Data Retention Policy
Last updated: October 3, 2024
This Data Retention Policy describes how Market Path collects, stores, and disposes of personal and operational data in connection with the services provided through marketpath.eu. By using our platform, you acknowledge the practices described in this document.
1. Purpose
Market Path retains data only for as long as necessary to fulfil the purposes for which it was collected, to maintain accurate records, to comply with applicable legal obligations, to resolve disputes, and to enforce our agreements. This policy establishes consistent standards for how long different categories of data are kept and how they are securely disposed of when no longer needed.
2. Scope
This policy applies to all data processed by Market Path, including data relating to registered users, seminar participants, prospective customers, and visitors to our website. It covers data held in electronic systems, databases, cloud storage, and any backup or archival systems maintained by or on behalf of Market Path.
3. Categories of Data and Retention Periods
The following table outlines the primary categories of data we process and the standard retention period applied to each.
| Data Category | Examples | Retention Period | Basis for Retention |
|---|---|---|---|
| Account and registration data | Name, email address, password hash, account settings | Duration of account plus 2 years after closure | Contractual necessity, legitimate interest |
| Participation and enrolment records | Seminar registrations, attendance logs, completion records | 5 years from the date of participation | Legitimate interest, record-keeping obligations |
| Payment and transaction data | Invoice details, payment confirmations, billing history | 7 years from the date of transaction | Financial and legal record-keeping |
| Communication records | Support tickets, email correspondence, chat logs | 3 years from the date of last interaction | Legitimate interest, dispute resolution |
| Technical and usage data | Log files, IP addresses, session data, error reports | 12 months from collection | Security monitoring, service improvement |
| Marketing and consent records | Newsletter subscriptions, consent timestamps, opt-out records | 3 years from last consent action or until withdrawal | Consent management, legal accountability |
| User-generated content | Discussion posts, submitted assignments, uploaded materials | Duration of account plus 1 year after closure | Service delivery, legitimate interest |
| Anonymised and aggregated data | Statistical reports, usage trends, performance metrics | Indefinite | No personal data present; used for platform improvement |
These periods represent standard defaults. Specific circumstances may require shorter or longer retention where justified and documented.
4. Retention Principles
4.1 Data Minimisation
We collect only the data that is necessary for the stated purpose. Data that is no longer required for its original purpose is reviewed for deletion or anonymisation on a scheduled basis.
4.2 Storage Limitation
Personal data is not kept in a form that allows identification of individuals for longer than is necessary. Where the purpose of processing has been fulfilled and no legal obligation requires continued storage, the data is scheduled for secure deletion.
4.3 Accuracy
During the retention period, reasonable steps are taken to ensure that stored data remains accurate and up to date. Users may update their account information at any time through their account settings or by contacting support.
5. Legal Holds and Extended Retention
In certain circumstances, data may be retained beyond the standard periods described above. These circumstances include:
- Ongoing or anticipated legal proceedings, investigations, or regulatory inquiries
- Requests from competent authorities requiring preservation of specific records
- Active disputes or unresolved complaints involving the data subject
- Contractual obligations requiring extended record-keeping for specific clients or partners
When a legal hold is applied, the affected data is flagged in our systems and excluded from routine deletion processes until the hold is formally lifted.
6. Backup and Archival Systems
Data held in backup or archival systems may persist beyond the active retention period due to the nature of backup cycles. Such data is not actively used for operational purposes and is subject to secure deletion in line with our backup rotation schedule. Backups are typically retained for no more than 90 days unless a legal hold applies.
7. Data Deletion and Anonymisation
7.1 Secure Deletion
When data reaches the end of its retention period, it is deleted using methods appropriate to the storage medium. Electronic data is overwritten or cryptographically erased in a manner that makes recovery impractical.
7.2 Anonymisation
Where deletion is not appropriate but continued use of data is justified for analytical or operational purposes, personal data may be anonymised. Anonymised data no longer constitutes personal data and falls outside the scope of this policy.
7.3 Account Closure
When a user closes their account, personal data associated with that account enters a post-closure retention period as described in the table above. During this period, the data is not used for active service delivery but is retained for legitimate administrative purposes. At the end of the post-closure period, the data is deleted or anonymised.
8. Third-Party Processors
Market Path may share data with third-party service providers who process data on our behalf. These processors are required by contract to apply retention and deletion standards consistent with this policy. We review processor agreements periodically to confirm that appropriate obligations remain in place.
9. User Rights Regarding Retained Data
Subject to applicable legal limitations, users may exercise the following rights in relation to data we hold:
- Access: Request confirmation of whether we hold personal data about you and obtain a copy of that data.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of personal data where retention is no longer justified and no legal obligation requires us to keep it.
- Restriction: Request that we limit processing of your data in certain circumstances.
- Objection: Object to processing carried out on the basis of legitimate interest.
- Portability: Request a copy of data you have provided to us in a structured, commonly used format.
To exercise any of these rights, please contact us at support@marketpath.eu or by post at County Road 16, Orangeville, ON L9W 2Z6, Canada. We will respond within a reasonable timeframe consistent with our obligations.
10. Security During Retention
Data retained under this policy is protected by appropriate technical and organisational measures throughout the retention period. These measures include access controls, encryption at rest and in transit, audit logging, and regular security assessments. Access to retained data is limited to personnel and systems with a legitimate operational need.
11. Policy Review
This policy is reviewed at least annually or when significant changes occur to our services, data processing activities, or applicable legal requirements. Where changes are material, we will notify users through appropriate channels prior to the changes taking effect. Continued use of our services following notification constitutes acceptance of the updated policy.
12. Contact
Questions or concerns regarding this Data Retention Policy may be directed to:
Market Path
County Road 16, Orangeville, ON L9W 2Z6,
Canada
Email: support@marketpath.eu
Phone: +1 416 878 8252