Skip to main contentSkip to main content
Immediate danger? Call Triple Zero (000). My Mind Is Ok is not monitored as a crisis service. Find urgent support
My Mind Is Ok
Menu

Legal & governance · Policy version 2026.09.1

Data Retention and Deletion Summary

How long different records are kept and how deletion requests are handled.

Effective 6 September 2026Australian servicePlain-language policy
Important: These policies preserve rights that cannot legally be excluded. They do not make MMIO a clinical or emergency service.

Retention principle

MMIO keeps information only for as long as it is reasonably needed for the purpose collected, a legal requirement, security, dispute resolution or a documented governance need. “Keep everything forever” is not a legal-defence strategy; unnecessary retention can increase privacy and cyber risk.

Indicative public schedule

RecordIndicative periodReason
Active account and entitlement dataWhile active, then a limited closure periodProvide access, resolve billing and support reactivation or deletion.
Tax, invoice and transaction recordsAt least the statutory tax/accounting periodTax, accounting, chargeback and consumer obligations.
Checkout policy acceptance evidenceNormally 7 years, subject to adviser reviewContract evidence and likely limitation periods.
Support ticketsNormally 2 years after closureService quality and repeat issue resolution; longer if linked to a complaint or claim.
Complaints, safety incidents and legal disputesNormally 7 years after closure, or longer under a legal holdAccountability, trend review, insurance and claims.
Security and access logsNormally 90 days to 12 months depending on purpose and riskAttack detection, investigation and reliability.
BackupsRolling limited cycleRecovery; deleted records may persist until protected backups expire.
Marketing consent and unsubscribe recordsWhile relevant and for a reasonable evidence periodRespect preferences and demonstrate compliance.
Browser-local private writingUntil the user or browser deletes itControlled by the device; MMIO cannot delete text it never receives.

The internal schedule identifies exact owners and periods after the operator receives legal, tax and insurance advice. Statutory periods vary by record and structure; this summary is not a promise to delete information where retention is required.

Deletion requests

Send requests to support@mymindisok.com. We will verify identity proportionately and identify information held by MMIO. We may refuse or defer deletion where law requires retention, a transaction record must be kept, a dispute or investigation is active, security would be compromised, or the information has already been irreversibly de-identified.

We will explain a refusal or limitation. Deletion from active systems may not instantly remove a record from immutable or protected backups, but the record will age out under the backup cycle and will not be restored to ordinary use unless recovery is necessary.

Legal holds

When litigation, a complaint, regulator inquiry, insurance claim or security incident is reasonably anticipated, relevant deletion may be paused. A legal hold must be scoped, documented, access-controlled and released when no longer needed.

Minimisation

Support staff should avoid copying sensitive information into multiple systems. Product analytics should not contain private writing. De-identified aggregate information may be retained where re-identification risk has been assessed and the information is no longer personal information.

Contact and version

support@mymindisok.com · Policy version 2026.09.1, effective 6 September 2026.