Data Retention Policy
Last updated: 6 February 2024
This Data Retention Policy describes how bifixoo ("we", "us", "our") collects, retains, and disposes of personal data and other information in connection with the services available at bifixoo.com. By using our services, you acknowledge the practices described in this policy.
1. Purpose
We retain data only for as long as necessary to fulfil the purposes for which it was collected, to provide and improve our services, to comply with applicable legal obligations, to resolve disputes, and to enforce our agreements. This policy establishes clear standards for how long different categories of data are kept and how they are securely disposed of when no longer needed.
2. Scope
This policy applies to all personal data and non-personal data processed by bifixoo, including data collected through our website, learning platform, communication channels, and any associated services. It covers data held in electronic systems, cloud storage, databases, and any other medium used to store information.
3. Categories of Data We Retain
3.1 Account and Registration Data
Information provided when creating an account, such as name, email address, and contact details. This data is retained for the duration of the active account and for a period following account closure as described in Section 5.
3.2 Learning and Course Activity Data
Records of course enrolments, progress, completion status, assessment results, and engagement with learning materials. This data supports the delivery of educational services and is retained to allow users to access their learning history.
3.3 Communication Data
Messages, support requests, feedback submissions, and correspondence sent to or received from us. This data is retained to maintain a record of interactions and to improve service quality.
3.4 Technical and Usage Data
Log files, IP addresses, browser type, device identifiers, session data, and analytics information collected automatically when you use our services. This data is used for security, performance monitoring, and service improvement.
3.5 Payment and Transaction Data
Records related to purchases, billing, and financial transactions. Payment card details are not stored directly by us; however, transaction references and billing records are retained for accounting and legal compliance purposes.
3.6 Marketing and Preference Data
Subscription preferences, communication opt-ins, and marketing interaction data. This data is retained while you maintain an active relationship with us or until you withdraw consent.
4. Retention Periods
| Data Category | Retention Period | Basis for Retention |
|---|---|---|
| Account and registration data | Duration of account plus 3 years after closure | Contractual obligation, legitimate interest |
| Learning and course activity data | Duration of account plus 5 years after closure | Service delivery, legitimate interest |
| Communication and support data | 3 years from date of last interaction | Legitimate interest, dispute resolution |
| Technical and usage data | 12 months from collection | Security, service improvement |
| Payment and transaction data | 7 years from transaction date | Legal and accounting obligations |
| Marketing and preference data | Until consent is withdrawn or 2 years of inactivity | Consent, legitimate interest |
| Backup and archived data | Up to 12 months beyond primary retention period | Data integrity, disaster recovery |
Retention periods may be extended where we are required to preserve data in connection with a legal claim, regulatory investigation, or other legal process. In such cases, data will be retained until the matter is fully resolved.
5. Account Closure and Data Handling
When an account is closed, whether by the user or by us, personal data associated with that account enters a restricted state. During this period, data is no longer actively used for service delivery but is retained in accordance with the periods set out in Section 4. Access to this data is limited to authorised personnel with a legitimate need.
Upon expiry of the applicable retention period, account data is securely deleted or anonymised so that it can no longer be attributed to an identifiable individual.
6. Anonymisation and Aggregation
Where data is no longer required in identifiable form but retains value for analytics, research, or service improvement, we may anonymise or aggregate it rather than delete it. Anonymised data that cannot reasonably be used to identify any individual is not subject to the retention periods in this policy and may be retained indefinitely.
7. Data Deletion and Disposal
7.1 Secure Deletion
When personal data reaches the end of its retention period, it is deleted using methods appropriate to the medium on which it is stored. Electronic data is overwritten or otherwise rendered unrecoverable. Physical media, where applicable, is destroyed in a manner that prevents recovery.
7.2 Deletion Requests
Users may request deletion of their personal data at any time by contacting us at help@bifixoo.com. We will assess such requests in accordance with applicable obligations. Where we are required to retain certain data by law or for legitimate purposes, we will inform the requesting party and retain only the minimum data necessary.
7.3 Backup Systems
Data deleted from primary systems may persist in backup copies for a limited period. Backups are subject to their own scheduled deletion cycles, and personal data within backups will be removed no later than 12 months after deletion from primary systems.
8. Third-Party Data Processors
We engage third-party service providers to assist in delivering our services. These providers may process personal data on our behalf and are contractually required to retain and delete data in accordance with our instructions and this policy. We take reasonable steps to ensure that third-party processors maintain appropriate data retention and deletion standards.
9. Data Security During Retention
All retained data is protected by appropriate technical and organisational security measures throughout its retention period. These measures include access controls, encryption where appropriate, and regular review of data holdings to identify and remove data that is no longer required.
10. Review of This Policy
We review this Data Retention Policy periodically to ensure it remains accurate and appropriate. Changes to our services, legal requirements, or operational practices may result in updates to retention periods or procedures. The date at the top of this page reflects when the policy was last revised. Continued use of our services after any update constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Data Retention Policy or wish to exercise any rights relating to your personal data, please contact us using the details below.
bifixoo
Brunswick St N, Dublin, D07 VF57, Ireland
Phone: +353 1 841 1594
Email: help@bifixoo.com
Website: bifixoo.com