Data Retention Policy
How Evergreen retains and securely disposes of personal and business information.
1. Purpose and approach
Evergreen retains personal information only for as long as necessary for the stated staffing, compliance, payment, security or legal purpose. We review retention and restrict access during any retained period; an end of employment, assignment or account does not automatically require immediate deletion where a lawful purpose remains.
2. Staff-to-practice disclosure records
For each assessment or booking, we may retain a record of the information disclosed to the relevant practice, the recipient, purpose, date, assignment and any practice confirmation or access log. These records support accountability, booking management, security, complaints and legal claims. They must not be used to create a general staff dossier or enable continuing access to underlying documents.
- Shortlisting and booking information: retained for the active assignment and for the documented booking, dispute, limitation and regulatory period that applies.
- Compliance-status confirmations: retained only for the relevant verification and audit purpose. We separate them, where feasible, from more sensitive source documents.
- Health, immunisation, DBS and criminal-offence information: retained under a separately documented schedule with restricted access and periodic review; no longer than necessary for the specific lawful purpose and any applicable legal obligation or claim.
- Practice, timesheet, invoice, safety, technical and audit records: retained according to their assignment, accounting, security and legal purposes.
3. Deletion, return and practice restrictions
When information is no longer required, Evergreen deletes, anonymises or securely disposes of it, unless retention is justified by law or a legal claim. Practices must delete or return staff information once it is no longer needed for the requested assessment, booking or their own documented legal obligation. Retention does not justify unnecessary ongoing access, reuse, marketing or onward sharing.
4. Retention periods and questions
Specific periods depend on the data category, the purpose, applicable legislation, contractual requirements, safeguarding and professional requirements, accounting obligations, and the time needed to establish, exercise or defend legal claims. Evergreen must maintain an internal retention schedule that records the actual periods and review triggers. To request the period applying to particular information, contact Evergreen using the details on the Data Protection Contact page.