Legal
Data Retention Policy
Last updated: 17 June 2026. This document is maintained centrally by Ffon Solutions Limited.
Data Retention Policy
Effective date: 15 June 2026
This policy explains how long different categories of data are retained within E-Dob. Retention periods balance the need to provide the service, meet legal obligations, and avoid keeping data longer than necessary.
Account data
Account data is retained while a subscription is active, and for 30 days after cancellation to allow for reactivation. After that period it is deleted, unless we are required to retain it for longer to comply with a legal obligation.
Incident report data
Incident reports are retained according to the customer's own regulatory requirements. E-Dob does not impose a maximum retention period; instead we recommend that customers configure retention in line with their sector's requirements.
Area for future development: the platform does not currently provide a configurable retention setting for incident data. Until such configuration is available, incident report data is currently retained indefinitely unless deletion is requested. We have flagged automated, customer-configurable incident retention as a planned enhancement.
Audit logs and security events
Audit logs and security event records are retained for 12 months for security monitoring and accountability purposes.
Login attempt records
Records of login attempts (used for brute-force protection and account lockout) are retained for 90 days.
Backups
Database backups are retained in line with Laravel Cloud's managed database backup retention. See the Laravel Cloud documentation for details of their backup schedule and retention.
Requesting deletion
To request deletion of personal data, or to ask a question about retention, contact our Data Protection Officer at dpo@e-dob.uk. Where we process data on behalf of a customer, we will refer or assist with the request in accordance with our agreement with that customer.
Medical Reports
Retention period: Medical reports contain special category health data (UK GDPR Article 9). Retention should be determined by your organisation's regulatory requirements:
- For workplace incidents: minimum 3 years recommended (RIDDOR)
- For healthcare settings: follow CQC/NHS records management guidance
- Default (if no specific requirement): 7 years
Deletion: Medical reports are deleted on account closure per the account data retention period above. If specific medical records need to be retained beyond account closure, export them before cancelling your subscription.
Access: Medical report data is accessible only to authenticated users within your organisation.
Central copy: view on the E-DOB Trust Centre →