MEMRY CORPORATION LIMITED

MEMO DATA RETENTION & DELETION POLICY

Version: 1.0

Effective Date: 20/07/2026

  1. Purpose

This Data Retention & Deletion Policy (“Policy”) explains how Memry Corporation Limited (“Memry”, “we”, “our” or “us”) retains, archives and securely deletes information processed through the Memo platform.

Its purpose is to:

  • comply with applicable data protection legislation;
  • protect the privacy of our users;
  • ensure information is retained only for as long as reasonably necessary;
  • support continuity of care where appropriate;
  • maintain appropriate records for legal, regulatory and security purposes.

This Policy forms part of the Memo Legal Framework and should be read together with the:

  • Privacy Notice
  • Terms of Use
  • Memry Vault Privacy Policy
  • Information Security Policy
  • Data Processing Agreement (where applicable)
  1. Our Retention Principles

Memry is committed to retaining personal information only for as long as necessary to:

  • provide the Service;
  • fulfil contractual obligations;
  • comply with legal or regulatory requirements;
  • protect the rights and interests of users;
  • maintain system security;
  • resolve disputes;
  • establish, exercise or defend legal claims.

When information is no longer required, it will be securely deleted, anonymised or archived in accordance with this Policy.

  1. Categories of Information

Depending on how Memo is used, we may retain information including:

  • account details;
  • contact information;
  • user preferences;
  • reminders and routines;
  • wellbeing information;
  • messages;
  • Memry Vault content;
  • audit logs;
  • system logs;
  • billing records;
  • support requests;
  • consent records;
  • authority verification records;
  • safeguarding records;
  • security records.

Different categories of information may be retained for different periods.

  1. Retention Schedule

Unless a longer retention period is required by law, regulation or contractual obligation, Memry will normally apply the following retention periods.

Information Category

Typical Retention Period

Account registration information

While the account remains active and up to 24 months after closure

Subscription and billing records

Minimum of 7 years where required for accounting and tax purposes

User preferences and settings

While the account remains active

Reminder schedules and routines

While the account remains active

Messages between authorised users

Until deleted by users or up to 24 months after account closure unless otherwise required

Memry Vault content

Until removed by the user or authorised representative, or following account closure and expiry of the recovery period

Audit logs

Normally up to 7 years where required for security, governance or regulatory purposes

Security logs

Normally up to 24 months unless required for investigation

Consent and authority records

Normally up to 7 years after authority ends where reasonably necessary

Customer support enquiries

Normally up to 3 years after resolution

Safeguarding records

As long as reasonably necessary to comply with legal obligations or protect legitimate interests

Anonymised analytical information

May be retained indefinitely as it no longer identifies individuals

These periods may be amended where legislation, regulatory guidance or contractual requirements change.

  1. Account Closure

Users may request closure of their Memo account at any time, subject to any legal or contractual restrictions.

Following account closure:

  • access to the Service will normally cease;
  • subscriptions will end in accordance with the Subscription Terms;
  • information will enter the retention and deletion process;
  • certain information may be retained where required by law or legitimate business purposes.

Closure of an account does not necessarily result in immediate deletion of all associated information.

  1. Recovery Period

Following account closure, Memry may maintain account information for a limited recovery period to:

  • allow recovery where closure occurred in error;
  • support authorised reinstatement requests;
  • protect against fraud;
  • resolve billing or contractual issues.

Unless otherwise required, the standard recovery period will normally be 30 days.

After the recovery period expires, information will proceed to permanent deletion or archival in accordance with this Policy.

  1. Deletion of Information

Where deletion is appropriate, Memry will take reasonable steps to securely remove personal information from active systems.

Deletion methods may include:

  • secure erasure;
  • cryptographic deletion;
  • irreversible anonymisation;
  • secure destruction of storage media where appropriate.

Deletion may occur in stages across different systems.

  1. Memry Vault Content

Users retain ownership of information stored within the Memry Vault.

Authorised users may remove individual items at any time, subject to applicable permissions.

Following account closure:

  • Vault content will normally remain available during the recovery period;
  • after that period it will normally be permanently deleted unless retention is required by law or another authorised arrangement applies.

Legacy arrangements, memorial accounts or other agreed services may be governed by separate terms.

  1. Backup Retention

To support resilience and disaster recovery, information may remain within secure encrypted backup systems after deletion from active systems.

Backup copies:

  • are retained only for operational resilience;
  • are protected by appropriate security measures;
  • are not ordinarily accessible for routine operational use;
  • are overwritten or securely deleted in accordance with backup lifecycle management.

The presence of information within encrypted backups does not mean it remains actively available.

  1. Legal Holds

Where required, Memry may suspend deletion of information.

Examples include:

  • actual or anticipated legal proceedings;
  • court orders;
  • regulatory investigations;
  • law enforcement requests;
  • safeguarding investigations;
  • fraud investigations;
  • contractual disputes.

Information subject to a legal hold will be retained only for as long as reasonably necessary.

  1. Archiving

Certain information may be transferred from active systems into secure archives where continued retention is justified.

Archived information may be retained for purposes including:

  • legal compliance;
  • audit requirements;
  • safeguarding;
  • business continuity;
  • regulatory obligations.

Archived information will be subject to appropriate access controls and security measures.

  1. Organisational Customers

Where Memo is used by NHS organisations, local authorities, care providers or other organisations, retention periods may be governed by:

  • contractual agreements;
  • organisational information governance policies;
  • NHS Records Management Code of Practice;
  • applicable legislation.

Where different requirements apply, the relevant contractual arrangements will take precedence.

  1. User Rights

Subject to applicable law, users may request:

  • access to their information;
  • correction of inaccurate information;
  • deletion of certain information;
  • restriction of processing;
  • portability where applicable.

Some requests may be limited where Memry is legally required or entitled to retain information.

Further information is provided in the Privacy Notice.

  1. Security During Retention

Information retained by Memry remains protected by appropriate technical and organisational measures, including:

  • encryption;
  • authentication controls;
  • role-based access;
  • audit logging;
  • monitoring;
  • secure hosting;
  • regular security reviews.
  1. Review of Retention Periods

Retention periods are reviewed periodically to ensure they remain:

  • proportionate;
  • legally compliant;
  • operationally appropriate;
  • consistent with recognised information governance standards.

Where appropriate, retention schedules may be updated without affecting users’ statutory rights.

  1. Changes to this Policy

Memry may amend this Policy to reflect changes in legislation, regulatory guidance, technology or operational requirements.

Material changes will be communicated through the Service or by other appropriate means.

  1. Contact

Questions regarding this Policy or requests relating to data retention or deletion should be directed to:

Memry Corporation Limited

Privacy & Information Governance Team

Email: Team@Memry.io

Website: www.Memry.io

Registered Office: The Towers Building, 6 Brincliffe Crescent, Sheffield, S119AW UK

 

Compassionate digital companionship for dementia care, supporting families with dignity and NHS-approved resources.

Quick Links

Support

Contact Us

© 2024 The Memry Project. All rights reserved. NHS Digital Health Partner.