Version 1.0 · Effective 14 September 2026
Both the Botswana Data Protection Act 18 of 2024 and POPIA require that personal information is not kept for longer than it is needed. This page sets out, category by category, how long Digital Learning Academy keeps each kind of record, why, and what happens at the end of the period.
Periods run from the trigger named in the schedule, which is usually the closure of your account or your last activity, not from the date the record was created. “Anonymised” means the link to you is removed permanently and what remains is a statistic that cannot be traced back. “Deleted” means removed from the live system; copies persist in encrypted backups until those backups age out, which is covered in section 3.
Periods marked [TO CONFIRM] are our proposal, set at what we consider defensible for a regional public-sector body running a professional learning platform. They are not yet ratified by the Centre. Where a period is still open, we apply the shorter of the proposed period and what the law requires.
| Data category | How long we keep it | Why | What happens at the end |
|---|---|---|---|
| Account and profile: name, email, organisation, institution, country, job title, headline, biography, skills, work history, phone number, language and notification preferences | While the account is open, then 90 days after closure [TO CONFIRM] | Performance of the agreement with you. The 90 days allow for a mistaken or disputed closure to be reversed and for any appeal to run. | Deleted. Where the record is needed to keep a credential verifiable, the name is retained on the credential record only. |
| Profile photograph (stored inside the database) | While the account is open, then 90 days after closure [TO CONFIRM] | Your consent. You can remove it yourself at any time in Settings. | Deleted from the live database. Because it is stored inside the database rather than as a file, copies remain in backups until those backups age out. |
| Password hash | While the account is open | Necessary to authenticate you. | Deleted with the account. |
| Learning records: enrolments, cohort membership, lesson completion, completion dates | 5 years from your last activity on the course [TO CONFIRM] | Programme reporting to member institutions and funders, and your own ability to evidence what you studied. Five years matches a typical audit and professional-development cycle. | Anonymised. Aggregate completion statistics are kept; the link to you is removed. |
| Video and lesson telemetry: seconds watched, last position, heartbeats, last active time | 12 months from the activity [TO CONFIRM] | It exists to drive completion tracking and resume-where-you-left-off. Once a lesson is complete it has served its purpose, and it is the most granular behavioural data on the Platform. | Deleted. The completion flag and completion date survive in the learning record. |
| Assessment records: attempt number, score, pass or fail, language, and the full set of answers given | 3 years from the attempt for the answer detail; 5 years for score and outcome [TO CONFIRM] | Credential integrity. If a result is challenged or a credential is questioned, the attempt must be capable of being re-examined. The answer detail is the part we can let go of first. | Answer detail deleted; score and outcome retained on the learning record, then anonymised with it. |
| Credentials, certificates and CPD points | 10 years from issue, and beyond that where a verification link is still in use [TO CONFIRM] | A certificate that cannot be verified is worthless. We tell holders and their institutions that a credential can be checked, and employers and regulators check them years after issue. The record kept is deliberately minimal: holder name, credential, issue date, verification identifier. | Reviewed and, unless a verification need remains, deleted. Survives the closure of your account by design; tell the Information Officer if you want a credential withdrawn from verification. |
| Posts, comments, likes, group discussions, event registrations | While the account is open; 90 days after closure [TO CONFIRM] | Performance of the agreement, and the coherence of discussions other members are part of. | Your posts and comments are deleted. Where deleting a post would break a thread others contributed to, we may instead detach it from you so it shows as from a removed member. |
| Direct messages and group conversations | While either participant holds an open account; 90 days after the last participant closes theirs [TO CONFIRM] | A conversation belongs to both sides, so one person leaving cannot erase the other person’s record of it. | Deleted. Message bodies are stored in readable form throughout, so keep the period in mind when deciding what to send. |
| Sign-in sessions: session identifier, IP address, user agent, creation and expiry times | Until the session expires or you sign out, and no more than 30 days after expiry [TO CONFIRM] | Necessary to keep you signed in, and to let us investigate suspicious access. | Deleted. |
| Presence: last seen time, and the IP address and user agent last seen from | One rolling record per member, continuously overwritten | Showing members who is currently active. No history is accumulated. | Deleted with the account. |
| Failed sign-in attempts: the email address typed, IP address, user agent, time | 90 days [TO CONFIRM, and see the note below] | Detecting password guessing and credential-stuffing attacks. Ninety days is long enough to see a slow campaign and short enough to be proportionate. | Deleted. This is the one category that can contain the email address of someone who has no account with us, which is why the period is short and the records are never used for anything but security. |
| Google sign-in tokens: access token, refresh token, identity token, expiry times, scopes | While the Google connection is active | Necessary to let you sign in with Google. | Deleted when you disconnect Google or close your account. Ask the Information Officer and we will also revoke them at Google. |
| Consent records: which version of the Terms and Privacy Policy you accepted, and when | Life of the account, then 3 years after closure [TO CONFIRM] | Both the Botswana Act and POPIA require a responsible party to be able to demonstrate the consent it relies on, after the fact. | Deleted. |
| Reports of breaches of the community guidelines, and the decisions taken | 3 years from the decision [TO CONFIRM] | Consistency between decisions, the ability to see repeat behaviour, and the ability to review a decision on appeal. | Deleted. |
| Error reports and session replays held by Sentry | The retention period of our Sentry plan [TO CONFIRM: the configured retention for errors and for replays, typically 90 days] | Diagnosing faults. Replays are masked and run only on a sample of errors. | Deleted automatically by Sentry. |
| Transactional email delivery logs held by the mail relay | [TO CONFIRM: the relay provider’s log retention, typically 30 days] | Proving that a verification or password-reset email was sent and delivered. | Deleted automatically by the provider. |
| Database backups | [TO CONFIRM: backup rotation, proposed 30 days of daily encrypted backups] | Recovery from failure, corruption or attack. A platform without backups is not a safe place for your learning record. | Overwritten on rotation. See section 3. |
| Stored translations | As long as the post or description they were made from | A translation is kept so the next person to ask for it is served instantly instead of the same text being sent away again. It is your words in another language, so it is treated as your words. | Removed with the content it came from. Editing the original orphans the old translation, which is then pruned by age. |
Deleting something from the live Platform does not reach into last night’s backup, and we will not pretend otherwise. Backups are encrypted, access to them is restricted, and they are used only to restore the service. A record you asked us to delete disappears from backups when those backups are overwritten on rotation. If we ever have to restore from a backup taken before a deletion, we re-apply the deletion afterwards.
You can ask us to delete your account or a specific record before the period above expires. There is no button for it yet; write to the Information Officer at SADC-DFRC@socoed.com and we will do it by hand. We will tell you what we can delete immediately, what has to wait, and why. The categories we normally cannot delete on request are credential records, where deletion would break verification for certificates already relied on, and anything the law requires us to keep.
Several periods above are marked [TO CONFIRM]. They are our proposal, not yet ratified, and they are published rather than hidden so that members and the Centre’s advisers can see exactly what is outstanding. Two of them are gaps rather than choices, and we would rather name them: failed sign-in records currently have no automatic expiry in the system, and there is no automated job enforcing the account and profile periods. Both are handled manually today, and both should be automated. [TO CONFIRM: target date for the automated retention job.]
This schedule changes as the Platform changes. The version and effective date at the foot of the page move with it, and material changes are notified on the Platform.
Version 1.0 · Effective 14 September 2026