This page explains how to request deletion of your Menovia platform account
and the personal data associated with it. It applies to the Menovia mobile app
(com.menovia.mobile) and the Menovia web application, both operated
by Menovia Ltd.
1. Deleting your account from within the app
The quickest route is in the app itself:
- Open the Menovia mobile app and sign in.
- Go to Profile.
- Select Delete My Account and confirm.
Your access is revoked immediately.
2. Requesting deletion without using the app
If you cannot sign in, no longer have the app installed, or would rather not use the in-app option, email privacy@menovia.co.uk with the subject line Account deletion request.
Please include the email address associated with your Menovia account, and the name of the organisation or consultancy you belong to. We may need to verify your identity before acting, so that we do not delete an account at someone else's request.
We aim to acknowledge requests within 5 working days and to complete them within one month, in line with UK GDPR.
3. What happens when your account is deleted
We want to be straightforward about this, because "delete" does not mean the same thing in every product.
Menovia is a health and safety compliance system. The records you contribute - inspections, incident reports, training records, signed acknowledgements - are your employer's or client's statutory compliance history, and they are often legally required to keep them. So rather than erasing everything, we anonymise your personal data in place.
Removed
- Your name, email address, and the sign-in identifier linking the account to you - scrubbed from your account. This permanently severs your ability to sign in.
- Your email address and sign-in identifier on account invitation records - those addressed to you, sent by you, or that you used to join - when you delete your own account using the in-app option in section 1. If your deletion is actioned by an administrator on your behalf, invitation records keep the invited address as part of your organisation's record of who was invited and by whom. Email privacy@menovia.co.uk if you want those removed too.
- Your profile details: mobile number, date of birth, job title, start date, home address, next-of-kin details, and notification preferences.
- Your profile photo and any CV you uploaded, removed from file storage on a best-effort basis. Signature images you drew when acknowledging a document are not removed - they form part of the acknowledgement evidence described below.
- Your role assignments and site assignments are revoked, and any pending invitations addressed to you are revoked so they can no longer be used.
Retained, and why
- Health and safety records you contributed are kept in anonymised form. Where such a record carries no identity snapshot of the kind listed below, once anonymised it no longer identifies you.
- Audit trail entries keep the name you acted under at the time of each recorded action. The audit trail is a tamper-evident record of who did what, and rewriting it would destroy its evidential value.
- Terms acceptance records keep the name and email address you accepted the End-User Terms under, together with the IP address and browser details captured at that moment, as evidence that you accepted them.
- Document acknowledgement records keep the name you acknowledged a document under, together with any typed initials and any drawn signature image captured as part of the acknowledgement, as evidence that the document was acknowledged by you.
- Attendance records (for example, a toolbox talk or training session sheet) keep your name as captured on the sheet, and the name of the person who captured the attendance.
- Meeting attendee records keep the name you were recorded under, as part of your organisation's record of who attended a health and safety meeting.
- Document authorship and invitation records keep the display name of the person who created a document or sent an invitation, together with the invitation's lifecycle timestamps, as provenance. The invitation record itself is kept rather than deleted, marked as cancelled; what is removed from it depends on how your account was deleted, as set out under "Removed".
These records are retained under Article 17(3)(b) UK GDPR (compliance with a legal obligation) and Article 17(3)(e) (establishment, exercise or defence of legal claims).
4. How long anything retained is kept
- Identity, organisational, task and attachment data: for the duration of the customer's service agreement, plus 90 days.
- Audit log entries: for the duration of the service agreement, plus 12 months.
- Encrypted database backups: up to 35 days, after which they age out of the backup window.
5. Deleting specific data without closing your account
You can ask us to correct or delete particular items without deleting your whole account. Email privacy@menovia.co.uk describing what you would like removed.
One thing to be aware of: for most records held in Menovia, your employer or the consultancy managing your organisation is the data controller, and Menovia acts as their data processor. Where that is the case we will pass your request to them and support them in acting on it, rather than deciding on our own. If you know who your Menovia administrator is, contacting them directly is usually faster.
6. Contact
- Email: privacy@menovia.co.uk
- Data protection contact: Nathaniel Waterworth, Technical Director, Menovia Ltd
- Post: Menovia Ltd, United Kingdom
For more detail on how we handle personal data, see our Platform Privacy Policy.
