We strive for excellent training experiences and continuously improve for learners and organizations.








Because you deserve a training platform that delivers.
Clarivive MedInsight
Last Updated: 12 July 2026
Version Number: 1.0
Clarivive MedInsight Ltd retains records only for as long as they are reasonably necessary for training delivery, learner administration, certification, quality assurance, legal and regulatory compliance, financial administration, audit, contractual obligations and legitimate business governance. Personal information is retained in accordance with the storage-limitation principle of the UK GDPR (Article 5(1)(e)), the Data Protection Act 2018 and applicable amendments introduced by the Data (Use and Access) Act 2025. We do not retain all records indefinitely. Retention periods are determined according to the type and purpose of the record and any applicable legal, regulatory, contractual or evidential requirement. Certain records may therefore need to be retained for longer, including where required for company accounting purposes (Companies Act 2006, section 388), or where reasonably necessary in connection with an ongoing complaint, safeguarding concern, investigation, contractual dispute or potential legal claim, having regard to applicable limitation periods (including the Limitation Act 1980, where applicable).
Purpose
This policy explains how Clarivive MedInsight Ltd manages the retention, review, archiving, anonymisation and secure disposal of learner, training, certificate and business records.
Its purpose is to ensure that records are:
Retention periods may be revised where legislation, regulatory requirements, accreditation arrangements, contractual duties, technology or business operations change.
Records we may hold
Records retained by Clarivive MedInsight Ltd may include:
We aim to retain only information that is adequate, relevant and necessary for the stated purpose.
General retention approach
Records may move through the following stages:
Active record
The record is required for a current learner account, course, booking, assessment, complaint, support matter or other active business purpose.
Restricted archive
The record is no longer used routinely but must remain available for an applicable retention, audit, legal, certification or contractual purpose. Access should be restricted to authorised individuals.
Metadata-only record
The detailed record is deleted or reduced, but limited information is retained for a specific purpose such as certificate verification, fraud prevention or confirmation that a request was previously completed.
Secure deletion or anonymisation
The record is securely deleted or irreversibly anonymised when there is no continuing lawful or operational reason to retain identifiable information.
Retention periods should normally begin from a defined event, such as:
Records may also be placed under a legal or safeguarding hold, meaning routine deletion is paused while an investigation, claim, audit or serious concern remains active.
Typical retention periods
The following periods are general operational standards. A shorter or longer period may apply where justified by the circumstances, legal requirements, awarding-body rules, contractual obligations or an active investigation.
| Record type | Typical retention period |
| Learner LMS account and profile | While active, then normally up to 15 months (1 year + 3 months) after the last meaningful account activity |
| Course enrolment and completion record | Normally up to 6 years after course completion |
| Attendance record | Normally up to 6 years after the relevant course or session |
| Certificate verification metadata | Normally up to 10 years after certificate issue, expiry or revocation |
| Downloadable certificate PDF | Until expiry or renewal. |
| Online assessment answers or detailed evidence | Normally up to 3 years after the assessment outcome |
| Assessment outcome as Pass or Fail | Normally up to 6 years after course completion |
| Practical assessment record | Normally up to 6 years after the assessment |
| Webinar attendance or participation record | Normally up to 2 years after the webinar |
| Routine LMS activity and technical logs | Normally up to 12 months, unless required for security or investigation |
| Accessibility or reasonable-adjustment records | Normally for the relevant course and up to 15 months afterwards, unless longer retention is justified |
| Complaints and appeals | Normally up to 6 years after final closure |
| Safeguarding and serious-incident records | According to the nature of the concern, legal advice and applicable safeguarding requirements |
| Malpractice, fraud or misconduct records | Normally up to 6 years after closure, or longer where justified |
| Employer and group-booking records | Normally up to 6 years after completion or contract closure |
| Routine learner-support communications | Normally up to 2 years after the matter closes |
| Payment, invoice and accounting records | Normally at least 6 years from the end of the relevant company financial year |
| Refund and cancellation records | Normally up to 6 years after the matter closes |
| Marketing consent records | While marketing continues and for a reasonable period afterwards to demonstrate the consent relied upon |
| Marketing objection or suppression record | Limited information may be retained for as long as necessary to ensure the person is not contacted again |
| Unsuccessful general enquiries | Normally up to 3 months after the final response |
| Website security logs | Normally between 6 and 12 months, unless needed for investigation |
Limited-company tax and accounting records may generally need to be retained for six years from the end of the relevant company financial year, with longer retention required in certain circumstances.
The periods in this table are maximum working standards, not automatic instructions to retain every record for the entire period. Records may be deleted earlier where they are no longer needed and no legal, contractual or operational reason requires continued retention.
Certificate verification
Clarivive MedInsight Ltd may retain limited certificate metadata for longer than detailed LMS activity, assessment answers or routine learner communications.
Certificate metadata may include:
This information may be retained to:
Certificate verification must be proportionate. We will not ordinarily disclose detailed assessment answers, health information, private communications or unrelated learner records merely to verify a certificate.
Where a detailed learner record is no longer needed, it may be deleted while limited verification metadata is retained.
Longer retention
Records may be retained beyond the usual period where this is reasonably necessary for:
Where a record is retained longer than its normal period, the reason should be documented and the need for continued retention reviewed periodically.
Longer retention does not mean unrestricted access. Archived records must remain protected and accessible only to authorised individuals with a legitimate need.
Deletion requests
Individuals may request deletion of their personal information through the privacy-request process described in our Privacy Policy.
A deletion request will be considered individually with a signed consent form uploaded while initiating a request for deletion. The right to erasure is not absolute, and some information may lawfully need to be retained.
For example, we may need to retain limited records for:
Where full deletion cannot be completed, we may:
Closing or deleting a learner account does not necessarily require deletion of all underlying course, assessment, transaction or certificate-verification records.
Secure deletion
When records are no longer required, they will be securely deleted, anonymised or reduced to limited metadata using methods appropriate to the system and sensitivity of the information.
This may include:
Information contained in backups may not disappear immediately when it is deleted from an active system. Backup copies should remain protected, should not be used for ordinary business purposes and should be overwritten or deleted through the normal backup-retention cycle.
Where deletion is completed in response to a formal privacy request, an appropriate record may be retained to demonstrate that the request was received and acted upon.
Contact
For questions about records retention, deletion or the use of personal information, please use the privacy-request form provided under our Privacy Policy.
If the form cannot reasonably be used, contact:
Email: info@clarivive.co.uk
Please provide enough information for us to identify the relevant records and understand your request. We may need to verify your identity before disclosing, correcting or deleting personal information.
Do not send passwords, full payment-card information, unnecessary medical records or confidential patient information through ordinary email.