Data Retention Policy
Last Updated: July 21, 2026
This Data Retention Policy describes how Ulnisrak collects, stores, and deletes personal and operational data across its platform and services. By using our services, you acknowledge the practices described in this document.
1. Purpose and Scope
This policy applies to all data processed by Ulnisrak in connection with the operation of its online platform, including data submitted by users, learners, instructors, and visitors. It covers personal data, account data, transactional records, and technical logs generated through use of our services.
The purpose of this policy is to ensure that data is retained only for as long as necessary to fulfill the purposes for which it was collected, to comply with applicable legal obligations, and to support legitimate business operations.
2. Categories of Data We Retain
2.1 Account and Profile Data
This includes registration details such as name, email address, password credentials, profile preferences, and communication settings provided when creating or maintaining an account on the platform.
2.2 Learning and Engagement Data
This includes course enrollment records, progress tracking, completion certificates, assessment results, and interaction history with platform content.
2.3 Transactional and Billing Data
This includes records of purchases, subscription history, payment references, invoices, and related financial correspondence necessary to support billing operations and dispute resolution.
2.4 Communications Data
This includes messages sent through platform support channels, feedback submissions, survey responses, and any correspondence exchanged between users and our team.
2.5 Technical and Usage Data
This includes IP addresses, browser and device identifiers, session logs, access timestamps, error reports, and behavioral analytics collected automatically during platform use.
2.6 Legal and Compliance Records
This includes records required to demonstrate compliance with applicable obligations, such as consent logs, policy acceptance records, and data subject request documentation.
3. Retention Periods
Data is retained for defined periods based on its category and the purpose it serves. The following table outlines standard retention durations applied across our platform.
| Data Category | Retention Period | Basis for Retention |
|---|---|---|
| Account and profile data | Duration of account plus 2 years after closure | Service delivery and legitimate interest |
| Learning and engagement data | Duration of account plus 3 years after closure | Service records and user entitlement |
| Transactional and billing data | 7 years from transaction date | Financial record-keeping obligations |
| Communications and support data | 3 years from last interaction | Dispute resolution and quality assurance |
| Technical and usage logs | 13 months from collection | Security monitoring and performance analysis |
| Consent and compliance records | 5 years from record creation | Regulatory accountability |
| Anonymised analytics data | Indefinite | Aggregated, non-personal research use |
Retention periods may be extended where data is required in connection with an ongoing legal claim, regulatory inquiry, or dispute resolution process. In such cases, data will be held until the matter is fully resolved.
4. How Retention Periods Are Determined
When establishing retention periods, Ulnisrak considers the following factors:
- The original purpose for which the data was collected
- The nature and sensitivity of the data
- The potential risk of harm from unauthorised use or disclosure
- Legal, regulatory, or contractual obligations that require retention
- The reasonable expectations of users at the time of collection
- Guidance from relevant data protection authorities
5. Data Deletion and Destruction
5.1 Scheduled Deletion
Upon expiry of the applicable retention period, data is either securely deleted or irreversibly anonymised so that it can no longer be associated with an identifiable individual. Deletion processes are applied systematically through automated and manual review cycles.
5.2 Deletion Methods
Digital records are deleted using methods that prevent recovery. Where data is held on physical media, secure destruction procedures are applied. Third-party processors engaged by Ulnisrak are required to apply equivalent standards under contractual obligation.
5.3 Anonymisation as an Alternative
Where deletion is not technically feasible for a subset of data, anonymisation may be applied as an equivalent measure. Anonymised data no longer constitutes personal data and may be retained for statistical or analytical purposes without restriction.
6. Account Closure and Data Removal Requests
6.1 Account Closure
When a user closes their account, active processing of personal data ceases. Data is moved to a restricted state and retained only for the residual periods specified in Section 3. During this period, the data is not used for marketing, profiling, or service delivery.
6.2 Right to Erasure
Users may submit a request for deletion of their personal data at any time. Upon receipt, Ulnisrak will assess the request and delete data that is no longer required for a lawful purpose. Where retention is required by legal obligation or legitimate interest, users will be informed of the reason and the expected retention duration.
Requests for data erasure may be submitted by contacting us at contact@ulnisrak.com.
6.3 Exceptions to Deletion Requests
Ulnisrak may decline to delete certain data where retention is necessary to:
- Comply with a legal obligation
- Establish, exercise, or defend a legal claim
- Protect the vital interests of another person
- Complete a transaction or service already in progress
7. Data Held by Third Parties
Ulnisrak engages third-party service providers to support platform operations, including hosting, payment processing, analytics, and communications. These providers process data on our behalf and are bound by data processing agreements that include retention and deletion requirements consistent with this policy.
Users should be aware that certain third-party providers maintain their own independent retention obligations. Where a third party processes data as a controller in their own right, their applicable policies govern the retention of that data.
8. Backups and Archived Data
Data included in system backups may persist beyond the standard deletion cycle due to technical constraints of backup architecture. Such data is subject to restricted access controls and will be overwritten or deleted in accordance with scheduled backup rotation cycles. Backup data is not used for any operational purpose.
9. Security During Retention
All retained data is protected by appropriate technical and organisational security measures throughout its retention period. These measures include access controls, encryption at rest and in transit, audit logging, and regular security reviews. Access to retained data is limited to personnel with a documented need.
10. Changes to This Policy
Ulnisrak reserves the right to update this Data Retention Policy at any time. When material changes are made, users will be notified through the platform or by email prior to the changes taking effect. Continued use of the platform following notification constitutes acceptance of the revised policy.
The current version of this policy is always available at ulnisrak.com.
11. Contact
Questions, concerns, or requests relating to this policy or the retention of your personal data may be directed to:
Ulnisrak
Svitlohirska St, 74, Kryvyi Rih, Dnipropetrovsk Oblast,
Ukraine, 50000
Email: contact@ulnisrak.com
Phone: +380689494867