Data Retention
Version 1.0 · effective 01/09/2026 · last updated 21/09/2026
How long Bevendo keeps personal data and business records, including when information is deleted, anonymised or retained for legal and regulatory purposes.
1. Purpose and Scope
This Policy sets out how Bevendo Ltd (“Bevendo”, “we”, “us”, “our”) retains, reviews, anonymises and deletes personal data and business records.
It applies to information processed in connection with the Bevendo platform, customer accounts, orders and payments, delivery, complaints and refunds, marketing, age verification and alcohol-licensing compliance, merchant and delivery relationships, personnel and corporate administration.
Bevendo will keep information only for as long as necessary for the purpose for which it is held and to meet applicable legal, regulatory, tax, accounting, contractual and operational requirements.
This Policy should be read alongside Bevendo’s Privacy Policy, Cookie Policy, Age Verification Policy, Alcohol Licensing Compliance Policy, Refund and Returns Policy and Complaints Policy.
2. Legal Framework
This Policy reflects:
- the UK GDPR storage-limitation principle;
- the Data Protection Act 2018, as amended;
- PECR;
- the Companies Act 2006;
- applicable HMRC requirements;
- the Limitation Act 1980;
- the Licensing Act 2003; and
- relevant employment, immigration and workplace-pension record-keeping requirements.
UK data-protection law does not impose one retention period for all personal data.
Bevendo therefore sets retention periods by reference to:
- the purpose of the record;
- legal requirements;
- regulatory expectations; and
- the period during which claims may arise.
3. Retention Principles
Bevendo will:
- retain only information that remains necessary for a lawful or legitimate business purpose;
- keep no more information than is reasonably required for that purpose;
- apply the longest relevant period where the same record is needed for more than one lawful purpose;
- delete or irreversibly anonymise information when it is no longer required; and
- suspend routine deletion where records are relevant to an actual or reasonably anticipated legal claim, regulatory enquiry, investigation, insurance matter or other legal obligation.
Information that has been irreversibly anonymised so that no individual can be identified is no longer personal data and may be retained for statistical, analytical or business-planning purposes.
4. Retention Schedule
The following are Bevendo’s standard retention periods.
A shorter period may be used where information is no longer necessary, and a longer period may apply where required by law or where Section 6 applies.
Customer Accounts and Profile Information
Customer accounts and profile information are retained while the account is active and normally for up to 2 years after closure where needed for:
- account administration;
- security;
- fraud prevention; or
- customer support.
Order, payment, complaint or other records are retained separately under the relevant period below.
Core Order, Transaction, Payment, Refund and Accounting Records
Core order, transaction, payment, refund and accounting records are generally retained for 6 years from the end of the relevant financial year, or longer where required by HMRC or an ongoing enquiry.
This also satisfies Bevendo’s minimum 2-year retention commitment for relevant order and delivery records under the Alcohol Licensing Compliance Policy.
Bevendo does not need to retain full payment-card numbers.
Payment references and necessary transaction information may be retained.
Delivery-Specific Personal Data
Delivery-specific personal data includes information such as:
- customer telephone numbers used for delivery;
- delivery instructions;
- access or door codes;
- rider notes; and
- other delivery-only information.
This information will be retained only for as long as reasonably necessary for delivery, customer-service, fraud-prevention and alcohol-compliance purposes and will normally be deleted or anonymised within 2 years unless a longer period is required for a complaint, dispute, regulatory enquiry or other lawful purpose.
Age-Verification Declarations and Refused or Unsuccessful Age-Restricted Deliveries
Age-verification declarations and refused or unsuccessful age-restricted delivery records will be retained for a minimum of 2 years from the relevant order, attempted delivery or refusal.
A longer period applies where the record is also relevant to:
- a transaction;
- complaint;
- suspected underage sale;
- regulatory enquiry; or
- dispute.
Bevendo does not routinely retain copies or photographs of identification documents for delivery-stage age verification.
Merchant Licensing and Compliance Records
Merchant licensing and compliance records are retained while the merchant is active and for at least 2 years after the relationship ends or the last relevant transaction, whichever is later.
Routine compliance-audit records will normally be kept for at least 2 years.
Material incidents may be retained for up to 6 years after closure or longer if required.
Complaints, Refund Claims and Customer-Service Records
Routine customer-service communications are normally retained for up to 2 years.
Formal complaints, refund claims and material disputes are normally retained for 6 years after resolution.
Special-category data, such as health information volunteered in a complaint, should be deleted or minimised earlier where it is no longer necessary.
Marketing Records
Active marketing data is kept only while Bevendo has a lawful basis to use it and it remains relevant.
Records evidencing marketing consent or another lawful basis may be retained for up to 6 years where needed to demonstrate compliance.
A minimal suppression record may be kept for as long as necessary to ensure an opt-out or objection continues to be respected.
Waitlists, Availability Alerts and “Notify Me” Requests
These records are retained until the request is:
- fulfilled;
- withdrawn; or
- 12 months after it was made,
whichever occurs first, unless the requested service remains genuinely pending and the individual would reasonably expect the request to stay active.
Ratings, Reviews, Surveys and Feedback
Identifiable ratings are normally retained for 2 years.
Other identifiable survey or feedback data is normally retained for no more than 2 years.
Aggregated or irreversibly anonymised information may be retained longer.
Cookies, Local Storage, Analytics and Advertising Data
These records are retained according to the durations and consent choices set out in Bevendo’s Cookie Policy.
This Policy does not extend those periods.
Security, Fraud-Prevention and Technical Logs
These records are retained only as long as reasonably necessary.
Routine logs are normally retained for no more than 2 years, and preferably for a shorter period where operationally sufficient.
Material security or fraud records may be retained for up to 6 years after closure or longer where required.
Data-Protection Rights Requests and Privacy Complaints
These records are normally retained for 6 years after the request or complaint is finally closed where needed to demonstrate compliance or defend legal claims.
Commercial Contracts and Related Records
Commercial contracts and related records are normally retained for 6 years after the agreement ends or the relevant obligation is discharged.
Agreements executed as deeds may be retained for up to 12 years where relevant.
Personnel Records
General employment and contractor records are normally retained for up to 6 years after the relationship ends where necessary.
Specific periods include:
- PAYE records: at least 3 years after the relevant tax year;
- right-to-work evidence: for the duration of employment plus 2 years;
- workplace-pension records: generally 6 years;
- applicable pension opt-out/leave records: generally 4 years;
- unsuccessful applicant records: normally up to 6 months; or
- up to 12 months where the applicant has agreed to be considered for future roles.
Corporate Governance and Policy Records
Directors’ meeting minutes, directors’ decisions, shareholder resolutions and general-meeting records are retained for at least 10 years.
Superseded compliance policies are normally retained for at least 6 years after replacement, and longer where needed to show which policy applied to a transaction, incident, complaint or investigation.
Statutory registers are retained for the applicable legal period.
5. Deletion, Anonymisation and Backups
When a retention period expires and no exception applies, Bevendo will take reasonable steps to securely delete or irreversibly anonymise the information.
This applies to:
- live systems;
- shared drives;
- local business files; and
- other locations under Bevendo’s control.
Where a third party processes data on Bevendo’s behalf, Bevendo will require appropriate deletion or return arrangements.
Information deleted from live systems may remain temporarily in secure backups until overwritten or expired through the normal backup cycle.
If a backup is restored, applicable deletion rules must be reapplied.
6. Legal Holds and Exceptions
Bevendo may retain information beyond the standard period where reasonably necessary for:
- an actual or anticipated legal claim;
- contractual dispute;
- police or regulatory investigation;
- licensing or underage-sale incident;
- fraud or security investigation;
- insurance matter;
- court order; or
- other binding legal obligation.
Only the information relevant to the matter should be placed on hold.
Once the matter ends, the hold will be reviewed and the information will be deleted, anonymised or returned to the normal retention schedule where appropriate.
7. Third Parties and Individual Rights
Third-party providers, merchant partners, delivery providers and payment providers may have their own lawful retention obligations.
Bevendo’s deletion of its own records does not necessarily require an independent controller to delete information it lawfully retains for its own purposes.
Where Bevendo ceases using a delivery provider, personal data obtained from that provider will be deleted, returned or otherwise handled in accordance with the applicable contractual requirements, subject to any continuing legal, regulatory, fraud-prevention or legal-claims retention requirement.
A request for erasure does not always require immediate deletion of every record.
Bevendo may retain information where it remains necessary to:
- comply with a legal obligation;
- establish or defend legal claims;
- prevent fraud;
- meet regulatory requirements; or
- pursue another lawful purpose.
Where only part of a record remains necessary, unnecessary information should be deleted, redacted or anonymised where reasonably practicable.
Individuals may exercise applicable data-protection rights by contacting info@bevendo.co.uk.
8. Governance and Review
Responsibility for this Policy sits with Bevendo Ltd.
Directors and personnel with access to Bevendo information must follow the applicable retention and deletion requirements.
Bevendo will review this Policy and its retention schedule at least annually and sooner where there is a material change in:
- law;
- ICO guidance;
- Bevendo’s business model;
- the information processed; or
- the systems and providers used.
9. Contact
Bevendo Ltd
128 City Road
London
EC1V 2NX
Email: info@bevendo.co.uk
10. Related Policies and Documents
This Policy should be read together with Bevendo’s:
- Privacy Policy;
- Cookie Policy;
- Age Verification Policy;
- Alcohol Licensing Compliance Policy;
- Refund and Returns Policy;
- Complaints Policy; and
- applicable contractual documents.
Where another Bevendo policy specifies a different retention period for the same record, the longer period applies only where the record remains necessary for the lawful purpose giving rise to that period.
Version History
| Version | Date | Changes |
|---|---|---|
| 1.0 | 1 September 2026 | Initial version |
