Data Retention Policy — Attento

Data Retention Policy

Last updated: May 2025  |  Version 1.0

This is a preliminary data retention policy. A full legally reviewed version will be published before launch.

1. Purpose

This policy explains how long Attento retains different categories of personal data, in compliance with UK GDPR Article 5(1)(e) (storage limitation principle).

2. Retention Schedule

Account Data

Data TypeRetention PeriodReason
Name, email, phoneDuration of account + 30 daysService provision
Password (hashed)Duration of accountAuthentication
Profile photoDuration of account + 30 daysService provision
Home addressDuration of accountJob matching

Guard-Specific Data

Data TypeRetention PeriodReason
SIA licence detailsAccount + 12 monthsCompliance
Identity documentsAccount + 12 monthsLegal obligation
Earnings records7 years from tax year endHMRC requirement

Job Records

Data TypeRetention PeriodReason
Job details7 yearsHMRC / legal disputes
OTP codesDeleted on completionNo ongoing need
Payment records7 yearsHMRC requirement

Location Data

Data TypeRetention PeriodReason
Real-time guard locationActive job only — deleted immediately on completionLive tracking only
Job destination address7 years (stored with job record)Legal disputes
Location historyNot retainedNot collected

Communications

Data TypeRetention PeriodReason
Support emails3 yearsCustomer service
In-app messages90 days after jobDispute resolution
Incident reports7 yearsLegal obligation

3. Deletion Process

When an account is deleted, personal data is erased within 30 days. Financial records are anonymised and retained for 7 years to comply with HMRC requirements. Location and OTP data is deleted immediately.

4. Your Rights

You have the right to request deletion of your data at any time, subject to legal retention obligations. Contact support@attentoservices.com to make a request.

5. Contact

support@attentoservices.com