MEMRY CORPORATION LIMITED
MEMO DATA RETENTION & DELETION POLICY
Version: 1.0
Effective Date: 20/07/2026
- Purpose
This Data Retention & Deletion Policy (“Policy”) explains how Memry Corporation Limited (“Memry”, “we”, “our” or “us”) retains, archives and securely deletes information processed through the Memo platform.
Its purpose is to:
- comply with applicable data protection legislation;
- protect the privacy of our users;
- ensure information is retained only for as long as reasonably necessary;
- support continuity of care where appropriate;
- maintain appropriate records for legal, regulatory and security purposes.
This Policy forms part of the Memo Legal Framework and should be read together with the:
- Privacy Notice
- Terms of Use
- Memry Vault Privacy Policy
- Information Security Policy
- Data Processing Agreement (where applicable)
- Our Retention Principles
Memry is committed to retaining personal information only for as long as necessary to:
- provide the Service;
- fulfil contractual obligations;
- comply with legal or regulatory requirements;
- protect the rights and interests of users;
- maintain system security;
- resolve disputes;
- establish, exercise or defend legal claims.
When information is no longer required, it will be securely deleted, anonymised or archived in accordance with this Policy.
- Categories of Information
Depending on how Memo is used, we may retain information including:
- account details;
- contact information;
- user preferences;
- reminders and routines;
- wellbeing information;
- messages;
- Memry Vault content;
- audit logs;
- system logs;
- billing records;
- support requests;
- consent records;
- authority verification records;
- safeguarding records;
- security records.
Different categories of information may be retained for different periods.
- Retention Schedule
Unless a longer retention period is required by law, regulation or contractual obligation, Memry will normally apply the following retention periods.
Information Category | Typical Retention Period |
Account registration information | While the account remains active and up to 24 months after closure |
Subscription and billing records | Minimum of 7 years where required for accounting and tax purposes |
User preferences and settings | While the account remains active |
Reminder schedules and routines | While the account remains active |
Messages between authorised users | Until deleted by users or up to 24 months after account closure unless otherwise required |
Memry Vault content | Until removed by the user or authorised representative, or following account closure and expiry of the recovery period |
Audit logs | Normally up to 7 years where required for security, governance or regulatory purposes |
Security logs | Normally up to 24 months unless required for investigation |
Consent and authority records | Normally up to 7 years after authority ends where reasonably necessary |
Customer support enquiries | Normally up to 3 years after resolution |
Safeguarding records | As long as reasonably necessary to comply with legal obligations or protect legitimate interests |
Anonymised analytical information | May be retained indefinitely as it no longer identifies individuals |
These periods may be amended where legislation, regulatory guidance or contractual requirements change.
- Account Closure
Users may request closure of their Memo account at any time, subject to any legal or contractual restrictions.
Following account closure:
- access to the Service will normally cease;
- subscriptions will end in accordance with the Subscription Terms;
- information will enter the retention and deletion process;
- certain information may be retained where required by law or legitimate business purposes.
Closure of an account does not necessarily result in immediate deletion of all associated information.
- Recovery Period
Following account closure, Memry may maintain account information for a limited recovery period to:
- allow recovery where closure occurred in error;
- support authorised reinstatement requests;
- protect against fraud;
- resolve billing or contractual issues.
Unless otherwise required, the standard recovery period will normally be 30 days.
After the recovery period expires, information will proceed to permanent deletion or archival in accordance with this Policy.
- Deletion of Information
Where deletion is appropriate, Memry will take reasonable steps to securely remove personal information from active systems.
Deletion methods may include:
- secure erasure;
- cryptographic deletion;
- irreversible anonymisation;
- secure destruction of storage media where appropriate.
Deletion may occur in stages across different systems.
- Memry Vault Content
Users retain ownership of information stored within the Memry Vault.
Authorised users may remove individual items at any time, subject to applicable permissions.
Following account closure:
- Vault content will normally remain available during the recovery period;
- after that period it will normally be permanently deleted unless retention is required by law or another authorised arrangement applies.
Legacy arrangements, memorial accounts or other agreed services may be governed by separate terms.
- Backup Retention
To support resilience and disaster recovery, information may remain within secure encrypted backup systems after deletion from active systems.
Backup copies:
- are retained only for operational resilience;
- are protected by appropriate security measures;
- are not ordinarily accessible for routine operational use;
- are overwritten or securely deleted in accordance with backup lifecycle management.
The presence of information within encrypted backups does not mean it remains actively available.
- Legal Holds
Where required, Memry may suspend deletion of information.
Examples include:
- actual or anticipated legal proceedings;
- court orders;
- regulatory investigations;
- law enforcement requests;
- safeguarding investigations;
- fraud investigations;
- contractual disputes.
Information subject to a legal hold will be retained only for as long as reasonably necessary.
- Archiving
Certain information may be transferred from active systems into secure archives where continued retention is justified.
Archived information may be retained for purposes including:
- legal compliance;
- audit requirements;
- safeguarding;
- business continuity;
- regulatory obligations.
Archived information will be subject to appropriate access controls and security measures.
- Organisational Customers
Where Memo is used by NHS organisations, local authorities, care providers or other organisations, retention periods may be governed by:
- contractual agreements;
- organisational information governance policies;
- NHS Records Management Code of Practice;
- applicable legislation.
Where different requirements apply, the relevant contractual arrangements will take precedence.
- User Rights
Subject to applicable law, users may request:
- access to their information;
- correction of inaccurate information;
- deletion of certain information;
- restriction of processing;
- portability where applicable.
Some requests may be limited where Memry is legally required or entitled to retain information.
Further information is provided in the Privacy Notice.
- Security During Retention
Information retained by Memry remains protected by appropriate technical and organisational measures, including:
- encryption;
- authentication controls;
- role-based access;
- audit logging;
- monitoring;
- secure hosting;
- regular security reviews.
- Review of Retention Periods
Retention periods are reviewed periodically to ensure they remain:
- proportionate;
- legally compliant;
- operationally appropriate;
- consistent with recognised information governance standards.
Where appropriate, retention schedules may be updated without affecting users’ statutory rights.
- Changes to this Policy
Memry may amend this Policy to reflect changes in legislation, regulatory guidance, technology or operational requirements.
Material changes will be communicated through the Service or by other appropriate means.
- Contact
Questions regarding this Policy or requests relating to data retention or deletion should be directed to:
Memry Corporation Limited
Privacy & Information Governance Team
Email: Team@Memry.io
Website: www.Memry.io
Registered Office: The Towers Building, 6 Brincliffe Crescent, Sheffield, S119AW UK

Compassionate digital companionship for dementia care, supporting families with dignity and NHS-approved resources.
- Made with care in the UK
Quick Links
- How It Works
- Features
- Pricing
- NHS Integration
- Family Resources
Support
- Help Centre
- Carer Guides
- Privacy Policy
- Terms of Service
- GDPR Compliance
Contact Us
- 07429 744007
- support@memry.io
© 2024 The Memry Project. All rights reserved. NHS Digital Health Partner.
- GDPR Compliant
- NHS Approved
- ISO 27001