Data Retention Policy
Effective Date: 31 July 2026
1. Purpose
This Data Retention Policy sets out The Payments Club's approach to retaining and disposing of personal information. It ensures that we keep personal information only for as long as necessary for the purposes for which it was collected, in compliance with POPIA and other applicable laws.
2. Retention Periods
| Information Type | Retention Period | Justification |
|---|---|---|
| Member profile and account records | Membership duration + 5 years | For membership administration, rights enforcement, and compliance |
| Consent and preference records | Membership duration + 5 years | Proof of consent as required by POPIA |
| Event RSVP, ticket and attendance records | Membership duration + 5 years | Event history and membership tracking |
| Guest (Bring a Friend) records | 90 days after the event | Unless the guest becomes a member |
| Marketing opt-out records | Indefinite (as suppression list) | To ensure we never market to opted-out individuals |
| Audit and security logs | Minimum 3 years | Security monitoring and legal compliance |
| Financial records | 7 years | Statutory tax and accounting requirements |
| Event photographs and recordings | 2 years (unless for promotional use) | Event documentation and marketing |
3. Secure Disposal
When personal information is no longer required, it will be securely disposed of using methods that prevent reconstruction or unauthorized access:
- Electronic records: Permanent deletion from systems and backups
- Paper records: Secure shredding or incineration
- Hardware: Secure wiping or physical destruction
4. Retention Exceptions
We may retain personal information for longer than the stated periods where:
- Required by law or court order
- Necessary for legal proceedings
- Required for legitimate business purposes (with justification)
- You have consented to longer retention
5. Guest Data Cleanup
Guest (Bring a Friend) data is automatically cleaned up 90 days after the event, unless the guest becomes a full member. The automated cleanup process runs daily and permanently deletes expired guest records.
6. Responsibility
- Information Officer: Overall responsibility for policy implementation
- System Administrators: Technical implementation of retention and deletion
- All Staff: Compliance with retention requirements
7. Policy Review
This policy will be reviewed annually and on any material change to processing or systems. The latest version is always published on our website.
Last Updated: 31 July 2026