Data Retention Policy
Last Updated: December 30, 2025
This Data Retention Policy describes how kohyxyu ("we", "us", or "our") collects, retains, and disposes of personal data and other information in connection with the services provided through kohyxyu.com. This policy applies to all users, participants, and customers who access or use our platform.
We are committed to retaining data only for as long as necessary to fulfil the purposes for which it was collected, to comply with applicable legal and regulatory obligations, and to support legitimate business operations. When data is no longer required, we dispose of it securely and in a timely manner.
1. Scope and Application
This policy applies to all personal data and non-personal data processed by kohyxyu, including data collected through our website, webinar platform, registration forms, communication tools, and any related services. It covers data held in electronic systems, cloud storage, databases, and any other formats used in our operations.
All staff, contractors, and third-party processors who handle data on behalf of kohyxyu are expected to adhere to the principles set out in this policy.
2. Principles Governing Data Retention
We apply the following core principles when determining how long data is retained:
Purpose Limitation: Data is kept only for the specific purpose for which it was originally collected. Once that purpose has been fulfilled and no other legitimate basis for retention exists, the data is deleted or anonymised.
Minimisation: We do not retain more data than is necessary. Where data can be aggregated or anonymised to serve an ongoing need, we prefer that approach over retaining identifiable personal data.
Accuracy: Data held for extended periods is subject to periodic review to ensure it remains accurate and relevant.
Security: Data retained in any form is protected by appropriate technical and organisational measures throughout its retention period.
Accountability: Retention decisions are documented and can be explained in response to enquiries from users or regulatory bodies.
3. Categories of Data and Retention Periods
The table below outlines the main categories of data we process and the standard retention periods applied to each.
| Data Category | Examples | Retention Period | Basis for Retention |
|---|---|---|---|
| Account and registration data | Name, email address, account credentials, profile information | Duration of account plus 2 years after closure | Contract performance, legitimate interest |
| Webinar participation data | Attendance records, session logs, interaction history | 3 years from the date of the event | Legitimate interest, service improvement |
| Payment and billing records | Transaction history, invoices, payment confirmations | 7 years from the date of transaction | Legal and financial compliance obligations |
| Communication records | Support tickets, emails, chat messages with our team | 3 years from the date of last communication | Legitimate interest, dispute resolution |
| Marketing and consent data | Email preferences, opt-in records, unsubscribe requests | 5 years from the date of consent or last interaction | Legal compliance, proof of consent |
| Technical and usage logs | IP addresses, browser data, session identifiers, access logs | 12 months from collection | Security, fraud prevention, service integrity |
| Survey and feedback data | Responses to post-webinar surveys, ratings, written comments | 2 years from collection | Service improvement, legitimate interest |
| Cookies and tracking data | Session cookies, analytics identifiers | As specified in our Cookie Policy, typically up to 13 months | Consent, legitimate interest |
| Anonymised and aggregated data | Statistical reports, usage summaries with no identifiers | Indefinite | No personal data present; used for analytics and reporting |
These periods represent standard defaults. In specific circumstances, data may be retained for longer periods where required by law, where a legal claim is anticipated or ongoing, or where explicit consent has been obtained for extended retention.
4. Extended Retention Circumstances
4.1 Legal and Regulatory Requirements
Certain categories of data must be retained for periods defined by applicable law or regulation. Where such requirements exist, we retain data for the full period mandated regardless of our standard schedule. Examples include financial records, tax documentation, and records related to contractual obligations.
4.2 Ongoing or Anticipated Legal Proceedings
Where we become aware of a dispute, complaint, investigation, or legal claim that involves data we would otherwise delete, we place a hold on that data until the matter is fully resolved. Once resolved, the data is deleted in accordance with the standard schedule or immediately if no further basis for retention exists.
4.3 User-Requested Retention
In limited cases, a user may request that we retain certain records for their own reference or documentation purposes. We accommodate such requests where technically feasible and where doing so does not conflict with our legal obligations or the rights of other individuals.
5. Data Deletion and Anonymisation
When data reaches the end of its retention period, we take one of the following actions:
Secure Deletion: Electronic data is deleted using methods that prevent recovery. Physical records, where applicable, are destroyed in a manner that renders them unreadable and irrecoverable.
Anonymisation: Where the underlying information retains value for statistical or analytical purposes, we may anonymise it rather than delete it. Anonymised data no longer constitutes personal data and is not subject to further retention limits.
Deletion and anonymisation processes are carried out on a scheduled basis. Where automated deletion is not in place, manual reviews are conducted at regular intervals to identify data that has exceeded its retention period.
6. Third-Party Data Processors
We engage third-party service providers to assist in delivering our platform and services. These providers may process personal data on our behalf. We require all such providers to maintain data retention and deletion practices consistent with this policy and with applicable legal standards. Data shared with third-party processors is subject to retention limits no longer than those applied to the same data in our own systems.
When a third-party engagement ends, we require the provider to return or securely delete all personal data held on our behalf within a reasonable timeframe.
7. User Rights in Relation to Retained Data
Users have the right to request information about what personal data we hold about them and for how long. Users may also request the deletion of their personal data where no legal or contractual basis for continued retention exists. We respond to such requests within the timeframes set out in our Privacy Policy.
Requests related to data retention can be submitted by contacting us at the details provided in Section 10 of this policy. We will confirm the action taken and, where deletion is not possible due to a legal obligation, explain the reason for continued retention.
8. Data Retention Reviews
This policy and the retention schedules within it are reviewed at least once per calendar year, or sooner where there is a material change in our services, legal obligations, or data processing activities. Reviews are conducted to ensure that retention periods remain proportionate, accurate, and compliant with current requirements.
Where a review results in changes to retention periods, affected data is reassessed and handled in accordance with the updated schedule.
9. Responsibility and Oversight
Responsibility for implementing and monitoring this policy rests with the designated data management function within kohyxyu. All staff involved in data handling are made aware of this policy and their obligations under it. Breaches of this policy are treated seriously and may result in disciplinary action or other consequences as appropriate.
10. Contact Us
If you have questions about this Data Retention Policy, wish to exercise your rights, or need to report a concern related to data handling, please contact us using the details below:
kohyxyu
Unit 9 Millfield Industrial Estate, Commons Road, Cork, T23 KX71, Ireland
Phone: +353 949 365 987
Email: [email protected]
Website: www.kohyxyu.com
We aim to respond to all enquiries within a reasonable timeframe and to handle all requests with care and transparency.