Alessia logo
FeaturesPricing
Clinicians

Clinicians

Specialists in Training

Specialty training logbook for busy doctors.

Portfolio Pathway Doctors

Comprehensive documentation management for specialist recognition pathways.

Migrating Doctors & IMGs

Migration-ready portfolios for doctors on the move.

BUILDING YOUR PORTFOLIO
What the Portfolio Pathway really costs
Read more
Portfolio Pathway success rates by specialty: What the numbers leave out
Read more
Institutions
Explore

Explore

Blog

Tips, guides, and behind-the-scenes thoughts from the team.

FAQ

Answers to the questions clinicians ask most.

THE LATEST FROM THE BLOG
How the ARCP panel reads your portfolio
Read more
About

About

About Alessia

What gets us up in the morning, and who we do it for.

Contact Us

Questions, ideas, feedback, love notes - we’re all ears. Drop us a line anytime.

Good reads for busy doctors
Portfolio logging habits that stick
Read more
The record that stays with you: Keeping one portfolio across a career
Read more
Coming soon...
Still on Logitbox?
Apple's 'Download on the App Store' iconGoogle's 'Get it on Google Play' icon
Download Alessia

Try Alessia for free in full. No tricks, no traps, no limits.

Apple's 'Download on the App Store' iconGoogle's 'Get it on Google Play' icon
Legal
Personal information retention and deletion schedule

Personal information retention and deletion schedule

About this document

FieldValue
Version1.0
Effective date1 August 2026
Publication date1 August 2026
Last reviewed18 July 2026
StatusApproved public document

Version history

VersionEffective dateChange summaryHow this version applies
1.01 August 2026Initial public versionApplies with the Privacy Notice; no separate acceptance is required

1. Principles

Alessia keeps personal information only for as long as reasonably necessary for the purposes described in our Privacy Notice, to provide the Service, meet legal and regulatory duties, resolve disputes and enforce agreements. When the applicable period ends, we delete the information, irreversibly anonymise it where appropriate, or restrict and isolate it while a documented legal hold applies.

Backup copies expire through their separate rotation cycle. If a backup is restored, applicable deletion instructions are reapplied before normal use.

The periods in section 2 reflect, among other things: the six-year limitation period for contract and most civil claims and the twelve-year period for deeds (Limitation Act 1980, sections 2, 5 and 8); company and tax record-keeping duties (Companies Act 2006 and HMRC requirements, generally six years from the end of the relevant financial year; seven years from year end is Alessia's chosen policy buffer, not a statutory requirement); and regulatory expectations for evidencing consent, rights requests and complaints handling. Where no statutory period applies, the period reflects a documented business need.

2. Retention periods

Record/categoryController/contextStandard retention periodEnd action
Active individual account and portfolioIndividual professional normally controller and Alessia processor for User Content; Alessia controller for account/operational recordsWhile the account remains active or its trial, subscription or paid service period remains currentContinue retaining the account and portfolio to provide the Service under the applicable role
Portfolio entry pending re-identification review, including a suspected direct identifierController depends on the accountNo separate automatic-deletion period applies merely because the entry is pending. It follows the active/expired account or Institution Customer Data period, an earlier valid deletion instruction, or a documented incident restriction or legal holdKeep the entry access-controlled and marked for review; show a persistent in-app review indicator; do not send reminder emails solely because it remains pending. An elevated combination may be acknowledged or remediated as permitted by the workflow. A suspected direct identifier must be removed and re-evaluated and cannot be cleared by acknowledgement alone. Delete the entry under the ordinary account, Institution or incident rule
Expired individual account and portfolioIndividual professional normally controller and Alessia processor for User Content; Alessia controller for account/operational recordsRead-only/export for exactly 90 days from trial/subscription expiry, including non-converting trials that contain portfolio dataDelete from live Service at day 90 unless renewed or subject to a documented legal hold/retention duty
User-requested account deletionIndividual professional instruction for User Content; Alessia controller for account/operational recordsAccess is revoked immediately and confirmation is sent. Live-database deletion is completed within 3 days, subject to identity verification and applicable legal, security or dispute-related exceptionsDelete/anonymise the live account and portfolio; retain only required records and expire backups under their separate cycle
Institution Customer DataInstitution controller; Alessia processorContract term plus negotiated read-only/export period in Order Document; default 90 daysReturn/delete on instruction; deletion default after exit period
Departed Institution memberInstitution controllerInstitution-configured/contracted period; account may become read-only without transfer to individual accountInstitution-directed restriction/deletion
Live deleted entries/filesController depends on accountRemove access immediately; complete the ordinary public-product live deletion job within 3 daysDelete from live database/object storage and derived indexes
Consumer rolling backups and replicasIndividual professional normally controller and Alessia processor for User Content; Alessia controller for its own recordsUp to 35 days after live deletionExpire by rotation; restore procedure re-applies deletion
Institution rolling backups and replicasInstitution controller; Alessia processorContracted period from 35 days to 7 years depending on the Institution's lawful preference and deploymentExpire by rotation; restore procedure re-applies deletion
Account-export ZIP file/linkController depends on account3 days after generationDelete generated export and revoke token; underlying entries follow account rule
PDF/report responseController depends on accountGenerated inline for the owning authenticated user; no persistent Alessia sharing link or stored report by designResponse completes; underlying entries follow account rule
Audio selected for transcriptionController depends on accountUser-kept source follows portfolio retention. The temporary transcription job and provider file copy follow the deletion and expiry period published in the Subprocessor ListDelete or expire the temporary provider copy; an approved transcript saved by the user follows portfolio retention
AI prompt/request and returned draftController depends on accountProvider-side inputs and outputs follow the current period published in the Subprocessor List; an approved output saved by the user follows portfolio retentionProvider deletion or expiry; retain in Alessia only content the user chooses to save
Product analytics eventsAlessia controller or Institution processor as configuredMaximum 365 days from event while identifiableDelete or approved aggregation/anonymisation
Public application/security logsAlessia controller90 days; longer only under a documented active investigation/legal holdDelete/aggregate
Institution portfolio audit logInstitution controller365 days by default; Order Document may specify another supported periodReturn/delete with Customer Data unless legally required
Shared operational logsAlessia controller/processor90 days by default; longer only under a documented active investigation/legal holdDelete/aggregate
Supervisor, assessor or colleague transparency email, notice evidence and no-contact suppressionIndividual professional or Institution controller and Alessia processor for portfolio/notice records; Alessia controller for minimum service-wide individual-account suppression/abuse preventionProcessor-held raw professional email: until successful notice delivery or no more than 30 days after first attempted delivery for retries and bounce handling. The email provider's delivery copy follows the current period in the Subprocessor List. Minimum protected notice evidence: 3 years after successful delivery or the final attempt, subject to a shorter controller instruction or documented legal requirement. Upheld no-contact suppression: while the relevant account or relationship remains active or until the objection is withdrawnNever include the email in portfolio reports. Remove the raw address from the portfolio and notification system when delivery/retry use ends. At evidence expiry, delete the protected recipient identifier, controller, notice version, date and delivery result. Apply the minimum Alessia-controlled suppression across individual-account controllers. Scope Institution-controlled suppression separately for each Institution and follow its instructions. The suppression record contains only a protected email identifier and scope and is deleted when its purpose ends
Identity, authentication and access-provider recordsAlessia controller/processorIdentity records are retained for the account life; provider authentication and access logs follow the current period published in the Subprocessor ListDelete the identity/provider mapping and revoke linked access on account deletion
Push-notification token and delivery eventsAlessia controller/processorDevice and push tokens are retained while notifications and the account remain enabled. Delivery-event records follow the current period published in the Subprocessor ListUnlink or delete the token when notifications are disabled, on logout where applicable, or when the account is deleted; delivery records then expire under the published provider period
Subscription, entitlement and transaction-provider eventsAlessia controllerSubscription and entitlement records are retained while needed to manage the subscription. Alessia's required transaction, accounting and tax records follow the seven-year financial-record period. Service-provider and app-store records follow the periods and independent legal duties described in the Subprocessor List and the provider's applicable termsFor requested account deletion, cancel direct-web renewal and delete the subscription-management provider's customer profile within the three-day live-deletion target. Retain only required cancellation, transaction, accounting and tax records. A later store-entitlement restoration does not restore deleted account or portfolio data
Subscription, invoices, tax and accountingAlessia controller7 years from the end of the relevant financial year; longer only where required by law, an audit/enquiry, a transaction spanning periods or documented legal holdDelete/minimise at expiry
Direct web payment tokens/referencesAlessia controller; approved merchant of record handles card dataWhile needed for the subscription; required transaction records follow the seven-year financial/tax periodDelete provider token where the account/payment relationship ends
App-store transaction recordsAlessia, store and subscription-provider respective rolesProvider rules; Alessia's required transaction records follow the seven-year financial/tax periodDelete/minimise Alessia copy
Support and ordinary enquiry recordsAlessia controller24 months after closure; a documented legal hold may extend only the necessary materialDelete/minimise the ticket; delete screenshots, diagnostic exports and other attachments as soon as no longer needed and no later than 90 days after closure
Complaint, dispute and legal-claim fileAlessia controller6 years after final closure. Retain necessary material longer only while proceedings, an appeal, regulator enquiry, insurer requirement, longer applicable limitation period or documented legal hold remains active; formally review a hold at least every 6 monthsDelete/minimise when the period and any hold end; anonymous trends may be retained while useful
Privacy rights request and identity-verification evidenceAlessia controller/processorMinimised case record: 3 years after completion. Identity-document copies: delete promptly and no later than 30 days after verification. Generated disclosure/response bundles and temporary exports: delete within 30 days after confirmed delivery. Documented legal hold/regulator need may extend only necessary evidenceDelete/minimise at expiry; retain only justified method, outcome, search/action and response evidence
Minimised security/privacy/clinical-safety incident fileAlessia controller/processor6 years after closure; longer only for a documented investigation, insurer/regulator requirement or legal holdDelete/minimise at expiry
Raw incident logs, screenshots, exports and affected contentRole assessed per incidentDelete as soon as no longer necessary and no later than 90 days after closure; longer only for a documented investigation, insurer/regulator requirement or legal holdSecurely delete and record confirmation in the incident file
Suspected prohibited patient dataRole assessed per incidentQuarantined only for the shortest period reasonably necessary to contain and investigate the incident, meet any notification or evidence-preservation duty, and securely delete the information. The exact period depends on the incidentDelete the patient information as soon as permitted. Retain only a minimised non-content incident record where necessary under the separate incident-record period
Marketing prospect/contactAlessia controllerActive account: while the single marketing choice remains valid. Newsletter-only lead or former user: until withdrawal/objection/unsubscribe, bounce/invalid address, or 24 months without a marketing-link click, reply, enquiry, purchase, preference update or renewed opt-in. Email opens and product use alone do not refresh the periodStop promptly; delete/anonymise the marketing profile or retain only the minimum suppression record
Marketing suppression recordAlessia controllerAs long as reasonably needed to honour an unsubscribe, withdrawal or objection and prevent accidental recontactRetain only email address or hash, opt-out date, scope and source
Cookie, analytics and marketing-choice evidenceAlessia controllerKeep the current minimal evidence while processing relies on the choice, then 3 years after withdrawal, supersession or the related processing ends. Keep master wording, banner/configuration and notice versions for 7 yearsAutomatically delete individual evidence at expiry; preserve a separate minimum marketing-suppression record where applicable
Executed customer, Institution and supplier contractsAlessia controllerContract term plus 7 years after termination or expiryDelete/minimise at expiry
Contracts executed as deedsAlessia controller12 years after termination or expiry, or longer where applicableDelete/minimise at expiry
Supplier security and privacy due diligenceAlessia controllerActive supplier relationship plus 7 yearsDelete/minimise at expiry
Unsuccessful proposals and procurement recordsAlessia controller2 years after the opportunity or procurement closesDelete/minimise at expiry
Routine non-marketing business contactsAlessia controllerActive relationship plus 2 yearsDelete/minimise at expiry
Constitutional and statutory company recordsAlessia controllerPermanently or for the period required by applicable company lawPreserve in controlled corporate record storage; review copies and superseded working material
Genuinely anonymous information, aggregate statistics and approved model artefacts derived only from themNot personal information after approved anonymisation and model-risk assessmentMay be retained while useful, including after deletion of the source account or contentReview periodically; delete when obsolete

3. Deletion workflow

When the applicable retention period ends, or we receive a valid deletion request or Institution instruction, we delete or irreversibly anonymise the information and require relevant service providers to do the same.

Backup copies are removed through their normal rotation cycle. We may retain a minimal record where necessary to show that the deletion request or instruction was completed.

4. Legal holds and exceptions

We may retain necessary information beyond the standard period where required for tax or accounting duties, legal proceedings, a regulatory request, a security or fraud investigation, insurance requirements, or the establishment, exercise or defence of legal claims.

While that exception applies, access and use are restricted to the relevant purpose. When the reason for extended retention ends, the normal deletion or anonymisation process resumes.

5. Institution configuration

Retention for Institution-controlled information is set by the Institution's Order Document and instructions. This may include member and leaver access, the post-termination export period, backup and audit-log periods, deletion timing and any agreed assistance.

If an Institution requests a period that is not legally or technically available, Alessia and the Institution must agree a supported alternative before the relevant service begins.

6. Review and evidence

We review this schedule at least annually and whenever a material change to our services, information handling or legal obligations may affect a retention period. Material updates are dated and recorded in the version history above.

Product
FeaturesPricing
Download
Download for iOSDownload for Android
Use Cases
InstitutionsPortfolio DoctorsInternational Medical GraduatesSpecialty Trainees
Read
About AlessiaFAQsBlog
Connect
Contact Us
Small sparks for big clinical weeks.  
Subscribe for genuinely useful reads.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

1-2 emails a month max. Unsubscribe any time.
© 2026 Alessia International Ltd. All rights reserved.
Registered in England and Wales, Company No. 17259224
Registered office: 27 Old Gloucester Street, London, WC1N 3AX UNITED KINGDOM
Legal
Cookies
Privacy notice
Website terms of use
Accessibility