# WiBiz Data Retention and Disposal Summary

**Version:** v1.0  
**Published:** 6 August 2026  
**Owner:** WiBiz Data Protection  
**Classification:** Public  
**Status:** Current public summary

## 1. Purpose

This summary explains how WiBiz sets retention, return, export, deletion, backup handling, legal holds, and disposal evidence. There is no one period that safely applies to every data category, client, product, jurisdiction, and provider.

## 2. Retention design

Each applicable build identifies:

- the data category, source, purpose, owner, and legal role;
- the retention trigger and active-service period;
- contractual, statutory, dispute, tax, security, and operational needs;
- production, log, backup, export, analytics, and provider copies;
- client export and transition needs;
- deletion method, timing, provider dependency, and verification evidence;
- legal-hold authority and release;
- exception, approver, deadline, and next review.

## 3. Data minimisation and review

Data that is no longer required for a documented purpose must be deleted, anonymised, or placed under an approved legal hold. Material changes to purpose, service, provider, region, or law trigger a review of the retention schedule.

## 4. Termination and deletion

The applicable contract and Build Security and Data Annex define return, export, production deletion, backup handling, provider deletion, legal holds, transition assistance, and available deletion evidence. Public summaries do not create a universal deletion promise that conflicts with a signed or legally required schedule.

## 5. Evidence boundary

A deletion claim requires a dated, scoped record for the named system and data. A policy statement or task completion is not evidence that every provider copy, backup, or log was deleted.

## 6. Contact

Data-protection enquiries: dpo@wibiz.ai

---

WiBiz Data Retention and Disposal Summary v1.0, 6 August 2026.
