Retention policy
We keep each category of data only as long as the reason for holding it lasts. This table is the whole policy: if a category is not on it, we should not be holding it.
| Category | What we hold | How long | Why |
|---|---|---|---|
| Advocate register entries | Name, practice number, admission date, status, county, firm | For as long as the entry is on the roll, and 12 months after it leaves it | A person checking who represented them needs the record to outlive the certificate |
| Advocate contact details | Email, phone, address, website, practice areas | Until the advocate switches them off or deletes their account, then immediately | Held on consent, so the moment consent ends the basis ends |
| Court and judicial officer entries | Court station details, officer name, court, designation, appointment date | Indefinitely, including after retirement, marked as retired | Public record of who held judicial office, and a decision has to stay attributable |
| Decisions | Judgment text, case number, citation, court, date, presiding officers | Indefinitely, or until the source withdraws or anonymises it | Published under licence; we mirror the source, including its removals |
| Claim submissions | Verification codes, LSK proof of membership, county, firm size | Codes: 15 minutes. Proof documents: 90 days after the decision. Claim record: while the profile stays claimed | The proof exists to verify identity once, not to sit on a server afterwards |
| LawFirmly leads | Name, practice number, email, phone, county, practice areas, firm size, consent timestamp | 24 months from consent, or until withdrawal, whichever comes first | Consent has to be evidenced and refreshed rather than assumed to last |
| Data subject requests | Name, contact details, what was asked and what we decided | 6 years from the decision | Evidence that the process was followed, which is the point of having one |
| Site accounts and sessions | Email, name, password hash, session records | While the account exists; sessions expire and are cleared | Needed for sign-in and nothing else |
| Ingest records | Source, file path, row counts, timestamps | 6 years | Lets any published page be traced back to the licensed file that produced it |
Deletion in practice
An upheld erasure request removes the entry from every public page immediately. The row itself is retained in a deleted state so that the slug is never reissued to a different person and so that we can evidence the removal if asked. Nothing about the person remains readable on the site.
A later licensed ingest will not resurrect a removed entry: erasures are checked on every import.
Who to ask
Timothy Mwirabua owns this policy and reviews it annually. Requests go through the request form or straight to privacy@uwakili.com.