Skip to content
E-DOB

Legal

Data Retention Policy

Last updated: 17 June 2026. This document is maintained centrally by Ffon Solutions Limited.

Data Retention Policy

Effective date: 15 June 2026

This policy explains how long different categories of data are retained within E-Dob. Retention periods balance the need to provide the service, meet legal obligations, and avoid keeping data longer than necessary.

Account data

Account data is retained while a subscription is active, and for 30 days after cancellation to allow for reactivation. After that period it is deleted, unless we are required to retain it for longer to comply with a legal obligation.

Incident report data

Incident reports are retained according to the customer's own regulatory requirements. E-Dob does not impose a maximum retention period; instead we recommend that customers configure retention in line with their sector's requirements.

Area for future development: the platform does not currently provide a configurable retention setting for incident data. Until such configuration is available, incident report data is currently retained indefinitely unless deletion is requested. We have flagged automated, customer-configurable incident retention as a planned enhancement.

Audit logs and security events

Audit logs and security event records are retained for 12 months for security monitoring and accountability purposes.

Login attempt records

Records of login attempts (used for brute-force protection and account lockout) are retained for 90 days.

Backups

Database backups are retained in line with Laravel Cloud's managed database backup retention. See the Laravel Cloud documentation for details of their backup schedule and retention.

Requesting deletion

To request deletion of personal data, or to ask a question about retention, contact our Data Protection Officer at dpo@e-dob.uk. Where we process data on behalf of a customer, we will refer or assist with the request in accordance with our agreement with that customer.

Medical Reports

Retention period: Medical reports contain special category health data (UK GDPR Article 9). Retention should be determined by your organisation's regulatory requirements:

  • For workplace incidents: minimum 3 years recommended (RIDDOR)
  • For healthcare settings: follow CQC/NHS records management guidance
  • Default (if no specific requirement): 7 years

Deletion: Medical reports are deleted on account closure per the account data retention period above. If specific medical records need to be retained beyond account closure, export them before cancelling your subscription.

Access: Medical report data is accessible only to authenticated users within your organisation.

Central copy: view on the E-DOB Trust Centre →

We use cookies

We use essential cookies to make E-DOB work, and optional analytics cookies to help us understand how the site is used. You can accept everything, reject non-essential cookies, or manage your preferences.

Read our Cookie Policy →