Email user terms & conditions

Email Retention, Archiving & Mailbox Responsibility Terms

Chill CIC (domain: chilluk.org)
Effective date: 1 September 2021


1) Purpose and scope

These Terms set out the responsibilities of individuals using an @chilluk.org email account for the saving, retention, and archiving of emails. They apply to all directors, staff, contractors, and volunteers (“Users”).

Because email may contain personal data, Users must comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).


2) Ownership and responsibility

  • Each User is solely responsible for the proper saving, management, and archiving of their own mailbox, including sent and received emails.
  • Chill CIC provides the @chilluk.org address, but does not accept liability for any loss of data, missed archiving, or failure by a User to store emails in line with these Terms.
  • Users have no expectation of privacy in their Chill CIC mailbox beyond what is required by law. Access may be monitored or delegated if legally or operationally required.

3) User responsibilities

Each User must:

  • Ensure all business-related emails they send or receive through @chilluk.org are properly saved and, where necessary, archived in an approved location (e.g., cloud storage, case folder, or designated archive tool).
  • Delete transitory or unnecessary emails when no longer required.
  • Avoid forwarding work emails to personal accounts or third-party systems.
  • Maintain their inbox so records are retrievable for business or legal purposes.
  • Respond promptly to any request for information, deletion, or preservation (e.g., Subject Access Request, legal hold).
  • Each User is responsible for the proper management of all contacts within their mailbox (including the inbox, sent items, and subfolders). This includes ensuring that personal data contained in contact records, address books, or distribution lists is accurate, kept up to date, and deleted when no longer required, in line with UK GDPR and these Terms.

Failure to do so may be considered a breach of both these Terms and UK data protection law.


4) Chill CIC’s role

Chill CIC will:

  • Provide Users with an @chilluk.org email address and guidance on data protection compliance.
  • Issue periodic instructions on retention, deletion, and archiving standards.
  • Reserve the right to access mailboxes for legal, operational, or compliance reasons.

Chill CIC is the data controller for personal data processed via its domain but does not undertake the day-to-day responsibility for saving or archiving individual mailboxes.


5) Data protection and retention

  • Under the UK GDPR and DPA 2018, personal data (including in emails) must not be kept longer than necessary.
  • Users must apply the storage limitation principle by deleting or archiving emails according to the guidance provided.
  • No email should remain in a mailbox longer than 2 years from the date sent or received.

6) Legal holds & investigations

Where litigation, an investigation, or a data subject request is received, Chill CIC may issue a legal hold. Users must preserve all relevant emails and suspend deletion until instructed otherwise.


7) Security

Users are responsible for:

  • Protecting mailbox access (e.g., strong passwords, MFA).
  • Ensuring archived data is stored securely and not exported to unauthorised systems.
  • Reporting suspected breaches or loss of access immediately.

8) Off-boarding

When a User leaves Chill CIC, they must:

  • Ensure all business-related emails are archived or transferred to a designated repository.
  • Understand that their mailbox may be closed after departure, with no guarantee of continued access.

9) Enforcement

Breach of these Terms may result in disciplinary or contractual action, and where applicable, reporting to the ICO.


10) Changes to these Terms

Chill CIC may update these Terms to reflect law, guidance or technical changes. Material changes will be communicated to Users.


11) Legal note

This policy is provided for compliance and governance. It does not replace legal advice. For specific cases, consult a solicitor.


Appendix — Email Retention & Archiving Schedule

Responsibility: Each individual User of an @chilluk.org mailbox is responsible for ensuring compliance with the below retention standards. Chill CIC provides the address but does not take responsibility for archiving, saving, or long-term storage of messages.

Contact data responsibility: Each User is responsible for reviewing and maintaining all saved contacts within their mailbox. Outdated or unnecessary contacts must be deleted, and personal data must not be retained beyond what is necessary for business purposes.


General principle

  • No email should be kept longer than 2 years from the date sent or received.
  • Users must regularly review their inbox, folders, and archives to ensure compliance.
  • Where an email must be retained for business or legal reasons, it should be moved to an approved archive location (not left indefinitely in the live mailbox).

Retention periods

CategoryExamplesMaximum retentionUser action
Routine correspondenceMeeting invites, updates, newsletters, informal notesDelete within 12 monthsDelete once no longer needed
General business communicationsProject updates, client enquiries, standard adminKeep max 2 yearsArchive or delete at 2-year mark
Contracts & agreements (and related emails)Negotiation, signed terms, variationsKeep max 2 years unless separately filed in official recordsMove copies to shared folder/approved archive
Finance & accounting supportInvoice emails, receipts, PO confirmationsKeep max 2 yearsExport or file with finance system, then delete
HR communicationsRecruitment, employment, volunteer adminKeep max 2 yearsFile in HR system if required, then delete
Sensitive personal dataMedical, safeguarding, personal circumstancesDelete as soon as processed; never exceed 2 yearsStore only where legally required and in secure archive
Leaver/role closureDeparting staff mailboxesMailbox closed immediately; all emails reviewed & archived within 1 month, then mailbox deletedUser (before leaving) must file/archive required emails

Additional rules

  • Legal hold: If a User is informed that certain emails must be preserved (e.g., investigation, SAR, litigation), the 2-year limit is temporarily suspended until the hold is lifted.
  • Personal copies prohibited: Users may not create personal, unencrypted archives (e.g., PST exports on a home device).
  • Shared responsibility: If more than one person uses a shared mailbox, the nominated mailbox owner is accountable for ensuring compliance.

Enforcement

Failure by Users to manage their inbox in line with these retention rules may:

  • Breach UK GDPR storage limitation principle.
  • Expose Chill CIC to regulatory or legal risk.
  • Lead to disciplinary or contractual action.

Isle of Man, Peel

Chill Isle of Man

Our mission is to enable and support more and more people to benefit from the many health benefits of cold-water immersion. 

Chill Southend

Based on Joscelyne’s beach, Chalkwell, we offer a welcoming, safe and supportive way to access all the health benefits of cold water immersion. 

Chill South Devon - Bigbury-on-sea

Chill South Devon

Chill South Devon enables people to benefit from the many health benefits of cold water immersion at some of the most stunning and restorative locations in the UK.

Cleethorpes Pier

Chill Nottingham and Lincolnshire

Chill Lincs and Notts CIC is an none for profit organisation. We offer a welcoming, supportive, and safe environment along the Lincolnshire coast.

Perthshire Tay

Chill Perthshire

CHILL Perthshire CIC, is a non profit organisation based in Crieff Perthshire. We provide CHILL courses in some of the most beautiful locations.

Chill Belhaven Beach, East Lothian

Chill East Lothian

Making the most of the beautiful beaches of East Lothian, we offer open water swimming courses to provide everyone with a safe and supportive way to access all the health benefits of cold water immersion.

Chill London

Chill London

Starting in June 2021 we are proud to be working with Olympic Open Water Swimming Medalist Keri-Anne Payne to deliver Chill courses to the NHS.

St Agnes

Chill St Agnes

Starting in June 2021 we are proud to be working with the Royal Cornwall Hospitals Trust to deliver Chill courses to the NHS

people on beach during daytime

Chill Brighton

Brighton chill has a decade of experience of offering open water swimming courses and our own dedicated swimming centre close to the beach

bournemouth beach, Chill

Chill Dorset

Chill Therapy Bournemouth is a not for profit organisation dedicated to providing sea swimming courses as a form of therapy for people with anxiety and depression

Chill Margate, East Kent

Chill East Kent

We use the surrounding area which boasts some of the UK’s best beaches with golden sand and chalk cliffs.

Chill CIC Devon

Chill North Devon

Chill started life here in North Devon and we’ve now run open water courses for over 200 people with lots more planned for this year

JOIN US IN THE OPEN WATER FOR SWIM SESSIONS TO NATURALLY HELP MANAGE ANXIETY AND DEPRESSION