Records Management & Retention Policy
| Policy owner | SuperSubBetting (sole trader) |
| Effective date | 1 January 2025 |
| Version | 1.0 |
| Review frequency | Annually |
1. Purpose
This policy establishes minimum retention periods for business records held by SuperSubBetting and sets out how records are stored and securely disposed of. It supports compliance with UK GDPR data minimisation requirements and assists in meeting statutory obligations relating to tax, contracts and financial records.
2. Scope
All records created or received in the course of operating the SuperSubBetting business, including financial records, commercial agreements, correspondence, analytics data and personal-data records.
3. Responsibilities
The sole trader is responsible for implementing and maintaining this policy. There are no employees or separate records-management function.
4. Retention schedule
| Record type | Minimum retention | Legal basis / reason |
|---|---|---|
| Accounting records, invoices, tax returns | 6 years | Companies Act 2006 / HMRC self-assessment requirement for sole traders |
| Commercial agreements and payment statements | 6 years from end of agreement | Limitation Act 1980 (contract claims) |
| Limited outbound-link event records | As required by contract, minimum 2 years | Contractual dispute evidence |
| Contact-form submissions containing personal data | Delete when purpose fulfilled, maximum 2 years | UK GDPR data minimisation (Article 5(1)(e)) |
| Website analytics data (aggregate / anonymised) | Up to 26 months (Google Analytics default); review annually | Best practice; UK GDPR storage limitation |
| Data breach register | 3 years minimum | ICO guidance / UK GDPR Article 33(5) |
| Subject-rights request log | 3 years | Best practice for demonstrating compliance |
| Correspondence with operators and commercial contacts | 6 years from end of commercial relationship | Limitation Act 1980 |
| Compliance policy documents and review records | Retain current version plus two prior versions | Due-diligence evidence / best practice |
5. Practical controls
- Storage: Business records are stored on password-protected devices and/or cloud services with access controls. See Information Security Policy.
- Backups: Key financial and contractual records are backed up to a secondary location (e.g. encrypted cloud storage).
- Disposal: Digital records are securely deleted using file-deletion tools that overwrite data. Physical records (if any) are shredded.
- Annual review: Records are reviewed annually against the retention schedule and disposed of when retention periods expire.
6. Not applicable
SuperSubBetting does not hold customer gambling records, payment card data or betting account balances. The record-keeping requirements of the Gambling Act 2005 applicable to licensed operators do not apply to this business.
7. Record-keeping for this policy
This policy document is itself retained in accordance with the compliance policy record row above. Dated review records are kept to demonstrate that the schedule has been applied.
8. Escalation
Any dispute or query from a commercial counterparty regarding record retention is escalated to the sole trader for direct response within five working days.