Data Protection
Data Retention Policy
Last updated 25 June 2026
1. Retention Principles
HeroPerks is committed to ensuring that personal data is not retained for longer than necessary for the purposes for which it was collected, in accordance with the UK GDPR principle of storage limitation.
We will:
- Only retain personal data where there is a valid business, legal, or regulatory reason
- Regularly review the data we hold
- Securely delete or anonymise data when it is no longer required
Retention periods are determined based on the purpose of processing, legal and regulatory obligations, contractual requirements, and legitimate business interests.
2. Categories of Data & Retention Periods
Customer / User Data — Account information, contact details, preferences. Retained for the duration of the account plus up to 24 months after last activity, for service provision, customer support, and re-engagement.
Marketing Data — Email subscriptions, communication preferences. Retained until consent is withdrawn or 24 months of inactivity, on the basis of legitimate interest and consent-based marketing.
Partner / Business Data — Business listings, contact details, agreements. Retained for the duration of the partnership plus 6 years after termination, for contractual and legal obligations.
Financial & Transaction Records — Invoices, payment records, accounting data. Retained for 6–7 years, in compliance with HMRC and Companies Act requirements.
Employee & Contractor Data — Employment records, payroll, HR data. Retained for the duration of employment plus 6 years after termination, for legal and employment obligations.
Website & Technical Data — IP addresses, analytics data, cookies. Retained for typically 12–26 months depending on tool or provider, for website performance and security.
Support & Communications — Emails, support tickets, enquiries. Retained for up to 3 years from last contact, for customer service and dispute resolution.
3. Data Review & Deletion
We conduct regular data audits to ensure data is accurate, relevant, and not excessive. When data reaches the end of its retention period, it will be securely deleted or anonymised so it can no longer identify individuals.
4. Legal Holds & Exceptions
In certain circumstances, we may retain data beyond standard retention periods where required for legal claims or disputes, regulatory investigations, fraud prevention, or compliance with legal obligations.
5. Data Storage & Security
Data is stored securely using encrypted cloud-based systems, access controls and authentication, and secure backup procedures. Only authorised personnel have access to personal data.
6. Responsibility & Governance
Responsibility for this policy sits with the Company Directors and the Data Protection Lead. All staff and partners handling data are required to follow this policy, undertake appropriate data protection training, and report any data breaches immediately.
7. Policy Review
This Data Retention Policy is reviewed at least annually, or when there are changes to legal or operational requirements. Retention periods are documented in an internal data retention schedule and may be updated where required to reflect legal, regulatory, or operational changes.y.
Legal responsibility for the content on this page sits with Employees Global Ltd.