Data Retention Policy

Effective Date: July 2026
Last Reviewed: July 2026
Review Date: July 2027

⸻

1. Purpose

This Data Retention Policy explains how Ascent Events Limited retains, manages and securely disposes of personal information and business records.

The purpose of this policy is to ensure compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and other applicable legal and regulatory requirements.

We will only retain personal information for as long as necessary for the purpose for which it was collected or where required by law.

⸻

2. Scope

This policy applies to all employees, directors, contractors, consultants and third parties acting on behalf of Ascent Events Limited.

It covers information held electronically and in paper format, including:

  • Delegate registrations
  • Exhibitor registrations
  • Sponsor information
  • Speaker information
  • Customer enquiries
  • Marketing databases
  • Email correspondence
  • Financial records
  • Employee records
  • Contracts
  • Website enquiries
  • Survey responses
  • Paper documents

⸻

3. Legal Basis

This policy has been prepared in accordance with:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Privacy and Electronic Communications Regulations (PECR)
  • HMRC Record Keeping Requirements

⸻

4. General Retention Principles

Ascent Events Limited will:

  • only collect information necessary for legitimate business purposes;
  • retain information only for as long as necessary;
  • securely destroy information when it is no longer required;
  • review retained information regularly;
  • ensure information remains accurate and up to date.

Where legal proceedings, investigations or regulatory enquiries are ongoing, information may be retained beyond the standard retention period.

⸻

5. Security During Retention

Personal information will be protected by appropriate technical and organisational measures including:

  • Password protected systems
  • Restricted user access
  • Secure cloud storage
  • Antivirus and firewall protection
  • Secure backup procedures
  • Locked filing cabinets for paper records where applicable

Only authorised personnel will have access to personal information.

⸻

6. Secure Disposal

When information reaches the end of its retention period it will be securely destroyed.

Electronic records will be permanently deleted from live systems.

Paper records containing personal information will be confidentially shredded.

Where external disposal companies are used they must provide secure destruction services.

⸻

7. Data Retention Schedule

Event Records

Record

Retention Period

Delegate registrations

3 years after the event

Exhibitor registrations

6 years after the event

Sponsor records

6 years after the event

Speaker information

3 years after the event

Event attendee lists

3 years after the event

Badge printing information

Deleted within 3 months after the event unless required for audit purposes

Event enquiries

2 years

⸻

Marketing

Record

Retention Period

Email marketing subscribers

Until consent is withdrawn or 2 years after last meaningful engagement

Newsletter subscriptions

Until unsubscribed

Competition entries

12 months after completion

Customer surveys

2 years

⸻

Website

Record

Retention Period

Website contact forms

2 years

Website analytics

26 months

Cookies

In accordance with the Cookie Policy

⸻

Customer Records

Record

Retention Period

Customer correspondence

3 years after last contact

Contracts

6 years after termination

Quotations

2 years

⸻

Financial Records

Record

Retention Period

Invoices

6 years

Accounting records

6 years

VAT records

6 years

Bank records

6 years

Supplier information

6 years

⸻

Employee Records

Record

Retention Period

Personnel files

6 years after employment ends

Payroll records

6 years

Pension records

As required by law

Recruitment records (unsuccessful applicants)

6 months

Recruitment records (successful applicants)

Duration of employment

Training records

Duration of employment

⸻

Email

Record

Retention Period

General business emails

Up to 3 years

Emails relating to contracts or legal matters

6 years

Marketing emails

Retained in accordance with marketing consent requirements

⸻

8. Individual Rights

Individuals may request:

  • access to their personal information;
  • correction of inaccurate information;
  • deletion of personal information where appropriate;
  • restriction of processing;
  • objection to processing;
  • data portability where applicable.

Requests should be submitted to the Data Protection Lead.

⸻

9. Policy Compliance

All employees are responsible for complying with this policy.

Failure to comply may result in disciplinary action and, where appropriate, legal action.

⸻

10. Policy Review

This policy will be reviewed annually or sooner where changes in legislation or business practices require.

⸻

Contact

For any questions regarding this policy or data protection matters, please contact:

Guy Whiffen
Data Protection Lead
Ascent Events Limited

Email: [email protected]

If you are dissatisfied with how your personal information has been handled, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO).

menu