Data Protection & Retention
How case evidence, workspaces, access and retention are controlled.
This page explains the controls ORVIA applies to case evidence. It sits alongside the Privacy Notice, which explains the lawful basis for using personal information.
Workspace access model
- Each matter is held in a workspace dedicated to that matter, separate from other engagements.
- Access is granted only to the people working on that matter, on the principle of least privilege.
- Access is granted by a named person, recorded, reviewed and removed when it is no longer needed.
- Accounts are individual. Shared logins are not permitted.
- Multi-factor authentication is required for every account with access to case evidence.
- Practitioners are only given access after identity, qualification, conflict and suitability checks and a defined working status.
Launch gate. The workspace platform, hosting location, encryption at rest and in transit, backup arrangement, logging and named subprocessors must be confirmed, contracted under Article 28 processing terms, and published here before ORVIA receives any evidence. This page describes the control model ORVIA requires; it does not claim a system that has been verified in production.
Secure transfer and the evidence register
- Do not send confidential evidence with a first enquiry. There is no upload facility on this website.
- Where a matter proceeds, we issue written instructions for secure transfer into the dedicated workspace.
- Every item received is entered on a controlled document register recording what it is, where it came from, when it arrived and its status.
- Findings are traced back to registered source material, so that a reader can see what a conclusion rests on.
- Evidence is not edited. Working notes and analysis are kept separately from the source record.
Retention
ORVIA applies these retention criteria by case status:
| Status | Retention criterion |
|---|---|
| Enquiry that does not proceed | Kept only as long as needed to record that the enquiry was received and not taken forward. Evidence sent unsolicited is returned or deleted. |
| Declined matter | Kept only as long as needed to evidence the reason for declining, including any conflict identified. |
| Active case | Kept for the life of the engagement, under the written scope. |
| Closed case | Kept for the period needed to answer questions about the findings and to meet legal, insurance and professional requirements, then destroyed. |
| Legal hold | Retained until the hold is lifted, whatever the ordinary period would be. |
Retention periods are set against ORVIA’s professional indemnity policy terms, limitation periods and legal advice, and confirmed on request. We do not publish invented periods.
Destruction and legal hold
When a retention period ends, records are destroyed securely, and the destruction is recorded. A legal hold suspends destruction: it is applied by a named person, recorded, and lifted only by a named person.
Subject access and other rights
You have the right to ask for a copy of the personal data we hold about you, to correct information that is wrong, to object to how we use it, to ask for it to be erased in certain circumstances, and to complain to the Information Commissioner’s Office. Requests are handled as described in the Privacy Notice. Case evidence often names people other than the requester, so a response may need to be redacted to protect them. Where information was created by another organisation, we will tell you who it came from so you can approach them as well.
Make an information-rights request
This form is the fastest route. We aim to acknowledge within three working days and to reply within the statutory time limit (usually one calendar month). This is not an emergency service.
Personal data breaches
- Anyone who suspects a breach must report it immediately to [email protected].
- We contain the incident, assess the risk to the people affected, and record it in a breach log whether or not it is reportable.
- Where there is a risk to people’s rights and freedoms, we report to the Information Commissioner’s Office without undue delay and within 72 hours of becoming aware.
- Where there is a high risk, we tell the people affected directly and explain what they can do.
- Where the breach involves case evidence, we consider whether it creates a safeguarding risk and act on that first.
Our breach response procedure names a responsible individual and a deputy and is tested. Named individuals are recorded internally and confirmed on request.