), that period applies, and the data is deleted promptly once it ends.
  • Anonymise where possible: data needed only for statistics is anonymised so it is no longer personal data.
  • Transparency: retention periods are summarised in Sew Hot’s privacy notice so customers know how long their data is kept.

3. Roles and responsibilities

Role Responsibility
Directors / owners Accountable for compliance; approve this policy and its annual review
Data Protection Lead Maintains the retention schedule, runs deletion reviews, handles data subject requests and liaises with the ICO
Team members Store data only in approved systems, follow the schedule and report data kept past its period
Processors (hosting, payments, email, couriers) Delete or return Sew Hot data under their contracts and Article 28 terms

Sew Hot does not currently need a statutory Data Protection Officer, as its core activities do not involve large-scale monitoring or special category data. This should be reassessed if that changes.

4. Retention schedule

Each period runs from the trigger event shown. At the end of the period the data is deleted or anonymised under section 5.

Data category Examples Purpose / lawful basis Retention period Action at end
Order and invoice records Name, address, items, prices, VAT, order number Contract; legal obligation (HMRC, VAT) 6 years after the end of the financial year of the order Delete personal details; keep anonymised sales totals
Returns, refunds and complaints Return reason, refund amount, correspondence Contract; legitimate interests (defending claims) 6 years after the order (Limitation Act 1980) Delete
Payment card data Card number, CVV Not stored by Sew Hot; handled by the payment provider under PCI DSS Not held N/A
Payment transaction references Provider transaction ID, last 4 digits Contract; legal obligation Same as order records Delete
Customer account Login email, hashed password, saved addresses, order history link Contract Until closed, or 3 years after last login or order Close account; order records follow their own period
Guest checkout details Email, phone, delivery address Contract Same as order records Delete
Abandoned baskets Basket contents linked to email Legitimate interests or consent (reminder emails) 30 days Delete
Customer service enquiries (not linked to an order) Emails, chat transcripts, call notes Legitimate interests 2 years after the enquiry is closed Delete
Email marketing list Email, name, preferences, consent record Consent or soft opt-in (PECR) Until unsubscribe, or 2 years with no opens or clicks after a re-permission attempt Remove from list; add email to suppression list
Marketing suppression list Email address only Legal obligation / legitimate interests (honouring opt-outs) Indefinitely, while marketing continues Review annually
Product reviews Display name, review text, rating Consent / legitimate interests While published; 1 year after removal Delete or anonymise
Competition and giveaway entries Name, email, entry Consent / contract 6 months after the winner is announced Delete; winners’ details kept 2 years
Analytics and cookie data Cookie IDs, browsing behaviour Consent (PECR), except strictly necessary cookies No longer than 13 months per cookie; reports anonymised Expire / delete
Cookie consent records Consent choice, timestamp, banner version Legal obligation (proof of consent) 2 years after the consent is given or changed Delete
Website server and security logs IP address, timestamps, requests Legitimate interests (security, fraud prevention) 90 days, longer only while investigating an incident Delete
Fraud screening records Flags, check results, linked order Legitimate interests; legal obligation 6 years after the order Delete
Data subject request records Request, ID check, response Legal obligation (accountability) 2 years after the request is closed Delete
Data breach log Incident details, decisions, ICO reports Legal obligation (Article 33(5)) 6 years after the incident is closed Delete
Supplier and business contacts Contact names, emails, contracts Contract; legitimate interests 6 years after the relationship ends Delete
Job applicants (unsuccessful) CV, cover letter, interview notes Legitimate interests 6 months after the decision Delete
Employee records Contract, personnel file, appraisals Contract; legal obligation 6 years after employment ends Delete
Payroll and PAYE records Pay, tax, NI, pension details Legal obligation (HMRC) 3 years after the end of the tax year, or 6 years if part of company accounts Delete
Right to work checks Copies of ID documents Legal obligation (Home Office) 2 years after employment ends Delete
Backups Copies of any of the above Business continuity Rolling, overwritten within 35 days Overwritten; deleted data is not restored to live systems

5. Secure deletion and anonymisation

Data past its retention period is removed in a scheduled review every quarter, with automated deletion used wherever the e-commerce platform allows it.

  • Electronic data: deleted from live systems, mailboxes and shared drives, and allowed to age out of backups. Deletion requests are sent to each processor holding a copy.
  • Paper records: cross-cut shredded or destroyed by a certified confidential waste contractor.
  • Devices: laptops, phones and drives are securely wiped or physically destroyed before disposal or reuse.
  • Anonymisation: where data is kept for reporting, names, contact details and other identifiers are removed so no individual can be identified, including by combining it with other data.
  • Record of deletion: the Data Protection Lead logs the date, data category and method for each review, without recording the deleted personal data itself.

6. Data subject rights and exceptions

Customers can ask Sew Hot to delete their data before the end of its retention period under the right to erasure (Article 17). Sew Hot responds within one month of receiving the request, extendable by two further months for complex requests.

Sew Hot will erase the data unless it must keep it, for example:

  • order and invoice records needed for HMRC and VAT purposes;
  • records needed to establish, exercise or defend a legal claim;
  • the email address on the suppression list, so marketing opt-outs are honoured.

In those cases Sew Hot deletes everything it can (such as the account and marketing profile), restricts the rest to the legal purpose, and tells the customer what has been kept and why.

Legal holds: if data is relevant to a dispute, investigation, insurance claim or regulator request, the Data Protection Lead suspends deletion of that data until the matter is closed. The normal schedule then resumes.

7. Third parties, review and contact

Processors. Every supplier that holds Sew Hot customer data (website hosting, e-commerce platform, payment provider, email marketing, couriers, accountants) must have a written contract meeting Article 28. Each contract requires the supplier to delete or return the data when the service ends and to follow retention periods no longer than this schedule. Data transferred outside the UK is protected by adequacy regulations or the UK International Data Transfer Agreement or Addendum.

Review. The Data Protection Lead reviews this policy at least once a year, and sooner if the law, Sew Hot’s systems or the data it collects change. Breaches of this policy are reported to the Data Protection Lead and may lead to disciplinary action.

Contact. Questions or requests about personal data: [email protected], Sew Hot, Carleton Court, 143-153 Lord Street, Fleetwood, FY7 6LY. Customers also have the right to complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.