Current · Vol. I · No. 17 · Sunday · 19 April 2026
Revised · 19 April 2026
NEXUS·DSP
Notice · Data retention

What we keep. For how long. Why.

Every piece of data we hold has a retention period and a deletion method. Operational data (Amazon scorecard, concession records, driver performance metrics) is retained for 24 months, then automatically purged. Audit logs last 36 months. Rate-limiting counters last 24 hours. Billing records are retained for 7 years because HMRC says so. This page lists all of it, plus how deletion actually works, plus what happens when you cancel. For questions, contact privacy@nexusdsp.ai.

This policy implements UK GDPR Article 5(1)(e) — the data minimisation principle — by defining how long personal data is kept in a form that permits identification of data subjects. We review this policy annually, or whenever a material change occurs to our processing activities, regulatory environment, or infrastructure.

§ 1 · Purpose

Published so you can verify.

NEXUS · DSP processes operational performance data on behalf of DSP organisations. This policy defines the retention periods for every category of data processed by the platform and the driver application, and the mechanisms by which that data is deleted.

The policy is published so that DSPs, drivers, and the ICO can independently verify our commitments.

§ 2 · The retention schedule

Fifteen categories. One schedule.

The table below sets out the retention period for each category of personal data, the justification for that period, and the method of deletion. Retention periods run from the date of collection or the most recent update of the record, whichever is later, unless otherwise stated.

CategoryRetentionJustificationMethod
Account dataActive subscription + 30 daysContract performance; 30-day reactivation grace periodAutomated purge
Driver performance data (scorecard metrics)24 monthsOperational analysis; covers Amazon review periodAutomated weekly purge
Concession records24 monthsDispute evidence requires historical patternsAutomated weekly purge
Contact, POD, PHR, DWC, False Scan records24 monthsConsistent with performance data retentionAutomated weekly purge
Derived intelligence (scores, clusters, service-update drafts, coaching messages)24 monthsDerived from source data; cascades when source expiresCascade delete
Field reports (camera / voice / GPS from driver app)24 monthsOperational evidenceAutomated purge
Audit logs36 monthsSecurity investigation and complianceAutomated purge
Login history90 daysSecurity audit trailAutomated purge (pg_cron)
Usage analytics12 monthsPlatform improvementAutomated purge
Push notifications and delivery receipts12 monthsDriver communication audit trailAutomated purge
Error events (Sentry)90 daysDebuggingSentry retention setting
Rate-limiting counters (Upstash Redis)24 hoursSliding-window auto-expireRedis TTL
Payment records (Stripe)7 yearsUK HMRC tax requirement (Finance Act 2008)Manual review at year-end
Support tickets24 months from resolutionService quality referenceAutomated purge
Database backups7 daysDisaster recovery (Supabase Pro Point-in-Time Recovery)Natural expiry
§ 3 · How deletion is triggered

Four triggers.

3.1  Automatic expiry

A scheduled weekly process identifies data that has exceeded its retention period and deletes it. The process runs outside peak hours and records each batch to the audit trail.

3.2  Account cancellation

When an organisation cancels, access to the platform is revoked immediately. Associated data is permanently deleted within 30 days of cancellation, except for payment records, which are retained for 7 years to satisfy HMRC requirements. The 30-day window exists to support recovery from accidental cancellation and to allow export of data.

3.3  Right-to-erasure request

Under UK GDPR Article 17, a data subject may request erasure of their identifiable data. Requests are fulfilled within 30 calendar days. Where data has been anonymised and aggregated to the point that the data subject is no longer identifiable, that aggregate data may be retained for statistical purposes.

Drivers whose data has been uploaded to the platform by a DSP should direct erasure requests to the DSP in the first instance. The DSP is the controller of that data.

3.4  Organisation deletion

If an organisation record is deleted — whether by the DSP or by us on account closure — all data associated with that organisation is cascade-deleted across every table. This includes driver records, performance data, concession records, derived intelligence, coaching messages, field reports, and all uploaded files. Audit logs referencing the organisation are anonymised (organisation identifiers removed) at the end of their 36-month retention period.

§ 4 · Exporting data before deletion

Three export routes.

Organisations are encouraged to export their data before cancelling a subscription. The platform provides three export routes:

  • CSV export. Driver performance data, concession records, and compliance metrics are available as CSV files from the dashboard.
  • PDF reports. Intelligence reports, briefing dossiers, and investigation summaries can be generated and downloaded as PDFs.
  • Full data-subject-access export. A complete, machine-readable export of all data held for the organisation is available on request, fulfilling UK GDPR Article 20 (right to data portability). Contact privacy@nexusdsp.ai.

We recommend completing all necessary exports before initiating cancellation. Data cannot be recovered after the 30-day deletion window has closed.

§ 5 · Backup and recovery

Seven days. EU-West.

  • Retention. Database backups are retained for 7 days via Supabase Pro infrastructure.
  • Point-in-Time Recovery. PITR is enabled, allowing restoration to any point within the 7-day backup window for disaster recovery.
  • Location. All backups are encrypted at rest and stored in the EU-West-1 (Republic of Ireland) region, ensuring data remains within UK-GDPR-adequate jurisdictions.
  • Relationship to deletion. Backups do not extend retention periods. When data is deleted from the live database, it expires from backups within the 7-day backup cycle.
§ 6 · Review

Annual review.

This policy is reviewed annually or whenever a material change occurs to the platform's data processing activities, regulatory environment, or infrastructure. Material changes include the introduction of new data categories, changes to sub-processors, or updates to UK data-protection legislation.

Next scheduled review: April 2027.

§ 7 · Contact

Four addresses.

For questions about this policy: privacy@nexusdsp.ai. For our Data Protection Officer: dpo@nexusdsp.ai. For general support: support@nexusdsp.ai. For legal matters: legal@nexusdsp.ai.

VELLOX LTD, company number 17136312, registered in England and Wales. Registered office: Cranberrie Heights, Old Newport Road, Old St Mellons, Cardiff CF3 5FX. ICO registration: ZC115373.