Retention schedule for schools Version 2026-09-30 v1 · Last updated 30 September 2026 Wilgenry Software Limited (trading as Squono), a company registered in England and Wales, company number 17392061, registered office 42a Church Street, Hatfield, England, AL9 5AW. Email hello@squono.com. Published at squono.com/schools/trust/retention How long Squono keeps each kind of school data, what the school can change, and how it is deleted. Backups roll off within 35 days. Retention by type of data ------------------------- Data Default What the school can change How it is deleted Consent slip answers End of the academic year plus one term: kept until 31 December after the academic year the activity fell in. The school can set a number of years after the activity instead (see the note below). Deleted automatically by Squono's background worker Consent slips on hold (for example after an incident) Kept until the hold is removed. The school places and removes holds. The normal rule applies once the hold is removed Emergency contact details given on a slip 7 days after the activity. For a slip with no activity date: 30 days after the slip closes (its reply-by date, or when staff close or cancel it, whichever is first). Nothing. Deleted automatically by Squono's background worker Lesson-leave lists Not stored. Each list is generated when needed from the fixture list. A send log of the date and the number of pupils only is kept for 13 months. Nothing. Send log deleted automatically "Back at school" updates Kept with the fixture. Deleted when the fixture is deleted. With the fixture Photo-consent records (from the school's import) Replaced on each import. Treated as "no" once older than 13 months. Deleted with the pupil. The school re-imports each academic year. Replaced on import; deleted with the pupil Pupils marked as left Removed at the start of the next academic year. Their past appearances stay in the team's history, marked as left. The school marks pupils as left, or deletes them sooner. Deleted automatically by Squono's background worker Parent contact emails from the import Deleted with the pupil. Once a parent accepts an invitation, their account is theirs (see the DPA, section 5). The school can delete contacts at any time. With the pupil Medical information, concussion flags and the record of who viewed medical information (off by default for schools) Deleted 30 days after the pupil leaves the team, or after the team is archived. The feature is off unless the school switches it on. A parent can delete their child's details at any time. Deleted automatically by Squono's background worker In-app notifications 180 days after they were created, whether read or not. Nothing. Deleted automatically by Squono's background worker Event comments (off in the School defaults) 180 days after the event, together with their reactions and the alerts about them. Straight away if the event is deleted. The school can leave event comments off or switch them off at any time (existing comments are kept, hidden, until their date). Staff can hide any comment; authors can delete their own. Deleted automatically by Squono's background worker Copies of emails in Squono's outbox 90 days. Emails that failed to send: 30 days (a Squono administrator can clear them sooner). Copies sent to an account holder are deleted when their account deletion completes. Nothing. Deleted automatically by Squono's background worker Delivery, bounce and complaint notices from the email provider 90 days. Nothing. Deleted automatically by Squono's background worker Bank details typed for an expense claim Stored encrypted. Deleted when the claim is paid or rejected, or 60 days after approval if it is still unpaid (the claimant is asked to enter them again). The last four digits stay with the claim. Nothing. Deleted automatically by Squono's background worker Sign-in sessions 30 days, extended while in use; removed 1 day after they expire. Session records include the IP address and browser used. Nothing. People can sign out of their devices themselves. Deleted automatically by Squono's background worker Audit logs Kept while the school uses Squono. There is no automatic deletion of audit logs yet. Nothing. Deleted at exit Photos, documents, fixtures, results and registers Kept until the school deletes them or leaves Squono. Staff can delete them at any time. Deleted by the school in the app, or at exit Accounts (parents and staff) Deleted or anonymised 30 days after the account holder asks for deletion. Invitations addressed to them then keep only the fact that they were sent (no email address, name or message). Volunteer check records (such as DBS) stay with the school as safeguarding records, shown as "Deleted account", until the school removes them. Not the school's decision – each account belongs to its holder. The school can delete volunteer check records at any time. Deleted automatically by Squono's background worker Database backups Daily backups kept for 14 days on the server, plus the hosting provider's snapshots. All backups roll off within 35 days. Nothing. Backups expire and are removed Everything, when the school leaves Export, then deletion within 30 days of termination. The school decides when to leave. A manual process run by Squono, with written confirmation on request Note: Educational-visit records: some schools keep records of educational visits for a set number of years, and may treat away-fixture consent slips as visit records. Department for Education record-keeping guidance may set a period for these (a figure of 10 years has been reported), but Squono has not been able to confirm it. The school must check the period against its own retention schedule before setting it. After deletion -------------- - Deleted data leaves the live service straight away, and leaves every backup within 35 days. - If Squono ever has to restore a backup, its written restore procedure re-applies deletions made since that backup before the service reopens.