Data Retention Schedule
This Schedule sets the retention periods GRAM Systems and Concept Informatics Ltd (a company registered in the United Kingdom) — separate companies delivering Roger That! in partnership, and joint controllers under Art. 26 GDPR — apply to personal data they control directly: platform account holders, billing contacts and website enquirers. It gives effect to the storage limitation principle under GDPR Art. 5(1)(e).
1. Data you control
Operational data uploaded or entered by a customer — parts catalogues, assemblies, stock records, maintenance history, checklists, sign-offs and attachments — is retained for as long as that customer's agreement runs. It is deleted or returned on the customer's instruction at the end of the engagement, per our Data Processing Agreement.
Offshore customers commonly have their own obligations — client contracts, class or certification requirements, or IMCA-aligned record-keeping practice — that require maintenance history to be retained well beyond the life of an individual account. Roger That! does not impose a retention period on that history. Each customer sets its own and instructs us accordingly.
2. The schedule
| Record category | Retention period | Legal basis |
|---|---|---|
| Platform account data (name, work email, role) | Duration of account + 2 years | Contract / legitimate interests |
| Billing, subscription and invoice records | 7 years from transaction date | UK and Cyprus tax law |
| Demo requests and sales enquiries that do not become customers | 24 months from last contact | Legitimate interests |
| Support correspondence | 3 years from resolution | Legitimate interests |
| Authentication and session logs | 12 months | Security / legitimate interests |
| Application and infrastructure error logs | 90 days | Security / legitimate interests |
| Customer operational data (parts, maintenance history, checklists, sign-offs, attachments) | Set by the controlling customer's own retention schedule | Processor instructions (Art. 28 GDPR) |
| Database backups containing any of the above | 35 days rolling, then overwritten | Integrity and availability (Art. 32 GDPR) |
| Data breach incident log | 5 years from incident date | GDPR Art. 33 accountability |
| Subject Access Request log and responses | 3 years from date of response | GDPR Art. 5(2) accountability |
3. Deletion and review
After the applicable retention period, data is securely deleted. Where data has already been written to a backup set, deletion from the live database takes effect immediately and the backup copy ages out within the backup retention window shown above — we do not restore backups to reinstate deleted records.
This Schedule is reviewed annually, or sooner if UK, EU or Cyprus law changes the applicable retention period for any category.
4. Contact
GRAM Systems and Concept Informatics Ltd, joint controllers, share a single point of contact: info@rogerthat.cloud. By phone: Geoff Davison on +44 7830 231672, Matthew Hudson on +44 7918 174779, or our Cyprus office on +357 95984544.