The Nullware Standard0 trackers on this page
Pledge 03 · Data minimisation

We keep only what we need.

Data that isn’t held can’t leak, be sold or be misused. Members collect what it takes to serve their customers, say how long they keep it, and delete it on schedule.

keptdeleted on schedule
01

Why less is safer

Most data problems start with data nobody needed any more.

01
Forms that ask too much
Date of birth for a newsletter. A phone number for a download. Collected “just in case”.
02
Data that never leaves
Old accounts, abandoned carts and years of support tickets, kept because deleting takes effort.
03
Bigger breaches
The more a business stores, the more there is to lose when something goes wrong.
04
Tempting later
Data kept for no reason is easy to find a reason for later, like selling or matching it.
The pledge
We collect what we need, and delete it when we’re done.

Members only ask for data that’s needed to serve the customer or required by law. They publish a retention schedule for each type of data they hold, and deletion happens automatically when the time is up, not when someone remembers. Deleted data leaves live systems at once and ages out of backups within a stated period.

Fineinside the line
Keeping order and tax records for as long as the law requires.
Asking for an address when there’s something to deliver.
Keeping support history while a problem is open, and for a stated time after.
Anonymised, aggregate figures kept for trends and planning.
Neveroutside it
Required form fields that aren’t needed for the service.
Keeping data indefinitely “in case it’s useful”.
Holding on to closed accounts or old customers’ details without a reason.
Retention periods that exist on paper but are never enforced.
02

A published retention schedule

Every member publishes one. It shows what they keep, why, for how long, and what happens after. This is an example layout.

Data
Why it’s kept
For how long
Then
Order records
Tax and accounting
6 years in the UK
Deleted automatically
Delivery details
Deliveries, returns and warranty
Kept with the order record
Removed from the courier after delivery
Support conversations
Solving the problem
12 months after it’s resolved
Deleted
Newsletter email
Sending what you asked for
Until you unsubscribe
Only a do-not-mail record stays
Closed accounts
Nothing, once closed
30 days
Permanently deleted
Backups
Recovering from failure
35 days
Aged out automatically
Legal holds
A dispute or an investigation
Until it ends
Logged, then back to schedule
03

How we check

Minimisation is a signed pledge, and the retention schedule is published on every member’s record. At review we read the schedule and every form a customer fills in. When a concern is reported, we ask for evidence that deletion actually runs, such as an automated job, a log or a test account that has disappeared on time.

This page is general information, not legal advice.
04

Questions

Won’t deleting data hurt our marketing?
Rarely. Aggregate trends survive deletion, and customers who asked to hear from you stay subscribed until they say otherwise.
Do we need exact numbers for every data type?
Yes. “As long as necessary” isn’t a schedule. Each type gets a period or a clear trigger, like “until the order is delivered”.
Previous · pledge 02LeavingNext · pledge 04Every channel
Holding less than you could?

Membership lets you prove it, with a schedule anyone can read.

Apply to joinTake the self-check