Data Retention and Deletion
Updated 2026-09-09
This policy sets out how long Shog Corporate Training keeps each kind of record, what happens when a subscription ends, and where our deletion reaches and where it does not. It is for customer organisations, and in particular for whoever has to answer a retention question from an auditor.
The principle
You are the controller of your learners' data. You decide how long you need it. We hold it for you, and we delete it when you tell us to or when our relationship ends.
Training evidence is the product. A certificate is worth something because the record behind it survives. So the default for evidence records is not a short timer: it is the life of your account. We would rather say that plainly than publish a tidy retention schedule that the product does not actually follow.
Retention table
| Record | What it is | How long we keep it |
|---|---|---|
| Attendee record | Learner name, work email, phone, job details, all encrypted at rest | Life of your account, or until you remove the attendee |
| Enrolment and progress | Which course, which language, modules completed, dates | Life of your account |
| Assessment record | Answers, score, pass mark applied, attempt history | Life of your account |
| Certificate record | Certificate number, course title, module set as it stood on the day, language version, score, issue date, expiry date, status | Life of your account. The record outlives the 12-month validity, because an expired certificate still has to be verifiable as having been genuinely issued |
| Certificate file | The certificate document itself | Your connected storage. We hold the record, never the file |
| Identity evidence | The completion photograph or the signed identity declaration | Your connected storage. We hold the record, never the file |
| Audit log | Your organisation's event log | Life of your account. Included in your export |
| Administrator accounts | Email, password hash, TOTP secret where enabled, linked Google or Microsoft identity | Until the administrator is removed, or the account ends |
| Magic links and one-time codes | The access credential emailed to a learner | Until used or expired. A magic link is issued with an expiry, and the one-time code that confirms it is valid for minutes. Expired links are retained only as an audit event, not as usable credentials |
| Sessions | Administrator and learner portal sessions | Short-lived. An administrator session and a learner portal session both expire on their own, and signing out ends them immediately |
| Email delivery records | That a message was queued, sent or failed, and to which address | Life of your account, as part of the audit trail. Message bodies are not retained as a separate store |
| Billing records | Invoices, receipts, subscription history | Retained after your account ends, for as long as UAE tax and accounting law requires. Card numbers are never held by us; they sit with Stripe |
| Support correspondence | Emails to training@shogconsulting.com and any attachments you send | Kept while the matter is open, and for a reasonable period afterwards for our own record |
| Backups | System backups of the databases | Retained on their own rotation and overwritten in the ordinary course. See "Backups" below |
| Marketing page-view events | First-party page views on our public marketing pages | Aggregate analytics only, not linked to a learner record |
When a subscription ends
There are three stages.
1. The subscription ends. Access to the workspace stops. Administrators can no longer sign in to run training, learners can no longer be enrolled, and outstanding magic links stop working. Nothing is deleted at this point.
2. The 30-day export window. You have 30 days from the end of the subscription to run a full data export. The export covers attendees, enrolments, certificates, assessment records and your audit log. Ask us at training@shogconsulting.com if you need help running it inside the window. Do not leave it to the last day.
3. Secure deletion. After the 30-day window, your organisation's data is securely deleted from our systems. Because each organisation has its own database, this is the deletion of that database rather than a filtered delete across a shared one.
You can ask us to delete earlier, in writing. We will do it, and we will not undo it afterwards.
Certificates already issued
Deleting your workspace data removes the ability to verify a certificate through us, because verification reads the certificate record and the record is gone.
Certificates already issued remain valid as statements of what happened. They keep their number, issue date and 12-month expiry. If continued public verification matters to you after you leave, export your data before the window closes and keep the export. Say so to us before deletion if you want to discuss any other arrangement.
Where you connected your own storage
If you connected Microsoft SharePoint, OneDrive or Google Drive, certificate files, identity photographs and signed declarations were written into your storage and not to ours. We held the evidence record, never the file.
That has a clean consequence at the end. Those files are already in your possession, on infrastructure you control. Our deletion does not affect them, and cannot affect them. We have no ability to reach into your tenant and delete them, and no wish to. Retention and deletion of those files is yours to manage under your own policy.
The reverse is also true while the subscription is live: if you revoke our access to your Drive or SharePoint, or move the folder, the files stay where they are and the certificate records with us stay verifiable. See the Customer Data and Storage policy.
Backups
Backups exist so that a failure does not lose your training evidence. They are retained on their own rotation and are overwritten in the ordinary course.
Two honest points. Data you delete from the live service can still exist in a backup that has not yet aged out, and it goes when that backup expires. And we do not restore an individual record out of a backup into the live service after a deletion; a restore is a disaster recovery action, not a way to undo a deletion.
We do not publish a recovery point or recovery time objective, because we have not committed to one. If your own policy needs one, raise it before you buy and have it recorded on your order form.
Your retention duties are not ours
This is the part that customers most often get the wrong way round.
The legal duty to keep training records sits on the employer, not on the training platform. We hold the records for you and delete them when you ask. Whether you are permitted to ask, and when, is your question to answer.
Two figures worth naming, as examples of what applies to a customer rather than to us:
- Abu Dhabi Global Market: a six-year retention period applies to certain records under the ADGM regime. If you are an ADGM entity, check whether your training evidence falls inside it.
- Abu Dhabi: a five-year retention period is used for occupational safety and health records under Abu Dhabi practice.
Other duties may apply to you, depending on your activity and your regulator. Occupational safety training records are required under Cabinet Resolution No. 1 of 2022 (Article 23(3)) and MoHRE Administrative Decision No. 19 of 2023. If you are a designated non-financial business or profession, or a financial institution, your training evidence duties sit under Federal Decree-Law No. 10 of 2025 on anti-money laundering and countering the financing of terrorism, in force from 14 October 2025, and Cabinet Resolution No. 134 of 2025. Those instruments replaced Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019, which are repealed; a retention policy still citing the repealed instruments needs updating.
We do not give legal advice on which period applies to you. Take your own advice, then set your retention accordingly and tell us if you need us to delete something sooner.
Data protection law and this policy
Onshore, UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data expects personal data not to be kept longer than the purpose requires. Its Executive Regulations have still not been issued, so the detailed rules that would normally set out deletion procedure and evidence of deletion do not yet exist in binding text, and the compliance clock in Article 29 has not started. We follow the principle and we have written above exactly what we do, rather than claim compliance with rules that are not yet published.
If you are in DIFC or ADGM, that free zone's data protection law applies to you instead, with its own supervisor and its own expectations.
Requests and questions
To ask for early deletion, to ask what we hold, or to ask for help with an export, write to training@shogconsulting.com from an address associated with an administrator on the account.
If a learner asks us directly to delete their record, we will refer them to you. The decision is yours, not ours.
This document is published in English. Published by Shog Consulting (FZC), licence SC242038101. Questions go to training@shogconsulting.com.
