How long we keep data
This page gives the full detail for section 9 of our Privacy Policy. It is provided for transparency and is not legal advice.
We keep personal data only as long as needed for the purpose it was collected, then delete or anonymise it. You can ask us to delete your account and associated data at any time.
Security and accountability log. The restricted security and accountability log described in section 2 is kept for up to 270 days and then deleted automatically, so that we can investigate incidents and defend legal claims within a realistic window. The more sensitive sign-in location records (IP address and approximate city) are kept for a shorter fixed period of 180 days and then deleted automatically. Because these records include a full IP address, we keep a written legitimate-interests assessment explaining why this period is necessary and proportionate; it is available on request.
Event attendance records (check in) are stored with the application they belong to and are deleted when that application or your account is deleted.
| What we keep | Why | How long | How it is deleted |
|---|---|---|---|
| Account details (name, email, password hash, date of birth, country of residence, citizenships) | To run your account and decide the age rules that apply to you | While your account exists | Deleted or anonymised when you or an administrator delete the account; accepted conference records are kept only as an anonymous entry |
| Parent/guardian contact (name, relationship, email, phone), stored encrypted | To obtain and record parental consent for a minor and for urgent contact | While the account that needs consent exists | Removed together with the account when it is deleted |
| Applications and answers (committee/country preferences, form answers) | To review and process your application | While the application exists | Deleted with the application or the account; unconsented minor drafts are removed automatically (see below) |
| Conference verification results (optional check) | To help reviewers confirm listed conferences | Stored with the application | Deleted when the application is deleted; holds no applicant personal data |
| Security and accountability log | To investigate incidents and defend legal claims | Up to 270 days | Deleted automatically by the nightly job |
| Sign-in location records (IP address and approximate city) | Security and abuse prevention | 180 days (fixed) | Deleted automatically by the nightly job |
| Consent receipts (record that consent was given/withdrawn) | To prove lawful basis under the GDPR | With your account; after an account is deleted, any left-over receipt is kept up to 90 days | Deleted automatically by the nightly job |
| Sent-email log (subject, body and delivery status of service emails) | To confirm what was sent and troubleshoot delivery | Until an administrator clears the log | Cleared manually by an administrator |
| Live-session recordings | Recording is disabled; where a recording ever exists it is short-lived | 96 hours after the session closes (unless placed under legal hold) | Deleted automatically by the nightly job |
| Accounts pending deletion after a guardian declines platform use, or with no guardian response | To honour a guardian's decision and clean up unconfirmed minor accounts | 72 hours after a platform decline; 21 days where no guardian consent arrives | Account is anonymised/deleted automatically by the nightly job |
| Sign-up block list (an email blocked after a guardian declines platform use) | To stop a declined child's account being recreated | Until an administrator lifts the block | Removed manually by an administrator |
Nordic Diplomacy Initiative. Guided by the North.