← Governance Centre

GOV-007

Data Retention & Deletion Policy

This document forms part of the Governance Framework for been. It should be read alongside the accompanying governance documents, which collectively describe the ethical, legal, technical, and operational principles that guide the design, development, implementation, and ongoing stewardship of the Companion.

Document ID
GOV-007
Version
2.2
Status
Current
Document Steward
Doaa Samir Bazan
Approved By
Doaa Samir Bazan, Founder and Document Steward
Effective Date
11 September 2026
Next Review
Periodically, or earlier if required by legal, ethical, operational, technical, methodological, research, or material product developments.
Document Classification
Public
Applies To
All participants and users of been

This Data Retention & Deletion Policy forms part of the Governance Framework for been. It should be read alongside GOV-001 – Our Commitment, GOV-002 – Ethical Principles of been, GOV-003 – AI Transparency Statement, GOV-004 – Privacy Policy, GOV-005 – Terms & Conditions, GOV-006 – Safety & Crisis Policy, and the remaining governance documents.

Together, these documents explain how participant information is collected, managed, retained, protected, and responsibly disposed of throughout its lifecycle.

1. Purpose

Responsible stewardship of participant information extends beyond its collection and protection. It also includes making thoughtful decisions about how long information should be retained, when it should be deleted, and how it should be securely managed throughout its lifecycle.

The purpose of this policy is to explain how been retains, manages, deletes, de-identifies, and securely disposes of participant information in a manner that is consistent with its ethical commitments, operational needs, and legal responsibilities.

Information should be retained only for as long as there is a legitimate, transparent, and proportionate reason to do so. Once that purpose has been fulfilled, reasonable steps should be taken to securely delete, de-identify, anonymize, or otherwise dispose of the information in accordance with applicable legal, ethical, organizational, and technical requirements.

This policy supports the responsible operation, governance, security, and continuous development of the Companion while respecting participant autonomy, privacy, and trust.

2. Scope

This policy applies to all participant information collected, processed, or managed through been, including:

  • account information;
  • purchase, license-verification, redemption, and access-entitlement records;
  • authentication information;
  • conversation history;
  • Journal entries;
  • participant preferences;
  • technical information;
  • diagnostic information;
  • feedback and support communications;
  • research-related information where applicable; and
  • other participant information processed through the Companion.

The policy applies to participant information managed directly by been as well as information processed on behalf of the Companion by approved third-party service providers supporting its operation.

The principles described in this policy apply throughout the entire information lifecycle—from collection and active use to retention, deletion, de-identification, secure disposal, and, where applicable, archival for approved legal or research purposes.

3. Retention Principles

been is guided by the principles of data minimization, proportionality, purpose limitation, and responsible stewardship.

Participant information is retained only for as long as reasonably necessary to:

  • provide the Companion and its features;
  • create, maintain, and secure participant accounts;
  • verify license redemption, prevent duplicate use, maintain paid access, administer refunds or disputes, prevent fraud, and meet applicable legal or contractual recordkeeping obligations;
  • support conversation history and Journal functionality where those features are enabled;
  • maintain the quality, reliability, security, and safety of the service;
  • fulfil applicable legal, regulatory, contractual, or ethical obligations;
  • support approved research activities where an appropriate legal basis and, where required, participant consent have been established; and
  • protect the security, integrity, and responsible operation of the Companion.

Information is not retained indefinitely without a legitimate, transparent, and proportionate purpose.

Retention periods are determined by balancing participant privacy, operational needs, legal obligations, research integrity, and the ethical commitments described throughout the Governance Framework.

Whenever information is no longer required for the purpose for which it was collected, reasonable steps will be taken to securely delete, de-identify, anonymize, or otherwise dispose of it in accordance with this policy.

4. Categories of Information

Different categories of participant information may be retained for different periods depending on their purpose and the legal, ethical, operational, security, or research requirements that apply.

Categories of participant information may include:

  • account information;
  • purchase, license-verification, redemption, and access-entitlement records, including a hashed license reference, purchaser email received from the provider, product reference, verification and redemption dates, access start and end dates, and redemption status;
  • authentication information;
  • conversation history;
  • Journal entries;
  • participant preferences and settings;
  • technical logs;
  • diagnostic information;
  • feedback and support communications;
  • research-related information collected through approved studies; and
  • other participant information reasonably necessary for the operation of the Companion.

These purchase and access records may be retained only for as long as reasonably necessary to prevent duplicate redemption, maintain and evidence access, administer refunds or disputes, prevent fraud, and comply with applicable legal, regulatory, tax, accounting, or contractual obligations. The raw Payhip license key is not retained in been’s license-redemption record.

Voice recordings captured through the optional voice-to-text feature are processed transiently for the purpose of generating a text transcript and are not retained in been's database, conversation history, or Journal. The resulting transcript is presented to the participant for review and is not stored as conversation information unless the participant chooses to send it. Processing performed by the transcription service may be subject to the service provider's applicable data-handling and retention arrangements.

Retention periods are determined according to the nature of the information, the reason it was collected, the obligations associated with it, and the requirements of responsible governance.

Wherever reasonably possible, participant information that is no longer required in an identifiable form will be de-identified or anonymized before longer-term retention.

5. Participant Requests for Deletion

Participants may request deletion of their personal information in accordance with applicable laws, the Privacy Policy, and the rights described throughout the Governance Framework.

Upon receiving a valid request, been will make reasonable efforts to delete, de-identify, or anonymize the requested information unless continued retention is reasonably necessary to:

  • comply with legal or regulatory obligations;
  • fulfil contractual obligations;
  • resolve disputes or enforce legal rights;
  • maintain the security, integrity, or reliable operation of the Companion;
  • fulfil approved research obligations where continued retention is permitted by applicable law, ethical approval, and participant consent where required; or
  • protect the rights, safety, or privacy of participants or others.

This may include limited purchase, license-redemption, and access records where continued retention is reasonably necessary for legal or contractual recordkeeping, fraud prevention, dispute or refund handling, or to prevent a previously redeemed license from being used by another account. Any such retained information remains subject to the safeguards and proportionality requirements in this policy.

Where complete deletion cannot be carried out immediately or is not legally or ethically possible, participants will, where appropriate, be informed of the applicable limitations and the reasons for continued retention.

Deletion requests will be managed respectfully, transparently, and within a reasonable timeframe. The handling of participant requests should reflect the same commitments to autonomy, transparency, and responsible stewardship that guide every other aspect of the Companion.

6. Account Deletion

Participants may discontinue their use of been at any time and may request deletion of their account, subject to applicable legal, contractual, operational, and approved research obligations.

Where an account is deleted:

  • access to the account will be removed;
  • participant information associated with the account will be deleted, de-identified, or anonymized where reasonably practicable;
  • information that must be retained for legal, regulatory, security, fraud prevention, operational continuity, or approved research purposes may be retained only for the minimum period reasonably necessary; and
  • any information retained for these limited purposes will continue to be protected in accordance with the Governance Framework for been.

Deletion of an account does not automatically require the deletion of all associated information where retention is required by applicable law, ethical obligations, approved research requirements, or the secure operation of the Companion.

Where participant information cannot be immediately deleted, been will seek to limit its use to the specific purposes for which continued retention is justified.

Requesting account deletion does not affect a participant's rights under the Privacy Policy or applicable privacy legislation.

7. Backups and System Recovery

To support the reliability, security, continuity, and recovery of the Companion, certain participant information may be included within secure system backups where operationally necessary.

Backup copies are maintained solely for purposes such as:

  • operational recovery;
  • disaster recovery;
  • business continuity;
  • security;
  • system integrity; and
  • restoration following technical failures where appropriate.

Backup systems are not intended for routine participant access, ordinary service operation, or ongoing conversational interactions.

Where participant information has been deleted from active systems, residual copies may remain within secure backup systems until those backups are securely overwritten, expire in accordance with established retention schedules, or are otherwise securely deleted through normal operational processes.

Where reasonably practicable, deleted information will not be restored from backup systems except where necessary to maintain the security, integrity, or reliable operation of the Companion.

Reasonable efforts will be made to ensure that backup retention remains proportionate, secure, and consistent with applicable legal, ethical, operational, and security requirements.

The inclusion of participant information within secure backups does not change the commitments described throughout the Governance Framework regarding privacy, confidentiality, responsible stewardship, or participant rights.

8. Research Information After Study Completion

Where participant information has been collected as part of an approved research study, its retention, management, and eventual deletion will be carried out in accordance with:

  • the approved research protocol;
  • the Participant Information Sheet;
  • the Informed Consent Form;
  • applicable research ethics requirements;
  • relevant legal and institutional obligations; and
  • any additional requirements imposed by the approving ethics committee or research institution.

Where reasonably possible, research information will be de-identified or anonymized before long-term retention.

Research records may need to be retained for a specified period after study completion to support:

  • scientific integrity;
  • publication and peer review;
  • audit and verification processes;
  • regulatory or legal obligations;
  • institutional record-keeping requirements; and
  • responsible future evaluation of the methodology.

Retention of research information after study completion does not permit unrestricted future use. Any subsequent research use will remain subject to applicable ethical approvals, legal requirements, participant consent where required, and the commitments described throughout the Governance Framework.

The long-term retention of research records is intended to support scientific transparency, methodological integrity, and responsible scholarship while continuing to respect participant privacy and confidentiality.

9. Secure Disposal of Information

When participant information is no longer required for the purposes for which it was collected, been will take reasonable steps to securely delete, de-identify, anonymize, or otherwise dispose of that information using methods appropriate to the type of information being managed.

The objective of secure disposal is to reduce the risk of unauthorized access, disclosure, recovery, misuse, or unintended future processing after participant information is no longer required.

Secure disposal practices are selected according to the nature of the information, the systems in which it is stored, applicable legal and regulatory requirements, recognized security standards, and the operational needs of the Companion.

Where participant information has been de-identified or anonymized for legitimate research or governance purposes, reasonable steps will be taken to minimize the risk of re-identification.

Disposal practices will continue to evolve alongside developments in technology, recognized security standards, privacy practices, and applicable legal or ethical requirements.

Responsible disposal of participant information is regarded as an essential part of the information lifecycle. Protecting participant information includes not only collecting and storing it responsibly, but also ensuring that it is no longer retained or recoverable once there is no legitimate reason for it to remain.

10. Policy Review

This Data Retention & Deletion Policy will be reviewed regularly as part of the ongoing Governance Framework for been.

Reviews may be undertaken in response to:

  • changes in applicable privacy or data protection legislation;
  • technological developments;
  • operational improvements;
  • advances in information governance practices;
  • research findings;
  • participant feedback;
  • security recommendations;
  • updates to related governance documents; or
  • other developments affecting the responsible management of participant information.

Where revisions are made, updated versions will include a revised version number and effective date. Where changes materially affect participant rights, retention practices, or the management of participant information, reasonable efforts will be made to communicate those changes transparently.

The purpose of ongoing review is not simply to update the policy, but to ensure that information management continues to reflect the ethical commitments, governance principles, and responsible stewardship upon which been is built.

Conclusion

Responsible stewardship of participant information extends throughout its entire lifecycle. It includes making thoughtful decisions not only about how information is collected and protected, but also about how long it is retained, when it should be deleted, and how it should be securely disposed of once it is no longer required.

This policy reflects been's commitment to data minimization, proportionality, transparency, accountability, and respect for participant autonomy. By retaining participant information only where there is a legitimate, transparent, and ethically justified purpose, and by disposing of it responsibly when that purpose has been fulfilled, been seeks to maintain the trust placed in it by every participant.

Responsible information management is not viewed solely as a technical or legal obligation. It is an ethical commitment that supports participant dignity, responsible artificial intelligence, trustworthy research, and the long-term integrity of the Companion.

As been continues to evolve, every decision relating to the retention and deletion of participant information should strengthen—not weaken—the Companion's commitment to privacy, responsible stewardship, and transparent governance.

Related Documents

This document should be read alongside: