Data Retention Policy
How long we keep data and why.
- Owner
- Data protection lead
- Version
- v1.0
- Effective date
- 25 July 2026
- Next review
- 25 July 2027
01Purpose
"bee Charity" Verein (“BeeCharity”, “we”, “us”, “our”) is a Swiss association (Verein) with its seat in Dübendorf, Canton of Zurich, registered in the Commercial Register Office of the Canton of Zurich under UID CHE-457.076.818. In the course of our work we collect and hold personal data and other records about donors, volunteers, beneficiaries, partners and others, and we take seriously our responsibility to keep that information only for as long as we genuinely need it.
The purpose of this Data Retention Policy is to explain how long BeeCharity keeps the different kinds of data we hold, why we keep them for those periods, and how we store and then securely destroy them when they are no longer needed. Keeping data for no longer than necessary is both a legal requirement — under the storage-limitation and data-minimisation principles of the European General Data Protection Regulation (GDPR) and the revised Swiss Federal Act on Data Protection (revFADP) — and an important safeguard: the less data we hold unnecessarily, the lower the risk to the people whose information it is.
This policy sits alongside our Privacy Policy, which explains what data we collect and how we use it, and supports our Anti-Fraud, Safeguarding, Complaints and other policies, each of which relies on records being kept for an appropriate time and then disposed of responsibly. It has been formally adopted by the board and is published in the spirit of transparency. The retention periods set out below describe the standards we apply.
02Scope
This policy applies to all data and records held by or on behalf of BeeCharity, in whatever form they are kept — including electronic data stored in our email, cloud storage, spreadsheets, website and third-party platforms, as well as any information held on paper. It covers personal data (information relating to identified or identifiable individuals) and also non-personal records such as financial and governance documents.
It applies to everyone who handles data for BeeCharity, including board members, volunteers, contractors and any service providers who process data on our behalf. Everyone in these groups is expected to follow this policy: to keep data only in approved locations, to retain it only for as long as this policy allows, and to dispose of it securely when the retention period ends. Where we use third-party processors — for example a cloud-storage, email or donation-platform provider — we expect them, through their terms and our instructions, to retain and delete data consistently with this policy.
The policy covers the whole lifecycle of a record, from creation and storage, through the active period in which it is used, to its eventual secure destruction or anonymisation. It applies whether data is held in Switzerland or, through our service providers, elsewhere, and it operates together with our Privacy Policy, which governs the lawful basis for processing and the rights of individuals in relation to their data.
03Categories of Data
We hold several broad categories of data, each of which may have different retention needs. The main categories are:
Some of these categories include “special category” or sensitive personal data — such as health information about the children our healthcare programme supports, or data revealing other sensitive characteristics — which attracts additional protection under both the GDPR and the revFADP. We identify such data, apply stricter controls to it, and are especially careful not to keep it for longer than is genuinely necessary.
- Donor and financial-supporter data — names, contact details, donation records, and related correspondence, including information needed for receipts, thank-yous and financial accounting.
- Volunteer data — application and contact details, records relating to a person’s volunteering, and, for certain roles, safeguarding-related checks.
- Beneficiary data — information about the individuals and communities our projects support, which in our children’s healthcare work may include sensitive health-related information.
- Partner and supplier data — contact and contract details, due-diligence records, and correspondence with organisations we work with.
- Governance and organisational records — statutes, minutes, decisions, registers (including the register of interests), and records relating to the running of the association.
- Financial and accounting records — books of account, invoices, receipts, bank records and related documents.
- Safeguarding and incident records — records of safeguarding concerns, complaints, and fraud or other incidents.
- Website and technical data — enquiries and messages sent through our website, and limited technical data such as cookie-consent choices, as described in our Privacy and Cookies policies.
04Retention Periods
We keep each category of data only for as long as we need it for the purpose it was collected, or for as long as we are required to keep it by law. The following retention periods are indicative and will be confirmed on formal adoption of this policy; where a legal minimum applies (in particular for financial records), that minimum governs:
Where none of the specific periods above applies, our default rule is to keep personal data only for as long as it is needed for the purpose for which it was collected, and then to delete or anonymise it. When a retention period ends, data is securely destroyed or irreversibly anonymised as described below, unless it is subject to a legal hold.
- Financial and accounting records — retained for at least ten years, reflecting the retention obligation for business/accounting records under Swiss law (Code of Obligations).
- Donor and donation records — retained for the period necessary for accounting and receipting and to meet financial-record obligations (aligned with the accounting-records period), after which contact data no longer needed is deleted or minimised; we stop sending communications promptly when someone opts out.
- Volunteer records — retained for the duration of the volunteering relationship and for a limited period afterwards (indicatively up to around three years) to deal with references and any follow-up, after which they are deleted.
- Safeguarding-related checks and records — retained in line with safeguarding good practice and any legal requirement; safeguarding incident records may need to be kept for an extended period given their seriousness, as set out in our Safeguarding and Child Protection Policy.
- Beneficiary data, including health-related data — retained only for as long as necessary to deliver and account for the relevant project and to meet any applicable legal or safeguarding requirement, then securely deleted or anonymised; sensitive health data is kept for the shortest period reasonably possible.
- Partner and supplier records — retained for the duration of the relationship and for a limited period afterwards (indicatively up to around ten years for records tied to financial or contractual obligations, otherwise shorter) to handle queries, disputes and due-diligence continuity.
- Governance records — core governance documents (such as statutes, key decisions and minutes) are retained for the life of the association as part of its permanent record.
- Complaints and incident records — retained for as long as necessary to resolve the matter, learn from it and meet legal or governance requirements, then securely deleted or anonymised, as set out in our Complaints Policy.
- Website enquiries and correspondence — retained only for as long as necessary to deal with the enquiry and any related follow-up.
- Cookie-consent and technical data — retained as described in our Cookies Policy, typically only until the choice is changed or expires.
05Secure Storage
For as long as we retain data, we store it securely and take appropriate technical and organisational measures to protect it against loss, unauthorised access, alteration or disclosure, as required by both the GDPR and the revFADP. The level of protection we apply reflects the sensitivity of the data, with the strongest safeguards reserved for sensitive information such as the health data of the children our programmes support and safeguarding records.
In practical terms, electronic data is held in reputable, access-controlled systems — such as our email, cloud storage and the platforms we use for donations and communications — protected by measures including strong, individual and non-shared credentials, multi-factor authentication where available, and access restricted to those who genuinely need it for their role. We keep the number of people with access to sensitive data to a minimum, we remove access promptly when a person’s involvement ends, and we prefer not to hold sensitive data on personal devices. Any paper records we hold are kept securely and access to them is likewise restricted.
Where we rely on third-party service providers to store or process data on our behalf, we choose reputable providers, expect them to apply appropriate security and to act only on our instructions, and take account of where they store data and any resulting international-transfer safeguards, in line with our Privacy Policy. We keep our security practices under review and strengthen them as the organisation grows, and any personal-data breach is handled in accordance with our Privacy Policy and applicable law, including notification to the competent authority and affected individuals where required.
06Secure Destruction
When data reaches the end of its retention period, or is otherwise no longer needed, we destroy it securely or irreversibly anonymise it, so that it cannot be reconstructed or accessed by anyone who should not have it. Simply deleting a file is not always enough, and we treat secure disposal as an important final step in the data lifecycle rather than an afterthought.
For electronic data, secure destruction means deleting the data from the relevant systems, including — so far as we reasonably can — from backups and from third-party platforms, and, where appropriate, using deletion methods that make recovery impracticable. Where we choose to keep information for legitimate statistical or historical purposes, we anonymise it fully so that it no longer relates to an identifiable person, in which case it falls outside data-protection retention limits. Any paper records containing personal data are destroyed by shredding or another secure means rather than simply discarded.
We carry out disposal in an orderly way: we periodically review the data we hold, identify records that have reached the end of their retention period, and dispose of them securely, keeping a proportionate record that destruction has taken place where it is useful to be able to demonstrate this. Where a third-party processor holds data on our behalf, we ensure that data is deleted or returned at the end of our arrangement with them. No data that is subject to a legal hold is destroyed until the hold is lifted, as described below.
07Legal Holds
Occasionally we may need to keep certain data for longer than its normal retention period because it is relevant to actual or reasonably anticipated legal proceedings, a regulatory investigation, an audit, or a safeguarding or fraud investigation. In such cases we apply a “legal hold”, which suspends the normal destruction of the relevant records until the matter is resolved and the hold is lifted.
When a legal hold applies, the records within its scope must not be deleted, altered or disposed of, even if their ordinary retention period expires while the hold is in place — doing so could destroy evidence, prejudice a legal position, or breach a legal obligation. The board is responsible for deciding when a legal hold is needed and for defining, as clearly as possible, which records it covers, and for informing anyone who handles those records so that routine deletion does not inadvertently remove them.
A legal hold lasts only as long as it is needed. Once the proceedings, investigation or other reason for the hold has concluded, and there is no continuing legal or good-practice reason to keep the records, the hold is lifted and the records are returned to the normal retention and secure-destruction process described in this policy. We keep a note of legal holds we have applied and lifted, so that our handling of the affected records can be explained if necessary.
08GDPR
Where we process the personal data of individuals in the European Union or European Economic Area — for example donors, volunteers or supporters based there — the General Data Protection Regulation (GDPR) applies, and this policy is designed to help us meet its requirements on how long data may be kept. The GDPR’s “storage limitation” principle requires that personal data be kept in a form which permits identification of individuals for no longer than is necessary for the purposes for which it is processed, and its “data minimisation” principle requires that we hold no more data than we need.
This policy gives effect to those principles by setting defined retention periods, by defaulting to keeping data only as long as necessary where no specific period applies, and by requiring secure destruction or anonymisation once data is no longer needed. It also supports the rights the GDPR gives individuals — including the right of access, the right to rectification, and the right to erasure (the “right to be forgotten”) — because clear retention rules make it possible for us to identify and delete data when someone exercises those rights, subject to any overriding legal obligation (such as the duty to retain accounting records) or legal hold.
Our overall approach to GDPR compliance — including the lawful bases on which we process personal data, how we respond to individuals exercising their rights, our handling of international transfers, and how to make a request or complaint — is set out in our Privacy Policy, which should be read together with this Data Retention Policy. Individuals in the EU/EEA also retain the right to complain to their national data-protection authority.
09Swiss FADP
As a Swiss association, our processing of personal data is governed by the revised Swiss Federal Act on Data Protection (revFADP, also referred to as the nFADP), which came into force in September 2023 and which, like the GDPR, requires that personal data be processed lawfully, in good faith and proportionately, and be kept only for as long as necessary for the purpose of processing. This policy is designed to meet those requirements as they apply to us in Switzerland.
Under the revFADP we must process data proportionately and delete or anonymise personal data once it is no longer needed for the purpose for which it was collected, and we must apply appropriate data security to protect it while we hold it — obligations that this policy implements through its retention periods, secure-storage measures and secure-destruction practices. The revFADP gives individuals rights broadly similar to those under the GDPR, including rights of access, correction and deletion, and clear retention rules enable us to honour those rights. Where the revFADP requires it, we also handle data-security breaches appropriately, including notifying the Federal Data Protection and Information Commissioner (FDPIC) and affected individuals where the breach is likely to result in a high risk to them.
Certain retention periods are set not by data-protection law but by other Swiss law — most notably the obligation under the Swiss Code of Obligations to retain business and accounting records for ten years — and where such an obligation applies, we retain the relevant records for the required period even though we would otherwise delete personal data sooner, and we then dispose of them securely. Our wider approach to the revFADP, including lawful processing and individuals’ rights, is described in our Privacy Policy, which operates together with this policy.
10Review
This policy, including the retention periods it sets out, was formally adopted by the board and is reviewed at least annually, or sooner if there is a relevant change in the GDPR, the revFADP, the Swiss Code of Obligations or other applicable law, in recognised good practice, or in the nature and scale of the data we hold. We will update the retention periods described above whenever the legal or practical position changes.
Any material change to this policy is approved under our joint signing authority, with two authorised representatives acting together. The version and status shown at the top of this page reflect its current standing as a policy formally adopted by the board, and we will update the version history whenever it is amended. This policy should always be read together with our Privacy Policy and our other related policies, including Anti-Fraud, Safeguarding and Complaints.
11Contact
If you have any question about this policy, about how long we keep your data, or if you wish to exercise your data-protection rights (such as asking us to delete data we no longer need to keep), please contact us and we will be glad to help.
Data protection and retention enquiries: beecharity1@gmail.com
Privacy enquiries: beecharity1@gmail.com
Complaints: beecharity1@gmail.com
Postal address: "bee Charity" Verein, c/o Jasmin Semra Gabrielli, Bahnhofstrasse 33, 8600 Dübendorf, Switzerland (please mark correspondence “Data Protection”)
