Skip to content

Privacy & Retention Policy

Field Value
Status draft
Owner DIR / COUNSEL
Applies to All processing of personal data by Partile: authentication, presence, matching, messaging, trust & safety, and (planned) analytics/ML.
Review cadence Annual; plus on any new processing purpose, data class, or counsel ratification.
Mapped controls PRIV-01–12 (privacy family), SEC-12 (session lifecycle).
Evidence ../registers/ropa.md, ../registers/retention-schedule.md, ../registers/dsar-log.md; readiness/data-inventory-and-retention.md; infra PR-12 retention spine.
Exception handling Any retention beyond schedule or processing without a basis is a dated decision queued for counsel.

Purpose

State Partile's privacy commitments and retention rules in one place, consistent with the RoPA, the retention schedule, and the UK GDPR posture — built before real users so the rules shape the product, not the reverse.

Principles (UK GDPR-aligned)

  • Lawfulness, fairness, transparency. Each purpose has a (provisional) lawful basis in the RoPA; the privacy notice (PRIV-07, not started, counsel C22) will make processing transparent before private beta.
  • Purpose limitation. Data collected for one purpose is not silently reused; analytics/ML reuse is consent-gated (ai-ml-data-governance-policy.md).
  • Data minimization. No raw boarding-pass artifacts; only minimal derived fields; tokens hashed; events carry no content (PRIV-06, ML-04).
  • Accuracy. LinkedIn-sourced profile fields refresh on login.
  • Storage limitation. Data is deleted per the retention schedule by the hard-delete spine — not retained "just in case".
  • Integrity & confidentiality. Per the security and crypto policies.
  • Accountability. This data room is the demonstrable evidence (Art 5(2)).

Lawful basis (provisional — counsel C1)

Contract for auth/matching/messaging; consent for proximity matching, analytics (T1), and ML training (T2); legitimate interest for safety. The RoPA holds the per-activity mapping; durations and bases are [counsel required] before external reliance.

Retention

Retention is defined per data class in ../registers/retention-schedule.md and enforced by the infra PR-12 worker sweeps (sessions, presences, candidates, stale matched conversations) — implemented (PRIV-03, SEC-12). Durations are placeholders pending counsel ratification (C4); they are env-configurable so ratification needs no code change. Blocks and LinkedIn PII persist for the life of the account; reports archive after resolution.

Data subject rights (PRIV-05, not started)

The process (access, rectification, erasure, portability, restriction, objection to profiling), the 1-month statutory clock, and identity verification are defined in ../registers/dsar-log.md. Erasure executes the cascade+purge deletion path and propagates to the pseudonymized event store (not to models — see ai-ml-data-governance-policy.md and ML-07). Edge cases (tombstoning sent messages C6; retaining reports against a deleted user C7) are counsel calls.

Special and high-risk processing

  • Special-category (Art 9): no inference/derivation/storage of protected attributes (ML-02, C13) — see ai-ml-data-governance-policy.md.
  • DPIA (PRIV-09, not started): required for matching/profiling/proximity (high-risk), scoped with counsel (C21).
  • Minors (PRIV-12): working assumption 18+; enforcement TBD (C16).
  • Re-identification: proximity/travel data is treated as personal data even without a name.

Exceptions

Retaining data beyond the schedule, or processing without a clear basis, requires a dated DIR decision and a counsel-queue entry; it is recorded on the relevant PRIV control row and reconciled at counsel ratification.