Data Retention & Deletion
Last updated: 2026-08-12
This policy explains how long InspectReady (Crocker Digital Ltd, company no. 17008789) keeps your data, and what happens when you delete it or close your account. It is referenced by our Privacy Policy and our Data Processing Agreement.
The short version
- Your home's policies, audits, and evidence files are kept for the life of your subscription.
- When your subscription ends — whether you cancel, or it lapses because a payment failed or a trial expired without one — we keep everything through a 30-day grace period so you can reactivate or export, including the evidence packs you have already generated. After that, a scheduled sweep deletes your evidence files and evidence records, deletes the downloadable pack archive (the ZIP) along with them — the archive holds copies of those same files — and anonymises the account holder's profile name. Your policies, audits, findings, readiness assessments, and the record of each evidence pack (its date range, contents list, and file hashes), together with any summary-only PDF generated in place of a ZIP, are retained as part of your compliance record and are removed on request.
- You can request a data export or account deletion by emailing our privacy team, which we action within one month.
- Our audit log — an append-only record of key account and compliance events — is kept as a compliance record. On deletion we remove or anonymise the personal data; we do not rewrite or destroy the log's historical events.
Retention windows
| Data | Kept for | Then |
|---|---|---|
| Evidence files and evidence records | Life of the subscription | Deleted after the 30-day grace window that follows the end of your subscription |
| Policies, audits, findings, readiness assessments | Life of the subscription | Retained as part of your compliance record; removed on request |
| Generated evidence packs — the downloadable ZIP archive | Life of the subscription, plus the 30-day grace window | Deleted together with your evidence files, because the archive holds copies of them |
| Generated evidence packs — the pack record (date range, contents list, file hashes) and any summary-only PDF | Life of the subscription | Retained as part of your compliance record; removed on request |
| Account profile (name, email, role) | Life of the account | Name anonymised after the grace window; profile removed on request |
| Billing records | As required by law (tax/accounting) | Retained by our payment processor per its own retention rules |
| Audit-log events (team invitations, evidence deletion, administrative changes, retention purge) | Retained as a compliance record | Personal identifiers anonymised on account deletion; events not destroyed |
| Cookieless analytics (GoatCounter) | Aggregated, no personal data | N/A |
How deletion works
After the 30-day grace period that follows the end of your subscription, a scheduled sweep:
- Removes your evidence files from private storage and deletes your evidence records.
- Removes the downloadable evidence-pack archive (the ZIP) for that home. A pack ZIP embeds a verbatim copy of every evidence file it covers, so keeping it would keep the very data step 1 deletes.
- Anonymises the account holder's profile name and revokes access.
Your policies, audits, findings, readiness assessments, and the record of each evidence pack — its date range, contents list, and file hashes — are retained as part of your compliance record, as is any summary-only PDF that was generated in place of a ZIP (a summary contains no evidence files). You can ask us to remove them — and to fully erase your remaining profile data — at any time, and we action erasure requests within one month (see Requesting export or deletion below).
Download your packs before the grace window closes. A pack you generated stays downloadable for the whole grace period, including while the account is suspended for non-payment, but the ZIP is removed with the evidence at the end of it.
If you delete your account directly, we begin this process without waiting for the grace period.
Erasure and the append-only audit log
InspectReady keeps an append-only audit log of key account and compliance events. Database rules prevent it being edited or deleted through the application — UPDATE and DELETE are revoked from every role the service runs as — so that it can serve as a contemporaneous compliance record consistent with Regulation 17(2)(c) of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and so that a historical evidence pack can be tied to the framework version it was built under. We retain administrative access to the underlying database, as any operator must; the controls above make the log tamper-evident against use of the product, not tamper-proof against us.
Because that ledger is append-only, an erasure request or account deletion is fulfilled by removing or anonymising the personal data associated with an individual (profile fields, evidence contents and metadata) and revoking access — not by destroying the log's historical events. Personal identifiers in the log are minimised or dissociated from the natural person so far as the append-only ledger allows. This reflects Article 17(3)(b) and (e) of the UK GDPR (retention for compliance with a legal obligation and for the establishment or defence of legal claims). It means we do not promise that every database row referencing you is physically destroyed where an append-only compliance record must be retained — erasure here is removal and anonymisation, consistent with audit-log retention.
Requesting export or deletion
- From Settings: use Request a data export or Request account deletion — we action these within one month.
- By email: contact
privacy@inspectready.co.uk. We respond to data-subject requests without undue delay and within one month, as required by the UK GDPR.
If you are a resident, service user, member of staff, or other individual whose data a care home has uploaded to InspectReady, the care home is the controller of that data — please contact them directly, or contact us and we will forward your request to them.