Last updated: January 2026
This Data Retention Policy explains how long WriteTrack Ltd ("we", "us", "our") retains personal data collected through our AI-powered writing assessment platform for UK primary schools.
We are committed to retaining your data only for as long as necessary to provide our service, comply with legal obligations, and protect our legitimate interests. This policy complies with the UK General Data Protection Regulation (UK GDPR) Article 5(1)(e), which requires data to be kept for no longer than necessary.
This policy applies to all users: teachers, school administrators, pupils, and parents. It should be read alongside our Privacy Policy.
Our data retention practices are guided by the following principles:
We only retain data where we have a lawful basis (consent, contract, legal obligation, or legitimate interests).
We retain data only for as long as required to fulfil the purpose for which it was collected, unless a longer retention period is required by law.
Personal data is securely deleted or anonymized when it is no longer needed, except where retention is required for legal, regulatory, or legitimate business purposes.
Users are clearly informed about retention periods and can request deletion of their data at any time (subject to legal exceptions).
We collect and retain only the minimum data necessary to provide our service effectively.
Teacher and School Administrator Accounts
Retention: Duration of active subscription
Includes: Name, email, school details, account settings, usage data
Pupil Data
Retention: Duration of teacher subscription
Includes: First name, last name, year group, username, class assignments
Submissions and Feedback
Retention: Duration of subscription
Includes: Handwritten work images, typed submissions, OCR transcriptions, AI-generated feedback, writing task metadata
Handwriting Samples (Biometric Data)
Retention: Duration of subscription (or until deletion requested)
Includes: Sample handwriting images, AI-extracted characteristics, quality scores
Classes and Tasks
Retention: Duration of subscription
Includes: Class names, cohorts, writing tasks, task metadata
All Personal Data
Retention: 30 days (grace period)
After account deletion, all personal data is retained for 30 days to allow for recovery in case of accidental deletion. After 30 days, all data is permanently and irreversibly deleted.
Anonymized Analytics
Retention: Indefinitely
Aggregated, anonymized usage statistics with no personally identifiable information are retained for service improvement.
Invoices and Payment Records
Retention: 7 years
Required by HMRC (UK tax authority) for accounting purposes under UK tax law.
Stripe Transaction Records
Retention: 7 years
Includes: Subscription type, status, payment dates (NOT full card details)
VAT Records
Retention: 6 years
Required by HMRC for VAT compliance.
Database Backups
Retention: 30 days
Automated daily backups retained for disaster recovery. Deleted data is overwritten within 30 days.
File Storage Backups
Retention: 30 days
Handwritten work images and handwriting samples in backups are purged within 30 days of deletion.
Transactional Emails (Resend)
Retention: 90 days
Email logs for welcome emails, payment confirmations, trial reminders, and account notifications.
Support Correspondence
Retention: 2 years
Support tickets and email correspondence for customer service and quality assurance.
Access Logs and Audit Trails
Retention: 3 years
For security monitoring, fraud detection, and GDPR compliance evidence.
Error Logs
Retention: 90 days
Sanitized error logs for debugging and service improvement (no personal data).
Session Cookies
Retention: 7 days (or until logout)
Authentication cookies for maintaining logged-in sessions.
We retain data based on the following lawful grounds under UK GDPR:
We retain teacher accounts, pupil data, submissions, and feedback for the duration of your subscription to fulfill our contractual obligation to provide the WriteTrack service.
Handwriting samples (biometric data) are retained based on explicit consent and can be deleted at any time upon request.
We conduct Legitimate Interests Assessments (LIAs) to ensure our retention practices do not override your rights and freedoms. Children's data is never retained solely on the basis of legitimate interests.
We use secure deletion methods to ensure data cannot be recovered once deleted:
When you delete your account, all associated data is automatically deleted through database cascade rules:
You have the right to request deletion of your data at any time under UK GDPR Article 17 (Right to Erasure / "Right to be Forgotten").
For Individual Teachers:
For School Administrators:
Parents can request deletion of their child's data by:
Some data is automatically deleted without user action:
We maintain automated backups for disaster recovery and business continuity. Backups are subject to the following retention policy:
Backups are restored only in the event of catastrophic data loss or system failure. We do NOT restore individual user data after deletion. Deletion is permanent.
UK tax law requires businesses to retain financial records for extended periods. This is a legal obligation under UK GDPR Article 6(1)(c).
Financial records retained for 7 years:
When you delete your account, all personal data is removed except for financial records required by law. We will inform you of this exception during the deletion process. Financial records are securely stored, access-controlled, and deleted after 7 years.
We are committed to collecting and retaining only the minimum data necessary to provide our service effectively, in accordance with UK GDPR Article 5(1)(c).
We regularly review our data collection and retention practices to ensure we are not retaining unnecessary data. Any data found to be no longer needed is securely deleted.
We conduct regular reviews of our data retention practices to ensure ongoing compliance with UK GDPR and best practices.
Under UK GDPR, you have the following rights related to data retention:
Request a copy of all data we hold about you, including retention periods and categories.
Correct inaccurate or incomplete data. You can update your account details in Settings.
Request deletion of your data (subject to legal exceptions like financial records). Use the account deletion feature in Settings.
Request we stop processing your data while verifying accuracy or assessing objections.
Request a copy of your data in machine-readable format (JSON, CSV). Contact us to request data export.
Object to processing based on legitimate interests. Contact us to exercise this right.
If you have any questions about our data retention practices or wish to exercise your rights, please contact us:
Data Protection Officer:
Email: privacy@writetrack.co.uk
General Support:
Email: support@writetrack.co.uk
Postal Address:
WriteTrack Ltd
Registered in England and Wales
We aim to respond to all enquiries within 5 business days. For data subject rights requests, we will respond within 30 days as required by UK GDPR.
If you believe we have not handled your data in accordance with UK GDPR, you have the right to complain to the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk