You have the right to request erasure of your personal data under UK GDPR (Article 17). This right is not absolute. Because Updraft is a regulated financial services firm, we must retain some records for legal and regulatory reasons even after your account is closed.
What we can delete or stop now
Close your account (if your loan balance is £0).
Stop marketing: remove you from all marketing and promotional emails, SMS and in-app offers.
Unlink Open Banking: revoke any active Open Banking permissions and tokens.
Restrict processing: move your records to secure archival so they are not used for day-to-day operations.
What we must keep (and why)
We are required to retain core records for defined periods, for example:
Anti-money laundering (AML) records: typically up to 5 years after the business relationship ends (Money Laundering Regulations 2017).
Contract, complaint and accounting records: typically up to 6 years after the relationship ends (statutory limitation and regulatory oversight).
During these periods your data is held securely and used only to meet legal, regulatory, audit or dispute-handling obligations. If there is an open dispute or investigation, we may need to retain relevant data until it is resolved.
After the retention period
Once the applicable retention period expires, we will securely and permanently delete your personal data from our live and archived systems.
Important points to be aware of
Credit reference files: We cannot edit or delete information held by credit reference agencies on your behalf. If you believe something on your file is inaccurate, you should raise a dispute with the agency directly.
Open Banking consent: We connect via TrueLayer. You can revoke consent in the Updraft app and via your bank’s own “Connected apps” settings.
Marketing vs. deletion: Even if we must retain certain records, you will remain off all marketing lists. We maintain a suppression list to ensure you are not re-added.
How to make a deletion request
To formally close your account and request the eventual deletion of your data in line with this process, please send an email to our Data Protection Officer.
Email: dataofficer@updraft.com
What to include: Please make the request from the email address associated with your Updraft account and include your full name and date of birth so we can securely identify you.
We want to assure you that during the retention period, your data is held with the highest level of security and will not be used for any purpose other than to meet our legal and regulatory obligations.
