Data Retention Schedule
How to request deletion. Club admins can disconnect Meta under Settings → Integrations. Members may contact the fitness business that holds their data, or email [email protected]. Verified requests are processed within 30 days, subject to this schedule and lawful retention in the Data Processing Addendum.
Contents
Purpose. This memorandum sets forth the data retention schedule for JAMr FIT.
I. INTRODUCTION
1.1 RetterTEK operates JAMr FIT (the "Platform"), a multi-tenant software application licensed to fitness clubs and other fitness businesses (each, a "Client")
Section 10 of the current JAMr FIT Data Processing Addendum (the "DPA") provides that RetterTEK may delete or de-identify Client Data "in accordance with its retention schedule." The following sets for the data retention schedule which is required for Clients absent agreement to the contrary.
III. RETENTION SCHEDULE
A. Tier A - retained indefinitely
3.2 The following categories would be retained without expiry:
- (a) Marketing opt-out and unsubscribe records. A suppression constitutes an ongoing restriction on contact; deletion could cause a previously suppressed recipient to be contacted again.
- (b) Consent audit history. Evidence that consent existed, and of the date and manner in which it was given or withdrawn.
- (c) Records of data-deletion requests honored. Evidence that an erasure request was performed.
- (d) Form consent records. Evidence of consent captured at the point of collection.
3.3 These four categories together occupy approximately 200 MB, representing some 2.8% of the Platform database. Indefinite retention accordingly carries negligible storage cost, subject to counsel's advice regarding data minimization and whether "indefinite" should instead be framed as "for so long as reasonably necessary to document suppression, consent, deletion compliance, or legal claims."
B. Tier B - retained seven (7) years from last activity
3.4 The following categories would be retained for seven years measured from the date of last activity:
- (a) time punches
- (b) time punch audit history
- (c) payroll audit history
- (d) payroll ledger entries
- (e) session pay overrides
- (f) commission overrides
- (g) employee payroll profiles
- (h) timekeeping change requests
- (i) per-message records used to evidence messaging activity or compliance
- (j) internal do-not-call request records; and
- (k) proof-of-consent records not otherwise retained in Tier A.
C. Tier C - no fixed retention obligation after offboarding
3.5 All remaining Client-scoped operational data, including member contact and profile data, appointment history, routine message history not retained under Tier B, tasks, cases, form submissions and media, would be subject to no fixed post-termination retention obligation unless applicable law, the Agreement, a Client instruction, a legal hold, security requirements, or dispute-resolution needs require otherwise.
3.6 Such data would ordinarily be made available for export for thirty (30) days after termination or expiration and then may be deleted or de-identified in accordance with this schedule, subject to backup cycles and the exceptions stated in the DPA.
D. Marketing and consent records
3.12 We hold marketing and consent records for the following periods:
- (a) Opt-out and revocation records - indefinite or for so long as reasonably necessary to maintain suppression and evidence compliance, subject to counsel's recommendation.
- (b) Per-message records - seven years.
- (c) Internal do-not-call requests - seven years.
- (d) Proof of consent - seven years from the last activity or last communication for which that consent was relied upon, unless retained longer under Tier A.
APPENDIX A. SYSTEM MAPPING (FOR A TECHNICAL REVIEWER)
Tier A: member_unsubscribes; consent_audit_log; data_erasure_log; form_consent_logs Tier B: employee_time_punches; time_punch_audit_log; payroll_audit_log; payroll_ledger_lines; payroll_session_pay_overrides; payroll_commission_overrides; employee_payroll_profiles; time_punch_change_requests; applicable messaging activity / DNC / consent evidence records Tier C: all remaining Client-scoped tables, subject to legal hold, security, billing, backup and other DPA exceptions