All policies

Legal

Data Retention & Deletion Policy

BEEVELOPE

DATA RETENTION & DELETION POLICY

Effective Date: 5 September 2026

1. Purpose

This Data Retention & Deletion Policy (”Policy”) establishes the principles governing the retention, deletion, anonymisation and disposal of data processed by BEEVELOPE (”Company”, “we”, “us or “our”).

The Policy is intended to ensure that data is retained only for as long as reasonably necessary for the purposes for which it is processed, or as required or permitted by Applicable Laws.

2. Scope

This Policy applies to data processed by BEEVELOPE in connection with:

(a) User Accounts;

(b) Customer Data;

(c) email and contact information;

(d) campaign and communication data;

(e) AI Inputs and Outputs;

(f) analytics and usage information;

(g) technical and security logs;

(h) support records;

(i) billing and transaction records;

(j) suppression and opt-out records; and

(k) backups and disaster-recovery copies.

3. Retention Principles

BEEVELOPE shall seek to ensure that:

(a) data is retained only for a legitimate business, contractual, legal, security or regulatory purpose;

(b) retention periods are proportionate to the purpose of Processing;

(c) data is deleted or anonymised when it is no longer required;

(d) longer retention is permitted only where required or reasonably necessary for legitimate purposes;

(e) access to retained data is appropriately restricted; and

(f) applicable Data Subject rights and contractual obligations are respected.

4. Categories of Data and Retention

Unless a different period is required by Applicable Laws, contractual obligations or legitimate business requirements, BEEVELOPE may retain data as follows:

Data CategoryPurposeRetention Principle
Account InformationAccount administration and ServicesFor the duration of the Account and thereafter as reasonably necessary
Customer DataProviding the ServicesDuring the applicable Customer relationship and thereafter in accordance with the DPA
Contact/Recipient DataEmail marketing and campaign functionalityFor as long as necessary for the Customer’s Services, subject to Customer instructions
Campaign DataCampaign management, reporting and analyticsFor the period reasonably necessary for the Services
AI Inputs/OutputsProviding AI functionalityFor the period reasonably necessary for the relevant functionality, subject to applicable contractual arrangements
Usage & Analytics DataSecurity, analytics and Service improvementFor the period reasonably necessary for those purposes
Security & Technical LogsSecurity, troubleshooting and incident investigationFor the period reasonably necessary for those purposes or as required by law
Billing RecordsBilling, accounting and legal complianceFor the applicable statutory/legal retention period
Support RecordsCustomer support and dispute resolutionFor the period reasonably necessary for those purposes
Suppression/Opt-Out DataPreventing further unwanted communicationsFor as long as reasonably necessary to honour the applicable opt-out
BackupsBusiness continuity and disaster recoveryIn accordance with applicable backup cycles

The specific retention periods for individual data categories may be maintained in the Company’s internal retention schedule.

5. Customer Data

5.1Customer Data shall be retained and deleted in accordance with:

(a) the Customer’s documented instructions;

(b) the applicable Terms of Use;

(c) the Data Processing Agreement; and

(d) Applicable Data Protection Laws.

5.2Where BEEVELOPE acts as a Processor, it shall not retain Customer Data for purposes inconsistent with the Customer’s documented instructions or the applicable contractual arrangements.

6. Account Closure and Termination

6.1Following termination or closure of a Customer Account, BEEVELOPE shall, subject to the applicable agreement and Applicable Laws:

(a) provide an appropriate opportunity for Customer Data to be exported, where technically and commercially applicable;

(b) return or delete Customer Data in accordance with the DPA;

(c) delete or anonymise data that is no longer required; and

(d) retain limited information where required or reasonably necessary for legal, security, fraud-prevention or dispute-resolution purposes.

6.2Any applicable post-termination data retention period shall not be interpreted as continuing the Customer’s right to use the Services.

7. Deletion Requests

7.1Where a valid deletion request is received, BEEVELOPE shall assess and process the request in accordance with:

(a) Applicable Data Protection Laws;

(b) the Company’s Privacy Policy;

(c) the Customer’s instructions, where applicable; and

(d) contractual obligations.

7.2Deletion may not be immediate where retention is:

(a) required by law;

(b) necessary to establish, exercise or defend legal claims;

(c) necessary for security or fraud prevention;

(d) required to maintain a suppression record;

(e) necessary to comply with a regulatory requirement; or

(f) otherwise permitted by Applicable Laws.

8. Suppression and Opt-Out Records

8.1BEEVELOPE or its Customers may retain limited information relating to an unsubscribe, opt-out, complaint or suppression request where reasonably necessary to ensure that the individual does not receive further unwanted marketing communications.

8.2Such information shall be used only for legitimate suppression, compliance, security or related purposes and shall not be used to resume marketing communications contrary to the applicable individual’s request.

9. Backups

9.1Data contained in backups may remain temporarily available after deletion from active systems.

9.2Backup copies shall remain subject to appropriate security controls and shall not ordinarily be restored or actively processed except for:

(a) disaster recovery;

(b) business continuity;

(c) security investigation; or

(d) other legitimate purposes.

9.3Backup copies shall be deleted or overwritten in accordance with the Company’s applicable backup-retention cycle.

10. Legal and Regulatory Retention

BEEVELOPE may retain information for longer than ordinary operational periods where reasonably necessary to:

(a) comply with applicable law;

(b) comply with regulatory requirements;

(c) respond to lawful governmental requests;

(d) maintain accounting or tax records;

(e) establish, exercise or defend legal claims;

(f) investigate fraud or abuse; or

(g) maintain necessary security records.

Such information shall remain subject to appropriate access restrictions and shall not be used for unrelated purposes.

11. Anonymisation

Where deletion is not operationally necessary and the Company can effectively anonymise information so that it can no longer reasonably identify an individual, BEEVELOPE may retain and use such anonymised information for legitimate purposes, including:

(a) analytics;

(b) statistical analysis;

(c) Service improvement;

(d) security analysis; and

(e) product development.

Anonymised information shall no longer be treated as Personal Data to the extent that it is genuinely and irreversibly anonymised under Applicable Laws.

12. Employee and Internal Data

Employee and contractor information shall be retained in accordance with applicable employment, legal, security and business requirements and the Company’s internal retention schedule.

13. Access and Security During Retention

Data retained under this Policy shall remain subject to appropriate technical and organisational safeguards, including, where applicable:

(a) access controls;

(b) authentication;

(c) encryption;

(d) logging;

(e) monitoring; and

(f) appropriate segregation.

Retention of data does not create an unrestricted right of access to such data.

14. Periodic Review

The Company may periodically review its retention practices to determine whether particular categories of data continue to serve a legitimate purpose.

Where data is no longer required, the Company shall seek to delete, anonymise or otherwise appropriately dispose of it.

15. Responsibility for Retention

Where BEEVELOPE acts as a Processor, the Customer remains responsible for determining the appropriate retention period for Customer Data, subject to the technical capabilities and contractual arrangements of the Services.

BEEVELOPE shall provide reasonable functionality or assistance for deletion and retention management where required under the applicable agreement or Applicable Laws.

16. Relationship with Other Documents

This Policy shall be read together with:

(a) the Privacy Policy;

(b) the Terms of Use;

(c) the Data Processing Agreement;

(d) the Cookie Policy; and

(e) other applicable policies and contractual documents.

Where a specific contractual or statutory retention obligation applies, that obligation shall prevail to the extent of any inconsistency.

17. Changes to this Policy

The Company may amend this Policy from time to time to reflect:

(a) changes in the Services;

(b) changes in data-processing practices;

(c) changes in Applicable Laws;

(d) changes in regulatory requirements;

(e) technological developments; or

(f) changes in retention practices.

The updated version shall indicate the applicable “Last Updated” date.

18. Contact

Questions concerning this Policy or requests relating to retention or deletion may be submitted through the privacy or support contact details specified in the Privacy Policy or on the BEEVELOPE Platform.

ANNEXURE A

DATA RETENTION SCHEDULE

The Company should maintain an internal schedule identifying the actual retention period applicable to each category of data.

Data TypeRetention PeriodDeletion / Disposal MethodResponsible Function
Account & User DataDuration of account + 90 days after terminationHard delete from databaseEngineering
Customer DataDuration of account; deleted/returned within 60 days of termination (after export window)Delete from database + blob storageEngineering
Contact / Recipient DataSame as Customer Data; deletable by the customer at any timeDelete from databaseEngineering / Customer
Campaign Data + reports/analyticsDuration of account; deleted within 60 days of terminationDelete from databaseEngineering
AI Inputs / OutputsTied to the related contact/campaign; deleted with the account (within 60 days)Delete from databaseEngineering
Usage & Analytics Data24 months (rolling), then deleted or anonymisedPurge / anonymiseEngineering / Product
Security & Technical Logs12 monthsRotate / purgeEngineering
Billing & Financial Records7-8 years (statutory - confirm local law)Delete after statutory periodFinance
Customer Support Records24 months after resolutionPurge from support inbox/toolSupport / Ops
Suppression / Opt-Out RecordsRetained indefinitely to honour opt-outs (minimal data only)Not deletedEngineering / Compliance
Backups & Disaster Recovery~30-35 day rolling backup cycleOverwritten per backup cycleEngineering / Ops