Overview
Aevum News recognizes that your data is entrusted to us, and we treat that responsibility with the utmost seriousness. This Data Retention Policy explains how long we retain different categories of your personal information and the criteria we use to determine retention periods.
Our approach is guided by the principles of data minimization and storage limitation — we only keep your data as long as necessary for the purposes for which it was collected, and we securely delete it once that purpose has been fulfilled.
No personal data is retained indefinitely without a valid legal or business justification. All retention periods are reviewed annually by our Data Protection Officer to ensure ongoing compliance and necessity.
What Data We Collect
We collect and process the following categories of personal data, each with specific retention schedules:
- Account Data: Name, email address, password hash, profile preferences, subscription tier, and account creation date.
- Usage Data: Pages visited, articles read, time spent on site, click patterns, search queries, and feature interactions.
- Communication Data: Email newsletter interactions, customer support tickets, comment submissions, and survey responses.
- Payment Data: Billing address, payment method tokens (never raw card numbers), transaction history, and invoice records.
- Device & Technical Data: IP address, browser type, operating system, device identifiers, cookies, and analytics tags.
- Legal & Compliance Data: Consent records, data processing agreements, audit logs, and legal correspondence.
Retention Periods
Each category of data has a defined retention period. Below is a summary of our core retention schedules:
Account Data
Retained for the duration of your account + 30 days after deletion request, then permanently erased from active systems.
Usage & Analytics Data
Retained in aggregated, anonymized form for 24 months. Personally identifiable usage data is deleted after 12 months of inactivity.
Payment & Billing Records
Retained for 7 years from the date of last transaction, in compliance with tax and accounting regulations.
Communication Records
Customer support tickets: 2 years after resolution. Newsletter data: Until unsubscribe or 2 years of inactivity.
Device & IP Data
Retained for 6 months for security and fraud prevention, then anonymized or deleted.
Legal & Consent Records
Retained for 10 years or as required by applicable law, whichever is longer.
Complete Data Retention Schedule
The table below provides a comprehensive overview of every data category, its purpose, retention period, and legal basis.
| Data Category | Purpose | Retention Period | Duration |
|---|---|---|---|
| Account Credentials | Authentication & access management | Until account deletion + 30 days | Variable |
| Profile & Preferences | Personalization & user experience | Until account deletion + 30 days | Variable |
| Email Address | Communication, account linkage | Until account deletion + 30 days | Variable |
| Reading History | Content recommendations & analytics | 12 months of inactivity | 12 months |
| Search Queries | Search improvement & analytics | 6 months, then anonymized | 6 months |
| Click & Behavior Data | Product optimization & A/B testing | 24 months, then anonymized | 24 months |
| Newsletter Interactions | Email marketing & engagement | Until unsubscribe or 24 months | 24 months |
| Support Tickets | Customer service & resolution | 24 months after resolution | 24 months |
| Payment Transactions | Billing, refunds, tax compliance | 7 years from last transaction | 7 years |
| Invoices & Receipts | Financial records & legal compliance | 7 years from issue date | 7 years |
| IP Addresses | Security, fraud prevention, analytics | 6 months, then anonymized | 6 months |
| Cookie & Tracking Data | Site functionality & analytics | Up to 13 months per cookie | 13 months |
| Device Identifiers | Security & session management | 6 months | 6 months |
| Consent Records | Legal compliance & audit trail | 10 years | 10 years |
| Legal Correspondence | Legal proceedings & compliance | As required by law | Indefinite |
| Comments & User Content | Community engagement & moderation | Until deletion or account removal | Variable |
Retention periods may be extended where data is subject to a legal hold, ongoing investigation, or legitimate business dispute. In such cases, data will not be deleted until the legal obligation has been satisfied.
Storage & Security
All personal data collected by Aevum News is stored on secure, encrypted servers located in compliance with international data protection standards. Our infrastructure follows industry-leading security practices:
- Encryption at Rest: All databases are encrypted using AES-256 encryption.
- Encryption in Transit: TLS 1.3 is enforced for all data communications.
- Access Controls: Role-based access with multi-factor authentication for all administrative systems.
- Audit Logging: All access to personal data is logged and monitored for anomalies.
- Regular Penetration Testing: Conducted quarterly by independent third-party security firms.
- Server Locations: Primary data centers in Frankfurt, Germany (EU) and Oregon, USA (US), with geo-replication for disaster recovery.
Aevum News maintains SOC 2 Type II certification and undergoes annual GDPR compliance audits. Our security posture is independently verified and documented.
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data. You can exercise any of these rights at any time by contacting our Data Protection team.
Right to Access
Request a copy of all personal data we hold about you, in a portable and machine-readable format.
Right to Rectification
Request correction of any inaccurate or incomplete personal data we hold.
Right to Erasure
Request deletion of your personal data, subject to legal retention obligations.
Right to Restriction
Request that we limit the processing of your data under certain conditions.
Right to Portability
Receive your data in a structured, commonly used format and transfer it to another controller.
Right to Object
Object to processing based on legitimate interests or direct marketing at any time.
Right Against Automated Decisions
Not be subject to decisions based solely on automated processing, including profiling.
Right to Withdraw Consent
Withdraw previously given consent at any time, without affecting the lawfulness of prior processing.
We will respond to all data subject requests within 30 calendar days, or within 45 days for complex requests. You will receive confirmation of receipt within 5 business days.
Data Deletion Process
When data reaches the end of its retention period, or when you exercise your right to erasure, the following process ensures complete and verifiable deletion:
Step 1: Identification
Our automated retention management system identifies data that has exceeded its retention period or has been flagged for deletion.
Step 2: Legal Hold Check
Before deletion, the system checks whether any legal holds, litigation, or regulatory obligations require the data to be preserved.
Step 3: Anonymization or Deletion
Data that no longer requires personal identification is anonymized. Where full deletion is required, data is permanently erased using certified destruction methods.
Step 4: Backup Purging
Deleted data is removed from all backup systems within 30 days. Backup tapes and archived media are overwritten or physically destroyed.
Step 5: Audit Trail
A deletion certificate is generated and logged, documenting what data was deleted, when, by whom, and under which authority.
Please note that due to automated backup systems, complete erasure of data from all copies (including backups) may take up to 30 additional days after the primary deletion. This is consistent with GDPR Article 17(3)(b).
Third-Party Processors
Aevum News works with carefully vetted third-party service providers who process data on our behalf. Each processor is bound by strict data processing agreements (DPAs) and must adhere to retention periods no longer than what is specified in this policy.
Key third-party processors include:
- Cloud Infrastructure: AWS (Amazon Web Services) — data hosted in EU and US regions.
- Payment Processing: Stripe — payment tokens and transaction data only.
- Email Delivery: SendGrid — email addresses and engagement metrics.
- Analytics: Google Analytics (with IP anonymization) — aggregated usage data.
- Customer Support: Intercom — support ticket content and communication history.
- CDN: Cloudflare — cache logs and device data (short-term only).
All third-party transfers outside the EU are protected by Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework.
Legal Basis for Retention
Our data retention practices are grounded in the following legal bases under GDPR Article 6 and applicable national legislation:
- Consent (Article 6(1)(a)): Data you explicitly consent to, such as newsletter subscriptions and marketing communications.
- Contractual Necessity (Article 6(1)(b)): Data required to fulfill our subscription agreement with you, including account and payment information.
- Legal Obligation (Article 6(1)(c)): Data retained to comply with tax, financial, and regulatory requirements (e.g., payment records for 7 years).
- Legitimate Interests (Article 6(1)(f)): Data retained for fraud prevention, security, service improvement, and analytics — balanced against your rights and freedoms.
For users in California, our practices also comply with the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), which provide similar rights to access, delete, and opt-out of the sale of personal information.
Frequently Asked Questions
Contact Our Data Protection Team
If you have any questions about this Data Retention Policy, wish to exercise your data rights, or have concerns about how we handle your personal data, please don't hesitate to reach out.
Get in Touch
Our Data Protection Officer and compliance team are available to assist you.
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. For EU users, this is your national supervisory authority. For US users, you may contact the California Privacy Protection Agency.