Document key: trine-retention Version: 1.0 Status: Published Approved by: Hyun Kyu Han, Director Approved on: 1 September 2026 Published: recorded in the legal registry at publication Effective: 19 days after publication Acceptance: informational, link only (no checkbox) Published at: https://trine.uk/legal/data-retention
This policy explains how long data is held in Trine, who decides retention periods, and what happens when a period expires.
2.1 You are the controller of the records you keep in Trine. Retention periods for those records are your decision, made against your own retention schedule and the statutory and regulatory requirements that apply to you.
2.2 Our role is to hold the data for as long as you instruct, to provide tools that support your retention decisions, and to delete data when you tell us to or when the Agreement ends.
2.3 The periods in section 4 are our operational defaults. They are starting points, not advice, and you should confirm them against your own schedule and against the Records Management Code of Practice and the applicable adult social care retention schedules.
3.1 Records remain available in Trine until you delete them, or until we delete them on your instruction.
3.2 Automated retention-based deletion is not currently implemented. Deletion is performed by you within the platform, or by us manually on your written instruction. We will tell you when automated retention rules become available.
3.3 Deleting a record removes it from the active platform.
3.3.1 Deleting an action or record deletes the version history held against it. Deleting an individual evidence document deletes its full version chain, including every superseded version and the stored file for each.
3.3.2 Retention-based deletion of stored evidence and uploaded files is not currently active. Files remain until deleted by you or by us on your instruction.
3.4 Audit log entries are not deleted when the underlying record is deleted, because their purpose is to evidence what happened.
| Record type | Default retention |
|---|---|
| Staff employment records | 6 years after employment ends |
| Recruitment records for unsuccessful candidates | 6 months after the recruitment decision, unless you instruct otherwise or a legal hold applies |
| Right-to-work documentation | Duration of employment plus 2 years |
| DBS certificate detail | 6 months after the recruitment decision. The check date, certificate reference and outcome may be retained on the staff record for the duration of employment |
| Training and qualification records | Duration of employment plus 6 years |
| Supervision and appraisal records | Duration of employment plus 6 years |
| Resident care and service-user records | 8 years after the last entry or after the resident leaves the service, subject to any longer statutory requirement or legal hold |
| Incident, accident and safeguarding records | In accordance with your safeguarding and incident retention schedule. Accident records are retained for at least 3 years |
| Complaints and compliments | In accordance with your complaints policy |
| Routine check records | 3 years |
| Compliance documents (policies, certificates, insurance) | Current version, plus superseded versions for 6 years |
| Meeting records | 3 years |
| Audit log | Retained indefinitely. The audit log is append-only. For records that have been deleted, it is in some cases the only remaining evidence that the record existed and what was done to it |
Where a legal hold applies to any record, retention continues until the hold is lifted, regardless of the period above.
5.1 Account and authentication data is retained for 12 months after the account is closed or the user is deactivated.
5.2 Billing records are retained for 7 years to meet accounting and tax requirements.
5.3 Support correspondence is retained for 3 years.
5.4 Platform security telemetry is retained for 12 months.
5.5 Transactional email content and delivery activity is retained by our email sub-processor for 45 days. This is the standard retention period on our plan and cannot currently be reduced.
6.1 Database dumps are retained for 30 days and point-in-time recovery data for 35 days. The single most recent database dump is always retained so that recoverability is never lost, and where scheduled backups have stopped running that dump persists beyond 30 days until backups resume.
6.2 Deleting a record removes it from the active platform immediately. It persists in backups until those backups expire on the normal cycle.
6.3 We do not restore individual records from backup to satisfy a deletion request, and we do not use backups to reinstate deleted data except in a disaster recovery scenario.
7.1 Retention after termination is governed by the Cancellation and Data Export Policy.
8.1 We may publish new versions of this policy. Changes take effect on publication and the current version is always available at https://trine.uk/legal/data-retention.