Compliance & Transparency

Data Retention Policy

Last Updated: September 2026

How Evergreen retains and securely disposes of personal and business information.

1. Purpose and approach

Evergreen retains personal information only for as long as necessary for the stated staffing, compliance, payment, security or legal purpose. We review retention and restrict access during any retained period; an end of employment, assignment or account does not automatically require immediate deletion where a lawful purpose remains.

2. Staff-to-practice disclosure records

For each assessment or booking, we may retain a record of the information disclosed to the relevant practice, the recipient, purpose, date, assignment and any practice confirmation or access log. These records support accountability, booking management, security, complaints and legal claims. They must not be used to create a general staff dossier or enable continuing access to underlying documents.

3. Deletion, return and practice restrictions

When information is no longer required, Evergreen deletes, anonymises or securely disposes of it, unless retention is justified by law or a legal claim. Practices must delete or return staff information once it is no longer needed for the requested assessment, booking or their own documented legal obligation. Retention does not justify unnecessary ongoing access, reuse, marketing or onward sharing.

4. Retention periods and questions

Specific periods depend on the data category, the purpose, applicable legislation, contractual requirements, safeguarding and professional requirements, accounting obligations, and the time needed to establish, exercise or defend legal claims. Evergreen must maintain an internal retention schedule that records the actual periods and review triggers. To request the period applying to particular information, contact Evergreen using the details on the Data Protection Contact page.