Privacy & Retention Policy¶
| Field | Value |
|---|---|
| Status | draft |
| Owner | DIR / COUNSEL |
| Applies to | All processing of personal data by Partile: authentication, presence, matching, messaging, trust & safety, and (planned) analytics/ML. |
| Review cadence | Annual; plus on any new processing purpose, data class, or counsel ratification. |
| Mapped controls | PRIV-01–12 (privacy family), SEC-12 (session lifecycle). |
| Evidence | ../registers/ropa.md, ../registers/retention-schedule.md, ../registers/dsar-log.md; readiness/data-inventory-and-retention.md; infra PR-12 retention spine. |
| Exception handling | Any retention beyond schedule or processing without a basis is a dated decision queued for counsel. |
Purpose¶
State Partile's privacy commitments and retention rules in one place, consistent with the RoPA, the retention schedule, and the UK GDPR posture — built before real users so the rules shape the product, not the reverse.
Principles (UK GDPR-aligned)¶
- Lawfulness, fairness, transparency. Each purpose has a (provisional) lawful
basis in the RoPA; the privacy notice (PRIV-07,
not started, counsel C22) will make processing transparent before private beta. - Purpose limitation. Data collected for one purpose is not silently reused;
analytics/ML reuse is consent-gated (
ai-ml-data-governance-policy.md). - Data minimization. No raw boarding-pass artifacts; only minimal derived fields; tokens hashed; events carry no content (PRIV-06, ML-04).
- Accuracy. LinkedIn-sourced profile fields refresh on login.
- Storage limitation. Data is deleted per the retention schedule by the hard-delete spine — not retained "just in case".
- Integrity & confidentiality. Per the security and crypto policies.
- Accountability. This data room is the demonstrable evidence (Art 5(2)).
Lawful basis (provisional — counsel C1)¶
Contract for auth/matching/messaging; consent for proximity matching, analytics (T1), and ML training (T2); legitimate interest for safety. The RoPA holds the per-activity mapping; durations and bases are [counsel required] before external reliance.
Retention¶
Retention is defined per data class in ../registers/retention-schedule.md and
enforced by the infra PR-12 worker sweeps (sessions, presences, candidates, stale
matched conversations) — implemented (PRIV-03, SEC-12). Durations are
placeholders pending counsel ratification (C4); they are env-configurable so
ratification needs no code change. Blocks and LinkedIn PII persist for the life of
the account; reports archive after resolution.
Data subject rights (PRIV-05, not started)¶
The process (access, rectification, erasure, portability, restriction, objection
to profiling), the 1-month statutory clock, and identity verification are defined
in ../registers/dsar-log.md. Erasure executes the cascade+purge deletion path
and propagates to the pseudonymized event store (not to models — see
ai-ml-data-governance-policy.md and ML-07). Edge cases (tombstoning sent
messages C6; retaining reports against a deleted user C7) are counsel calls.
Special and high-risk processing¶
- Special-category (Art 9): no inference/derivation/storage of protected
attributes (ML-02, C13) — see
ai-ml-data-governance-policy.md. - DPIA (PRIV-09,
not started): required for matching/profiling/proximity (high-risk), scoped with counsel (C21). - Minors (PRIV-12): working assumption 18+; enforcement TBD (C16).
- Re-identification: proximity/travel data is treated as personal data even without a name.
Exceptions¶
Retaining data beyond the schedule, or processing without a clear basis, requires a dated DIR decision and a counsel-queue entry; it is recorded on the relevant PRIV control row and reconciled at counsel ratification.