Data Retention Policy
Last updated: 2 March 2024
This Data Retention Policy explains how glowlucky.vip collects, stores, and disposes of personal and operational data. It applies to all users, clients, and individuals whose information is processed through our platform and services.
1. Purpose
We retain data only for as long as necessary to fulfil the purposes for which it was collected, to comply with applicable legal and regulatory obligations, to resolve disputes, and to enforce our agreements. This policy establishes the principles and schedules that govern how long different categories of data are kept and how they are securely removed when no longer required.
2. Scope
This policy applies to all personal data and operational records processed by glowlucky.vip, including data collected through our website, learning platform, communication channels, and administrative systems. It covers data held in digital databases, cloud storage, backup systems, and any third-party processors acting on our behalf.
3. Categories of Data and Retention Periods
The table below outlines the primary categories of data we hold, the basis for retaining each category, and the standard retention period applied.
| Data Category | Examples | Retention Period | Basis for Retention |
|---|---|---|---|
| Account and registration data | Name, email address, password hash, registration date | Duration of account plus 2 years after closure | Contractual necessity, legitimate interest |
| Learning activity records | Course enrolments, session attendance, progress, assessments | 5 years from last activity | Service delivery, legitimate interest |
| Payment and billing records | Transaction history, invoices, payment method references | 7 years from transaction date | Legal and financial compliance |
| Communication records | Support tickets, emails, chat logs, instructor messages | 3 years from last communication | Legitimate interest, dispute resolution |
| Technical and system logs | Access logs, error logs, IP addresses, device identifiers | 12 months from creation | Security, fraud prevention |
| Marketing preferences | Consent records, subscription status, opt-out history | 3 years from last interaction or until consent withdrawn | Legal compliance, consent management |
| Backup and disaster recovery data | System snapshots, database backups | 90 days from creation | Business continuity |
| Anonymised and aggregated data | Usage statistics, performance metrics | Indefinite | No personal data present after anonymisation |
4. Retention Principles
4.1 Data Minimisation
We collect only the data necessary for the stated purpose. Data that is no longer required for its original purpose is either deleted, anonymised, or archived in accordance with this policy.
4.2 Purpose Limitation
Data is not retained in a form that permits identification of individuals for longer than is necessary for the purposes for which it was collected. Where data is retained for secondary purposes such as analytics or service improvement, it is anonymised prior to use.
4.3 Accuracy
We take reasonable steps to ensure that data held within retention periods remains accurate and up to date. Users are encouraged to update their account information when changes occur.
4.4 Storage Security
All retained data is stored using appropriate technical and organisational security measures proportionate to the sensitivity of the data and the risks involved. Access is restricted to authorised personnel on a need-to-know basis.
5. Extended Retention
In certain circumstances, data may be retained beyond the standard periods outlined above. These circumstances include:
- An ongoing legal claim, investigation, or regulatory inquiry in which the data is relevant
- A specific legal or regulatory obligation requiring longer retention
- An explicit request from a competent authority
- A contractual obligation with an institutional client specifying a longer retention period
Where extended retention applies, the data is flagged, access is restricted, and a review is scheduled for the earliest permissible deletion date.
6. Early Deletion and the Right to Erasure
Users may request the deletion of their personal data before the end of the standard retention period. Such requests are assessed against applicable legal obligations and legitimate interests. Where no overriding ground for retention exists, data is deleted within 30 days of the verified request.
Requests for erasure can be submitted by contacting us at help@glowlucky.vip. We will acknowledge your request and communicate the outcome within the timeframe required by applicable law.
Note that deletion of account data may result in the loss of access to learning records, certificates, and other platform features associated with that account.
7. Data Disposal
7.1 Deletion Methods
When data reaches the end of its retention period, it is disposed of using methods appropriate to the medium and sensitivity of the data:
- Digital records are permanently deleted from active systems and overwritten or cryptographically erased where technically feasible
- Backup copies are purged in accordance with the backup rotation schedule
- Data held by third-party processors is deleted in accordance with our data processing agreements with those parties
7.2 Verification
Disposal of data categories subject to regulatory retention requirements is logged to provide an auditable record of compliance. These disposal logs are themselves retained for a period of 3 years.
8. Third-Party Processors
Where personal data is shared with or processed by third-party service providers, those providers are required by contract to apply retention and deletion standards consistent with this policy. We conduct periodic reviews of processor compliance as part of our vendor management programme.
9. Cookies and Tracking Data
Data collected through cookies and similar tracking technologies is subject to separate retention periods defined in our Cookie Policy. In general, session cookies are deleted at the end of the browser session, while persistent cookies are retained for the period stated at the time of consent, typically no longer than 13 months.
10. Review of This Policy
This policy is reviewed at least annually and updated whenever there are material changes to our data processing activities, applicable legal requirements, or business operations. The date at the top of this page reflects the most recent revision. Continued use of our services following an update constitutes acceptance of the revised policy.
11. Contact
Questions regarding this policy or requests relating to your personal data may be directed to:
glowlucky.vip
Lysaght St, North Wollongong NSW 2500, Australia
Email: help@glowlucky.vip
Phone: +61 430 441 155