Data Retention Policy
We keep personal data only as long as we need it, and we are explicit about who decides how long that is.
Purpose
The UK GDPR requires that personal data is kept in a form which permits identification for no longer than is necessary for the purposes for which it is processed — the storage limitation principle. This policy sets out how NetFM UK Limited meets that requirement, and how retention decisions are made for the data we hold.
It sits alongside our Privacy Policy, GDPR statement, Information Security Policy and Record Management Policy. NetFM UK Limited is registered with the Information Commissioner's Office under registration number ZB049295.
Controller and processor: who decides
This is the most important distinction in this policy. For most of the personal data that passes through our systems — visitor records, staff parking allocations, bookings, vehicle registrations read by ANPR cameras — our customer is the data controller and NetFM is the processor. The retention period for that data is set by the customer in their contract and data processing agreement with us, and configured per deployment. We do not decide it, we do not extend it, and we do not repurpose that data.
Where a customer has not specified a period, we will ask them to; we will not silently default to keeping data indefinitely. On termination of a contract we return or securely delete customer personal data in accordance with the agreement, and confirm deletion in writing on request.
For our own records — employees, applicants, suppliers, our accounts, and enquiries made through this website — NetFM is the controller, and the periods below apply.
Retention periods where NetFM is the controller
| Record | Retention | Why |
|---|---|---|
| Website enquiry and support-request forms | 24 months from last contact | Responding to and following up enquiries |
| Customer contracts and related correspondence | 6 years after the contract ends | Limitation Act 1980 — contractual claims |
| Accounting records, invoices, expenses | 6 years from the end of the accounting period | Companies Act 2006 and HMRC requirements |
| Employee records (during and after employment) | 6 years after employment ends | Employment claims and statutory obligations |
| Payroll and PAYE records | 6 years from the end of the tax year | HMRC requirements |
| Unsuccessful job applications | 6 months from the decision | Equality Act 2010 claim window; discarded thereafter unless the applicant asks us to keep them on file |
| Right-to-work checks | 2 years after employment ends | Statutory excuse under immigration law |
| Accident and incident records | 3 years from the date of the entry | RIDDOR and personal injury claim window |
| Data breach records | 6 years from the incident | Accountability under UK GDPR Article 33(5) |
| System, access and audit logs | 12 months | Security monitoring and incident investigation |
| Backups | On a rolling cycle, then overwritten | Disaster recovery — see below |
Where a record is subject to a legal hold — an actual or anticipated claim, investigation or regulatory request — it is retained until the matter concludes, regardless of the period above.
Backups
Personal data deleted from a live system may persist in backups until those backups age out of the rolling cycle. We do not restore backups to retrieve data that has been deleted on request. Where we action an erasure request, the data is removed from live systems immediately and from backups as the cycle overwrites them; we will tell the individual or customer that this is how it works rather than claim an instant total deletion we cannot deliver.
Disposal
Electronic records are deleted from live systems and storage using methods appropriate to the sensitivity of the data. Storage media and end-user devices are securely wiped or destroyed before disposal or reuse. Paper records containing personal data are cross-cut shredded. Where a supplier disposes of equipment on our behalf we obtain confirmation of destruction.
Your rights
You have the right to ask what personal data we hold about you, to have it corrected, and in certain circumstances to have it erased or its processing restricted. Contact hello@netfm.org and we will respond within one month. If your data is held in a customer's system — for example if you visited or parked at a site that uses our software — the customer is the controller, and we will direct your request to them and support them in answering it. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.
Responsibility and review
The Directors are responsible for this policy. The Director of Operations reviews retention practice against it at least annually, and whenever we take on a new category of processing.
Owner: Nici Hills, Director of Operations · Last reviewed: August 2026 · Next review: August 2027
NetFM UK Limited, registered in England & Wales, company number 08165293. Questions about this policy: hello@netfm.org.