Thanks sbillard, you're always quick and helpful.
That being said, the apache user must be able to control those files, so by not allowing delete by the apache user it shouldn't be able to delete the files, am I right? I think I can control that using ACLs "deny delete", if the apache user can follow those. Anybody know for sure?