Dealorigin
Unit 4/1 Angus Ave, South Nowra NSW 2541, Australia

Data Retention Policy

Last Updated: 8 June 2026


This Data Retention Policy describes how Dealorigin collects, stores, and deletes data generated through the use of our online platform. It applies to all users, participants, and account holders who access our services.

1. Purpose

We retain data only for as long as necessary to fulfil the purposes for which it was collected, to maintain service quality, to meet legitimate business needs, and to comply with applicable legal obligations. When data is no longer required, it is securely deleted or anonymised.

2. Scope

This policy applies to all personal and operational data processed by Dealorigin, including data submitted by users directly, data generated through platform activity, and data received from third-party integrations connected to our services.

3. Categories of Data and Retention Periods

The table below outlines the primary categories of data we process and the standard retention periods applied to each.

Data Category Examples Retention Period Basis for Retention
Account Information Name, email address, password hash, account preferences Duration of account plus 90 days after deletion request Service provision, user authentication
Workshop and Course Data Enrolment records, progress, completed assignments, certificates 5 years from course completion Educational records, accreditation support
Payment and Billing Records Transaction identifiers, invoice history, payment status 7 years from transaction date Financial record-keeping obligations
Usage and Activity Logs Login timestamps, feature interactions, session duration 12 months from event date Security monitoring, service improvement
Support and Communications Help requests, email correspondence, chat transcripts 3 years from last interaction Quality assurance, dispute resolution
API Usage Data API call logs, endpoint access records, error reports 12 months from event date Debugging, performance optimisation
Marketing Preferences Subscription status, communication opt-ins Until opt-out, plus 30 days Consent management
Anonymised Analytics Aggregated usage statistics, cohort data Indefinite (no personal identifiers) Platform development, reporting

4. Retention Principles

4.1 Minimum Necessary Retention

We do not retain data beyond the period required for its stated purpose. Retention periods are reviewed periodically and adjusted where the original purpose no longer applies.

4.2 Legal and Contractual Obligations

Where a legal obligation, regulatory requirement, or contractual commitment requires us to retain data for a defined period, that obligation takes precedence over shorter internal retention periods. Data subject to such obligations will not be deleted until the obligation is satisfied.

4.3 Legitimate Interests

In limited circumstances, we may retain data beyond standard periods where we have a documented legitimate interest, such as the prevention of fraud, resolution of ongoing disputes, or enforcement of our terms of service. Such retention is reviewed on a case-by-case basis.

4.4 Anonymisation as an Alternative to Deletion

Where full deletion is not operationally feasible within the standard period, data may be anonymised so that it can no longer be attributed to any identifiable individual. Anonymised data is not subject to this policy's deletion timelines.

5. Deletion and Disposal

When a retention period expires, data is removed through one of the following methods depending on its format and storage location:

6. User-Initiated Deletion

Users may request deletion of their personal data at any time by contacting us at help@dealorigin.website. Upon receiving a verified deletion request, we will:

Deletion requests do not apply to data that has already been anonymised, as such data cannot be attributed to the requesting individual.

7. Account Closure and Inactivity

7.1 User-Initiated Account Closure

When a user closes their account, personal account data is marked for deletion and removed within 90 days, subject to any applicable retention obligations described in Section 4.2.

7.2 Inactive Accounts

Accounts showing no activity for a continuous period of 36 months are considered inactive. We will attempt to notify the account holder at the email address on file prior to any action. If no response is received, the account may be closed and data processed in accordance with this policy.

8. Third-Party Data Processors

We engage third-party service providers to assist in delivering our platform. These providers are required, through contractual data processing agreements, to apply retention and deletion standards consistent with this policy. We do not permit third-party processors to retain personal data beyond the periods authorised by Dealorigin.

9. Data Security During Retention

All data retained under this policy is protected by appropriate technical and organisational security measures, including encryption at rest and in transit, access controls limited to authorised personnel, and regular security assessments. The level of protection applied is proportionate to the sensitivity of the data.

10. Review of This Policy

This policy is reviewed at least annually or whenever significant changes occur to our data processing activities, applicable legal requirements, or platform functionality. The date at the top of this document reflects the most recent review.

11. Contact

If you have questions about this Data Retention Policy or wish to exercise any rights in relation to your personal data, please contact us using the details below:

Dealorigin
Unit 4/1 Angus Ave, South Nowra NSW 2541, Australia
Email: help@dealorigin.website
Phone: +61 407 244 692