← Governance Centre

GOV-007

Data Retention & Deletion Policy

This document forms part of the Governance Framework for been. It should be read alongside the other governance documents, which collectively describe the ethical, legal, technical, and operational principles that guide the design, development, and ongoing stewardship of the Companion.

Document ID
GOV-007
Version
1.0
Status
Pilot Draft
Document Steward
been Governance Framework
Approved By
Doaa Samir Bazan, Founder and Document Steward
Effective Date
30/7/2026
Next Review
Annually, or earlier if required by legal, ethical, operational, or research developments.

1. Purpose

The purpose of this policy is to explain how been retains, deletes, and manages participant information throughout its lifecycle.

Responsible information management includes not only collecting and protecting information appropriately but also ensuring that it is not retained longer than necessary. This policy describes the principles that guide retention, deletion, anonymization, and disposal of participant information while supporting the safe operation, governance, and responsible development of the Companion.

2. Scope

This policy applies to all participant information collected through been, including account information, conversation history, journal entries, technical information, support communications, feedback, and research-related information where applicable.

It applies to information managed directly by been as well as information processed through approved third-party service providers that support the operation of the Companion.

3. Retention Principles

been is guided by the principles of data minimization, proportionality, and responsible stewardship. Participant information is retained only for as long as reasonably necessary to:

  • provide the Companion and its features;
  • maintain participant accounts;
  • support journals and conversation history where those features are enabled;
  • improve the quality, reliability, and safety of the service;
  • fulfil legal or regulatory obligations;
  • support approved research activities where appropriate consent has been obtained; and
  • protect the security and integrity of the platform.

Information is not retained indefinitely without a legitimate purpose.

4. Categories of Information

Different categories of information may be retained for different periods depending on their purpose.

These categories may include:

  • account information;
  • authentication information;
  • conversation history;
  • journal entries;
  • participant preferences;
  • technical logs;
  • diagnostic information;
  • feedback and support communications; and
  • research information collected with appropriate participant consent.

The specific retention period for each category may vary according to operational, legal, ethical, security, or research requirements.

5. Participant Requests for Deletion

Participants may request deletion of their personal information in accordance with applicable laws and the Privacy Policy.

Where deletion is requested, been will make reasonable efforts to delete, anonymize, or de-identify the requested information unless retention is required to:

  • comply with legal obligations;
  • resolve disputes;
  • maintain platform security;
  • fulfil approved research obligations where consent and applicable regulations permit continued retention; or
  • protect the integrity of the service.

Where complete deletion is not immediately possible, participants will be informed of any applicable limitations where appropriate.

6. Account Deletion

Participants may choose to discontinue their use of been and request deletion of their account, subject to applicable legal, contractual, and research obligations.

Where an account is deleted:

  • access to the account will be removed;
  • personal information associated with the account will be deleted, anonymized, or de-identified where reasonably practicable;
  • information that must be retained for legal, security, fraud prevention, or approved research purposes may be retained for the minimum period necessary; and
  • information retained for these limited purposes will continue to be protected in accordance with the Governance Framework for been.

Deletion of an account does not automatically require the deletion of information that must legally or ethically be retained.

7. Backups and System Recovery

To support the reliability, security, and continuity of the Companion, certain information may be included in secure system backups where appropriate.

Backup copies are maintained solely for operational recovery, disaster recovery, security, and system integrity purposes. They are not intended to be used for routine access or ongoing participant interactions.

Where information has been deleted from active systems, residual copies may remain within secure backup systems until those backups are overwritten or securely deleted according to established operational procedures.

Reasonable efforts will be made to ensure that backup retention remains proportionate and consistent with applicable legal, ethical, and security requirements.

8. Research Information After Study Completion

Where participant information has been collected as part of an approved research study, retention and deletion will be managed in accordance with:

  • the approved research protocol;
  • the Participant Information Sheet;
  • the Informed Consent Form;
  • applicable research ethics requirements; and
  • relevant legal and institutional obligations.

Where possible, research information will be anonymized or de-identified before long-term retention.

Research records may need to be retained for a specified period after study completion to support scientific integrity, publication requirements, audit processes, regulatory obligations, or institutional requirements.

9. Secure Disposal of Information

When participant information is no longer required, been will take reasonable steps to securely delete, anonymize, or otherwise dispose of that information using methods appropriate to the type of information being managed.

The objective of secure disposal is to reduce the risk of unauthorized access, disclosure, recovery, or misuse after information is no longer required.

Disposal practices will continue to evolve alongside changes in technology, recognized security standards, and applicable legal requirements.

10. Policy Review

This Data Retention & Deletion Policy will be reviewed regularly as part of the ongoing Governance Framework for been.

Reviews may occur in response to:

  • changes in applicable privacy legislation;
  • technological developments;
  • operational improvements;
  • research findings;
  • participant feedback;
  • security recommendations; or
  • updates to related governance documents.

Where revisions are made, updated versions will include a revised version number and effective date.

Conclusion

Responsible stewardship of participant information extends beyond its collection and protection. It also includes making thoughtful decisions about how long information is retained, when it should be deleted, and how it should be securely managed throughout its lifecycle.

This policy reflects been's commitment to data minimization, transparency, and respect for participant autonomy. By retaining information only where there is a legitimate, transparent, and ethically justified purpose, and by disposing of it responsibly when that purpose has been fulfilled, been seeks to uphold the trust placed in it by every participant.

These commitments are intended not only to support responsible information management but also to uphold the ethical principles upon which the Companion has been designed, governed, and continuously refined.

Related Documents

This document should be read alongside: