PapayaLearner Journey

Last updated 23 September 2026

Data retention

This page summarises how long Papaya Learner Journey keeps personal data, and how a customer asks Bidlow Ltd for a data processing agreement. It matches the way the product behaves today. It is not the customer’s own retention schedule, and it is not a signed contract.

Principles

  • The customer is the controller of workforce data. Bidlow Ltd is the processor for that data.
  • Training records are kept long enough to show an inspector that training happened.
  • Records that have been scored or signed are not hard-deleted to tidy a roster.
  • People who have left are marked as resigned or dismissed. Their login stops. Their history stays.
  • A shorter or longer period belongs in the customer’s own policy and, where it changes the product default, in the written agreement.

Training and assessment records

Scores, sign-offs, uploaded evidence, reviews, and the journey they belong to are kept for the length of employment and for at least six years after the person leaves. The product records the leaving date when status changes to resigned or dismissed, and it counts the six years from that date. A later edit does not restart the clock. If the person returns, the leaving date is cleared.

That six-year floor follows the practical need to evidence training under the Health and Safety at Work etc. Act 1974, and the expectation in food-manufacturing audit standards (including BRCGS) that records are genuine, legible, and retrievable. It is also in line with the usual six-year period for civil claims. It is a product rule, stated here so the customer can see it. It is not a formal legal opinion.

The product refuses to delete an employee who already has a score, a sign-off, or an evidence file. The person using the screen is told to set the employment status instead. An employee added in error, with no assessment history, can still be deleted. That deletion removes the row and the files that belonged only to it.

Competency statements that have been scored are retired, not deleted, so a historical assessment still points at the statement it was marked against.

Accounts, logs, and technical data

  • Login accounts are kept while the person needs access. When they leave, the login is deactivated rather than reused for someone else.
  • Session cookies last up to twelve hours of inactivity. See the cookie policy for the full list.
  • The cookie-notice dismissal and the sidebar preference stay in the browser until site data is cleared. They are not a server-side profile.
  • An assessment saved on the device while offline is removed from the device after it is sent.
  • Change-history entries (who changed a record, and when) are kept with the employee record they describe, for the same period as that record.
  • Security and support logs are kept only as long as needed to investigate misuse and to operate the service, and not as a second copy of the training file.

Backups

Database and file storage run on Microsoft Azure. Backups exist so the service can be restored after a fault. A restored backup can briefly contain a record that has since been deleted. We do not state a backup window on this page; the operational runbook and the signed agreement are the right place for that figure. Backup media is not a way for a customer to bypass the retention rules above.

When the customer relationship ends

The customer may ask for an export of its records. After the export, deletion follows the training-record rule above and whatever the signed agreement says. Bidlow Ltd does not silently wipe a six-year training file on the day a subscription ends. Equally, we do not keep data for a new purpose after the customer has left.

Data processing agreement

UK GDPR Article 28 requires a contract when a processor handles personal data for a controller. Bidlow Ltd will provide a data processing agreement template for each customer to review and sign. The points below are an overview of what that agreement is for. They are not the agreement, they are not signed, and accepting this website does not execute them.

The template is written to cover, in the usual way:

  • Roles. The customer is the controller of workforce data. Bidlow Ltd is the processor. Bidlow Ltd remains an independent controller for its own account administration, security, and the commercial relationship, as the privacy policy describes.
  • Subject matter and duration. Hosting the customer’s competency and training records for the life of the subscription, and afterwards for the retention period on this page.
  • Nature and purpose. Storing, displaying, and backing up the assessments, evidence, and documents the customer enters, and providing the optional text features the customer chooses to use.
  • Types of personal data. Identity and job details, account data, competency scores, sign-off, evidence files, and audit responses.
  • Data subjects. The customer’s employees, managers, and administrators.
  • Instructions. Bidlow Ltd processes workforce data on the customer’s documented instructions (the way the customer configures and uses the product) and on the law. We will tell the customer if an instruction appears to break UK GDPR.
  • Sub-processors. Microsoft Azure for hosting, database, and file storage. xAI for optional text features (script drafting, translation, and document summary). Hugging Face for slide-video illustrations when a script is rendered. The current description is in the privacy policy. The signed schedule is the contractual list.
  • International transfers. Database and files in UK South. The application currently in West Europe (EEA), covered by the UK adequacy regulations for the EU. Text sent to xAI or Hugging Face may leave the UK under the UK International Data Transfer Agreement, unless an adequacy regulation applies. The signed agreement will name the locations for that customer.
  • Rights requests and breaches. We will assist the customer with access, correction, erasure (subject to the retention floor), and the other UK GDPR rights, and we will tell the customer of a personal-data breach without undue delay.
  • Return and deletion. Export on request, then deletion consistent with this page and the agreement. The customer stays responsible for any legal hold that requires it to keep a copy.
  • Audit information. The customer may ask for information reasonably needed to show the processing meets the agreement. A formal on-site audit clause, if wanted, is negotiated in the signed document. It is not granted by this page.
Product
Papaya Learner Journey
Provider
Bidlow Ltd
Service
https://papayalearner.bidlow.co.uk
Provider website
https://bidlow.co.uk
Company number
16374082
Registered office
27 Roxburgh Road, Stamford, Lincolnshire, England, PE9 2XE
Privacy contact
support@bidlow.co.uk
Data protection officer
No DPO is appointed

How to request a signed DPA

To ask for the template:

  1. Write to support@bidlow.co.uk, the privacy contact shown in the company details.
  2. Include the customer’s legal name, the site the account is for, and the name of the person who will sign.
  3. Bidlow Ltd sends the current template. The customer reviews it, marks any changes, and both parties sign. The signed copy is the agreement. This web page is not.

We will not generate a signed contract from this screen, and there is no click-to-accept that pretends otherwise. Questions about a person’s own record still go to their employer first. The privacy policy is at /privacy and the cookie policy is at /cookies.

Data retention and DPA — Papaya Learner Journey