⚠️ DRAFT — This schedule requires review by a UK-qualified data protection solicitor or your appointed DPO before launch. Bracketed [PLACEHOLDERS] must be filled in before the Platform goes live.

Data Retention Schedule

Last updated: April 2026 · Version: 1.0 (DRAFT) · Jurisdiction: United Kingdom & European Union

This Data Retention Schedule is the reference document that sits underneath our Privacy Policy. It sets out, for each category of personal data we process, how long we retain it, the lawful basis, and the trigger for deletion.

It exists to satisfy:

  • UK GDPR Article 5(1)(e) — personal data must be kept for no longer than is necessary for the purposes for which it is processed ("storage limitation");
  • UK GDPR Article 30 — the obligation to maintain a record of processing activities (ROPA);
  • ICO guidance on retention schedules published at ico.org.uk;
  • Online Safety Act 2023 record-keeping requirements for age-assurance and illegal-content handling;
  • HMRC and Companies Act 2006 record-keeping for financial transactions.

Where statute imposes a minimum retention period that is longer than our operational need, we retain for the statutory minimum. Where statute imposes a maximum that is shorter than our operational need, we retain only for the statutory maximum.


1.How this schedule works

For every category listed below we record:

  • What it is — the data category.
  • Where it lives — the system(s) that hold it.
  • Retention period — how long we keep it.
  • Trigger for deletion — what event starts the clock.
  • Legal basis — Article 6 (and Article 9 where applicable) grounds.
  • Deletion method — how we actually erase it.

"Retention" means live, queryable storage. We also run backups on a rolling 35-day cycle. When a record is deleted from live storage, it is removed from backups no later than 35 days later — we do not restore a deleted record from a backup except in an emergency authorised by an authenticated data subject or a court order.


2.Account and profile data

CategoryWhereRetentionTriggerLawful basis
Email, hashed password, username, account settingsSupabase (PostgreSQL, EU region)Life of account + 30 days after deletion request (grace period for reactivation and fraud review)User requests deletion, OR account inactive for 24 monthsArt. 6(1)(b) contract
Display name, bio, pronouns, orientation self-labelsSupabaseSame as aboveSameArt. 6(1)(b) contract + Art. 9(2)(a) explicit consent for special-category inferences
Relationship status / configurationSupabaseSame as aboveSameArt. 6(1)(b) + Art. 9(2)(a)
Location (city/region only — no persisted GPS)SupabaseSame as aboveSameArt. 6(1)(b)
Blocked-user lists and hotlistSupabaseSame as aboveSameArt. 6(1)(f) legitimate interests (member safety)

Deletion method: hard-delete from PostgreSQL; cascading deletion triggers remove dependent records. Verified by automated post-deletion audit query running 24h after deletion.


3.Media (photos and videos)

CategoryWhereRetentionTriggerLawful basis
Profile photos (original + derivatives)Cloudflare R2 — bucket profile-photosLife of account + 30 daysUser deletes image / user deletes accountArt. 6(1)(b) + Art. 9(2)(a) where image is intimate
Quick Post photosCloudflare R2 — bucket profile-photosPermanent while account is active (note: Quick Post status/looking-for/event-shortcut expire by type — see Privacy Policy §7; photo posts persist)Same as aboveSame
Profile videos (original)Cloudflare R2 — bucket profile-videos (default)Life of account + 30 daysSameSame
Messaging media (chat attachments, ephemeral views)Cloudflare R2 — messaging bucket24 hours for ephemeral media; duration of conversation + 2 years for standard mediaAuto-expiry / user deletes / account deletionArt. 6(1)(b)
Blurhash thumbnails + image-processing derivativesCloudflare R2Same as parent mediaSameSame

Deletion method: R2 DELETE operations with bucket-level lifecycle confirmation. Files on replica regions are purged within 24 hours. Backblaze B2 video replicas (if enabled) are purged on the same cadence.


4.Messaging

CategoryWhereRetentionTriggerLawful basis
Direct message contentSupabase (encrypted at rest)2 years from sending, OR until account deletion, whichever is soonerRolling window OR account deletionArt. 6(1)(b)
Message metadata (timestamps, read receipts)SupabaseSameSameSame
Reported messages (flagged for review)Supabase + moderation DB3 years from report to retain evidence against repeat offendersReport closure + 3 yearsArt. 6(1)(c) legal obligation + Art. 6(1)(f)
Video-call session records (LiveKit)LiveKit session logs30 days (no recording of call content — only session metadata)30-day rollingArt. 6(1)(f)

5.Age-verification records

These are retained under a distinct regime because the Online Safety Act imposes record-keeping duties for age-assurance processes.

CategoryWhereRetentionTriggerLawful basis
Fact of age verification (boolean + method + timestamp + provider reference ID)Supabase age_verifications tableLife of account + 7 years after account closureAccount deletionArt. 6(1)(c) legal obligation (OSA)
DOB self-declaration (where permitted — not in UK/EU production)SupabaseLife of accountAccount deletionArt. 6(1)(b)
Third-party provider transaction ID (VerifyMyAge or equivalent)SupabaseSame as fact-of-verificationSameArt. 6(1)(c)
Identity documents / selfies / biometric templatesNot stored by us. Held by the age-assurance provider under their own retention schedule.N/A — we never receive the document imagesN/AN/A

We deliberately do not receive or store ID documents, biometric face templates, or credit-card numbers from age-assurance providers. We only receive a pass/fail result and a reference ID.


6.Financial records

CategoryWhereRetentionTriggerLawful basis
Subscription records (tier, start date, end date, price)Supabase + CCBill7 years after final transactionSubscription end + 7 yearsArt. 6(1)(c) legal obligation (Companies Act 2006, VATA 1994 s.58, HMRC guidance for record-keeping)
Invoices and receiptsSupabase + CCBill7 yearsSameSame
Refund and chargeback recordsCCBill + internal finance log7 years after resolutionDispute resolution + 7 yearsArt. 6(1)(c)
Payment-card data (PAN, CVV, expiry)Not stored by us. CCBill handles PCI-scope data under PCI-DSS.N/AN/AN/A
Billing name and addressCCBill (primary), Supabase billing shadow table7 years after final transactionSame as invoicesArt. 6(1)(c)

We rely on CCBill's PCI-DSS compliant systems for card data. We retain only the fields needed for accounting and dispute resolution.


7.Moderation, safety, and illegal-content records

CategoryWhereRetentionTriggerLawful basis
Reports received from members (Tier 1 and Tier 2)Supabase moderation schema3 years from report closureCase closed + 3 yearsArt. 6(1)(c) + Art. 6(1)(f)
Moderation decisions (removals, suspensions, bans) and rationaleSupabase moderation schema3 years from decisionDecision + 3 yearsSame
Automated moderation classifier scores (NudeNet, Sightengine)Supabase (short-term) + data warehouse (aggregated)90 days at record level; aggregated/anonymised indefinitelyRolling 90dArt. 6(1)(f)
Appeal recordsSupabase3 years from appeal closureAppeal closed + 3 yearsArt. 6(1)(c) + Art. 6(1)(f)
Evidence of Category A violations (CSAM, terrorism)Preserved per law-enforcement / NCMEC / IWF / CTIRU instructions — may exceed 3 years where a referral is openPer direction of law enforcementReferral openArt. 6(1)(c) + Art. 6(1)(d) vital interests + Art. 9(2)(g) substantial public interest
CyberTipline submission receipts (NCMEC)Secure evidence storeIndefinite or as directedSubmissionArt. 6(1)(c) (18 U.S.C. § 2258A)
Age-gating breach investigations (underage user suspected)Secure evidence store7 years from closureClosure + 7 yearsArt. 6(1)(c)

Where we receive a preservation order from law enforcement or a court, we preserve the specified records for the period stated in the order — this overrides ordinary retention.


8.Technical, security, and operational logs

CategoryWhereRetentionTriggerLawful basis
Web-server access logs (IP, user-agent, URL, status, timestamp)Cloudflare + internal log store30 daysRolling 30dArt. 6(1)(f) security, fraud detection
Authentication events (logins, password resets, MFA events)Supabase Auth + internal log12 monthsRolling 12 monthsArt. 6(1)(f) + Art. 6(1)(c)
Application error logs (Sentry)Sentry (EU region)90 daysRolling 90dArt. 6(1)(f)
Push-notification delivery logsInternal log30 daysRolling 30dArt. 6(1)(f)
Rate-limit and abuse-detection eventsInternal log12 monthsRolling 12 monthsArt. 6(1)(f)
Security-incident investigation filesSecure evidence store6 years from closureIncident closed + 6 yearsArt. 6(1)(f) + Art. 6(1)(c) (Limitation Act 1980 for potential civil claims)
Data subject request (DSR) recordsDSR register6 years after fulfilmentFulfilment + 6 yearsArt. 6(1)(c) + ICO guidance

9.Communications and marketing

CategoryWhereRetentionTriggerLawful basis
Transactional email (account, security, billing) logsResend / Supabase12 monthsRolling 12 monthsArt. 6(1)(b)
Marketing email opt-in / newsletterResendUntil opt-out, then 3 years for suppression-list purposes (so we don't re-send)Opt-outArt. 6(1)(a) consent (then Art. 6(1)(f) for suppression)
In-app notification historySupabase90 daysRolling 90dArt. 6(1)(b)
Support / contact form submissionsSupabase3 years from closureClosed + 3 yearsArt. 6(1)(b) + Art. 6(1)(f)
Complaints submitted under the Complaints ProcedureSecure complaints register6 years from closureClosed + 6 yearsArt. 6(1)(c) (OSA record-keeping + Limitation Act 1980)

10.Analytics

CategoryWhereRetentionTriggerLawful basis
PostHog event stream (pseudonymous)PostHog (self-hosted / EU-hosted)12 months at event level; aggregated indefinitelyRolling 12 monthsArt. 6(1)(a) consent
Session replaysDisabled. We do not run session replay on adult-content surfaces.N/AN/AN/A
A/B test assignment recordsPostHogDuration of experiment + 90 daysExperiment end + 90dArt. 6(1)(a)

11.Data we do not retain

For clarity — we do not store, and have never stored:

  • Raw face images, biometric templates, or identity-document images submitted to age-assurance providers (these live with the provider).
  • Raw payment-card numbers, CVVs, or card-expiry dates (these live with CCBill).
  • Your keystrokes, mouse movements, scroll behaviour, or session replays.
  • "Shadow" profile data scraped from social networks.
  • Device fingerprints used for cross-site tracking.

12.Deletion of backups

Backups are held on a rolling 35-day window. When a record is deleted from live storage, the deletion propagates to backups within that window. We do not restore individual deleted records from backup except where required by a court order or by the data subject themselves.

Where we receive a legal preservation notice — for example a subpoena, court order, civil-discovery preservation notice, or law-enforcement preservation order — we preserve the identified records for the required period, notwithstanding the retention periods in this schedule. Affected data subjects will be notified of the hold where we are permitted to do so.

14.Review cadence

This schedule is reviewed:

  • at least annually by the data protection lead;
  • whenever a new processor, data category, or product surface is introduced;
  • whenever a change in UK or EU law affects a retention period;
  • immediately after any material security incident.

15.Contact

[LEGAL ENTITY] — company number [COMPANY NUMBER] — registered at [REGISTERED OFFICE ADDRESS]

Data Protection queries: privacy@galerieminuit.com (placeholder) Data Protection Officer: [DPO NAME AND CONTACT — to be appointed before launch] ICO registration reference: [ICO REGISTRATION NUMBER — to be confirmed]


This document is a draft. It must be verified against your live systems, reviewed by a UK-qualified solicitor or your appointed Data Protection Officer, and fact-checked against your ROPA before it is published.