Skip to content

Legal

Data Retention & Deletion Policy

Effective 25 September 2026 · Maintained by MetaEdx Inc · Reviewed at least every 6 months

1. Principles

We keep personal and financial data only as long as needed to provide SoftBillo, meet legal duties, and resolve disputes — in line with UK GDPR, EU GDPR, and applicable US state privacy laws (including the CCPA/CPRA) and Gramm-Leach-Bliley Act expectations for consumer financial data.

2. Retention schedule

DataKeptDeletion
Bank access keys (Plaid, GoCardless, Mono)Until you disconnect the bankDeleted immediately on disconnect; access also revoked with the provider.
Bank accounts and transactionsWhile the bank is connectedDeleted automatically 30 days after disconnect. Transactions you confirmed as matched to an invoice or expense stay with that record.
Invoices, payments and accounting recordsWhile your account is activeUp to 7 years where tax and accounting law requires it; otherwise deleted with your account.
Account and other business dataWhile your account is active30 days after cancellation (for export or reactivation), then deleted or anonymised.
BackupsRollingDeleted data is purged from backups within 90 days.
Security and audit logs12 monthsDeleted automatically afterwards.
Support correspondence24 monthsDeleted afterwards.

3. How deletion happens

4. Review

This policy and our Privacy Policy are reviewed at least every six months, and whenever we add a data source or provider. Each review is logged with the reviewer and date. Material changes are announced at least 30 days in advance.