Retention principle
MMIO keeps information only for as long as it is reasonably needed for the purpose collected, a legal requirement, security, dispute resolution or a documented governance need. “Keep everything forever” is not a legal-defence strategy; unnecessary retention can increase privacy and cyber risk.
Indicative public schedule
| Record | Indicative period | Reason |
|---|---|---|
| Active account and entitlement data | While active, then a limited closure period | Provide access, resolve billing and support reactivation or deletion. |
| Tax, invoice and transaction records | At least the statutory tax/accounting period | Tax, accounting, chargeback and consumer obligations. |
| Checkout policy acceptance evidence | Normally 7 years, subject to adviser review | Contract evidence and likely limitation periods. |
| Support tickets | Normally 2 years after closure | Service quality and repeat issue resolution; longer if linked to a complaint or claim. |
| Complaints, safety incidents and legal disputes | Normally 7 years after closure, or longer under a legal hold | Accountability, trend review, insurance and claims. |
| Security and access logs | Normally 90 days to 12 months depending on purpose and risk | Attack detection, investigation and reliability. |
| Backups | Rolling limited cycle | Recovery; deleted records may persist until protected backups expire. |
| Marketing consent and unsubscribe records | While relevant and for a reasonable evidence period | Respect preferences and demonstrate compliance. |
| Browser-local private writing | Until the user or browser deletes it | Controlled by the device; MMIO cannot delete text it never receives. |
The internal schedule identifies exact owners and periods after the operator receives legal, tax and insurance advice. Statutory periods vary by record and structure; this summary is not a promise to delete information where retention is required.
Deletion requests
Send requests to support@mymindisok.com. We will verify identity proportionately and identify information held by MMIO. We may refuse or defer deletion where law requires retention, a transaction record must be kept, a dispute or investigation is active, security would be compromised, or the information has already been irreversibly de-identified.
We will explain a refusal or limitation. Deletion from active systems may not instantly remove a record from immutable or protected backups, but the record will age out under the backup cycle and will not be restored to ordinary use unless recovery is necessary.
Legal holds
When litigation, a complaint, regulator inquiry, insurance claim or security incident is reasonably anticipated, relevant deletion may be paused. A legal hold must be scoped, documented, access-controlled and released when no longer needed.
Minimisation
Support staff should avoid copying sensitive information into multiple systems. Product analytics should not contain private writing. De-identified aggregate information may be retained where re-identification risk has been assessed and the information is no longer personal information.
Contact and version
support@mymindisok.com · Policy version 2026.09.1, effective 6 September 2026.
