Data Retention Policy
Last Updated: February 26, 2026
This Data Retention Policy describes how Humypaa collects, stores, and manages data relating to users of the platform available at humypaa.com. It explains how long different categories of data are retained, the reasons for those retention periods, and how data is disposed of when it is no longer needed.
By using our platform, you acknowledge that your data will be handled in accordance with this policy. This policy forms part of our broader Privacy Policy and should be read alongside it.
1. Purpose of This Policy
Humypaa retains data only for as long as necessary to fulfil the purposes for which it was collected, to comply with applicable legal and regulatory obligations, to resolve disputes, and to enforce our agreements. This policy establishes consistent standards for data retention across all systems and processes operated by Humypaa.
The objectives of this policy are to:
- Define clear retention periods for each category of data we hold
- Ensure data is not kept longer than necessary
- Protect individuals whose data we process
- Support operational continuity and legal compliance
- Establish a structured process for secure data disposal
2. Scope
This policy applies to all personal data and non-personal data processed by Humypaa, including data collected through:
- User registration and account management
- Platform usage, workshops, and interactive exercises
- Communications via email, contact forms, or support channels
- Payment and billing processes
- Marketing and promotional activities
- Technical systems including logs, analytics, and cookies
This policy applies to all staff, contractors, and third-party processors who handle data on behalf of Humypaa.
3. Data Categories and Retention Periods
The table below sets out the main categories of data we process and the standard retention periods applied to each.
| Data Category | Examples | Retention Period | Basis for Retention |
|---|---|---|---|
| Account and profile data | Name, email address, username, password hash, profile settings | Duration of account plus 2 years after closure | Contractual obligation, legitimate interest |
| Learning and progress data | Workshop completions, assignment submissions, exercise results, certificates | Duration of account plus 3 years after closure | Legitimate interest, service delivery |
| Payment and billing data | Transaction records, invoices, payment method type (not full card numbers) | 7 years from transaction date | Legal and financial compliance |
| Communication records | Support tickets, email correspondence, feedback submissions | 3 years from last interaction | Legitimate interest, dispute resolution |
| Marketing data | Email preferences, campaign interaction history, opt-in records | 3 years from last engagement or until opt-out | Consent, legitimate interest |
| Technical and system logs | IP addresses, access logs, error logs, session data | 12 months | Security, fraud prevention |
| Analytics data | Aggregated usage statistics, page views, feature usage | 26 months (anonymised thereafter) | Legitimate interest, platform improvement |
| Cookie data | Session cookies, preference cookies, analytics cookies | As specified in our Cookie Policy (typically 1–24 months) | Consent, functionality |
| Contractual documents | Signed agreements, terms acceptance records | 7 years from contract end | Legal compliance, dispute resolution |
| Backup data | System backups containing any of the above | Overwritten on a rolling 90-day cycle | Business continuity |
Where a legal obligation requires us to retain data for a longer period than stated above, the longer period will apply. Where data is no longer needed before the end of the stated period, it will be deleted or anonymised earlier.
4. Basis for Determining Retention Periods
Retention periods are determined by reference to one or more of the following factors:
- Legal and regulatory requirements: Certain categories of data must be kept for minimum periods under applicable law, including financial, tax, and employment records.
- Contractual obligations: Data may need to be retained for the duration of a contract and for a reasonable period afterwards to address any claims arising from it.
- Legitimate business interests: We may retain data where there is a genuine and proportionate business reason, such as resolving disputes, preventing fraud, or improving our services.
- Consent: Where processing is based on consent, data is retained until consent is withdrawn or expires, unless another basis applies.
- Limitation periods: Data relevant to potential legal claims may be retained for the duration of applicable limitation periods.
5. Account Closure and Data Deletion
5.1 User-Initiated Account Closure
When a user requests closure of their account, we will begin the process of removing or anonymising personal data associated with that account. Certain data may be retained beyond the closure date where required by this policy or applicable law.
Following account closure:
- Active profile and login credentials are deactivated immediately
- Personal data is flagged for deletion and removed within 30 days, subject to the retention periods set out in Section 3
- Aggregated or anonymised data derived from your usage may be retained indefinitely as it no longer identifies you
5.2 Inactive Accounts
Accounts that have had no activity for a continuous period of 24 months are considered inactive. We will notify the registered email address at least 30 days before taking any action. If no response is received, the account may be closed and data handled in accordance with the account closure process described above.
5.3 Requests for Early Deletion
Users may submit a request for deletion of their personal data at any time by contacting us at contact@humypaa.com. We will assess each request and respond within a reasonable timeframe. Where deletion is not possible due to a legal or contractual obligation, we will inform the requester and explain the reason for the limitation.
6. Data Anonymisation
Where data is no longer required in identifiable form but retains value for analytical or operational purposes, we may anonymise it rather than delete it. Anonymised data is processed in a way that permanently removes any means of identifying the individual to whom it originally related.
Once data has been properly anonymised, it falls outside the scope of this policy and may be retained and used indefinitely for purposes such as platform improvement, research, and reporting.
7. Data Disposal and Destruction
When data reaches the end of its retention period, it is disposed of securely. The method of disposal depends on the format and sensitivity of the data:
- Electronic data: Permanently deleted from active systems and purged from backups in accordance with the backup rotation schedule
- Database records: Deleted using secure deletion procedures that prevent recovery
- Physical records (if any): Destroyed using cross-cut shredding or equivalent secure method
- Third-party held data: Disposal instructions are issued to processors in accordance with data processing agreements
Disposal activities are logged to maintain an auditable record of data lifecycle management.
8. Third-Party Data Processors
Humypaa may share data with third-party service providers who process data on our behalf, including hosting providers, payment processors, analytics services, and communication platforms. All such processors are required to:
- Process data only on our documented instructions
- Maintain retention and deletion practices consistent with this policy
- Delete or return data at the end of their engagement with us
- Provide sufficient guarantees regarding their data protection practices
A list of current processors and further information on data sharing is available in our Privacy Policy.
9. Security During Retention
Data held during its retention period is protected by appropriate technical and organisational security measures, including:
- Encryption of data at rest and in transit
- Access controls limiting data access to authorised personnel only
- Regular security assessments and vulnerability testing
- Monitoring and logging of access to sensitive data
- Staff training on data handling obligations
Security measures are reviewed and updated regularly to reflect current best practice.
10. Your Rights
Depending on your location and applicable law, you may have rights in relation to the personal data we hold about you. These may include the right to:
- Access a copy of your personal data
- Request correction of inaccurate data
- Request deletion of your data where no legitimate basis for retention exists
- Object to or restrict processing of your data
- Request portability of your data in a structured, machine-readable format
- Withdraw consent where processing is based on consent
To exercise any of these rights, please contact us at:
Humypaa
5 Templeroan Dr, Rathfarnham, Dublin 16, D16 W8X2, Ireland
Email: contact@humypaa.com
Phone: +353 65 684 0088
We will respond to all requests within a reasonable timeframe and in accordance with our legal obligations. We may need to verify your identity before processing a request.
11. Policy Review and Updates
This policy is reviewed at least annually and updated as necessary to reflect changes in our data processing activities, applicable law, or best practice. When material changes are made, we will notify users through the platform or by email.
The date at the top of this document indicates when the policy was last revised. Continued use of the platform following any update constitutes acceptance of the revised policy.
12. Contact
If you have any questions about this Data Retention Policy or how we manage your data, please contact us:
Humypaa
5 Templeroan Dr, Rathfarnham, Dublin 16, D16 W8X2, Ireland
Email: contact@humypaa.com
Phone: +353 65 684 0088
Website: humypaa.com