Skip to main content
Last updated: [Month DD, YYYY] Squid Academy retains personal data only for as long as it is needed for the purposes described in our Privacy Policy and to meet legal, contractual, and operational requirements. This page summarizes the main retention periods and deletion procedures referenced in Section 12 of our Privacy Policy and Section 8 of our Data Processing Addendum.

1. Key Principles

  • Purpose limitation – We keep personal data only for as long as necessary for the specific purpose it was collected.
  • Legal obligations – Some data must be retained for statutory reasons (e.g., tax, accounting, or child protection laws).
  • Customer instructions – For organization-provisioned accounts, we follow the controller’s instructions for retention and deletion under our DPA.
  • Secure deletion – When data is no longer needed, it is securely deleted or anonymized.

2. Standard Retention Periods

Data CategoryExamplesStandard RetentionDeletion / Anonymization Method
Account Data (Public Users)Name, email, profile infoKept until account deletion request or 24 months of inactivitySecure database deletion; backups overwritten within 35 days
Account Data (Org-Provisioned)Name, username, org affiliationRetained until controller instructs deletion or contract endsDeleted per controller request; backups overwritten within 35 days
Course & Activity DataAssignments, grades, attendanceRetained while account is active; deleted within 12 months after deletionSecure deletion from LMS & storage systems
Tournament DataPlayer IDs, match stats, leaderboardsKept for active season + 12 monthsPurged from tournament platform; anonymized for analytics
Payment & Billing DataBilling name, address, transaction history7 years (tax & accounting compliance)Secure deletion from billing system
Support & Communication RecordsEmails, chat transcripts, support tickets24 months after case closureSecure deletion from ticketing platform
Security LogsLogin history, IP addresses, device info12 months (security & fraud prevention)Automatic purge from log management system
Marketing DataNewsletter sign-ups, marketing preferencesUntil withdrawal of consent or inactivity for 24 monthsRemoved from CRM/email platform

3. Backup Data

  • Backups are retained for 35 days unless otherwise required by law or contract.
  • Deleted data may remain in backups until the backup cycle expires. Backups are encrypted and access is restricted.

4. Deletion Process

  1. Trigger – Retention period expires or a valid deletion request is received.
  2. Verification – Confirm identity of requester (public users) or confirm request with controller (org-provisioned).
  3. Deletion – Remove data from active systems.
  4. Backup purge – Data naturally removed as backup cycles expire.
  5. Confirmation – For DSR requests, confirmation sent to requester or controller.

5. Exceptions

Some data may be retained beyond standard periods:
  • To comply with legal obligations.
  • To resolve disputes or enforce agreements.
  • For ongoing investigations into misuse or violations.

6. Contact

For questions about data retention or deletion: email privacy@squid.gg or Submit a Privacy Request