How to delete your personal data from the Menovia Health & Safety platform, and what is deleted or kept.
Menovia is a business-to-business health & safety compliance platform, published by Menovia. This page explains how a user of the Menovia app can request that their personal data is deleted, what happens to that data, and how long any retained data is kept.
Delete some of your data (keep your account)
You can remove individual pieces of your personal data yourself without deleting your account. Signed in to the app:
- Open My Profile.
- Remove your profile photo or CV using the delete control on each.
- Clear editable fields - mobile number, date of birth, job title, home address, next-of-kin details - and save.
Delete your whole account
- Open My Profile (or Settings) and choose Delete My Account.
- Confirm. Your sign-in access is revoked immediately and your personal data is deleted as described below.
If you cannot sign in, or want written confirmation
Email privacy@menovia.co.uk from the address associated with your account and ask us to delete your data. We will action verified requests and can provide written confirmation on request. Because Menovia is used on behalf of your organisation (the data controller), some requests may be coordinated with your organisation's administrator.
What is deleted
On account deletion we scrub your personal data from your account record and from file storage, including:
- Name, email address, mobile number, date of birth
- Job title, start date, home address, next-of-kin details
- Profile photo and CV - removed from file storage on a best-effort basis, so a file may briefly outlive the account if storage is temporarily unavailable
- Notification preferences
- Your sign-in identity link is severed, permanently revoking access
What is kept, and why
Menovia is a compliance product. Some data is retained where deleting it would destroy a legally required health & safety record, or the evidence that something was agreed or acknowledged. These are retained under Article 17(3) UK GDPR - (b) compliance with a legal obligation, and (e) establishment, exercise or defence of legal claims.
- Health & safety records, tasks and activity you contributed are retained in anonymised form as part of your organisation's compliance history. Where such a record holds none of the identity snapshots listed below, once anonymised it no longer identifies you.
- Audit trail entries keep the name you acted under at the time of each recorded action - the tamper-evident record of who did what.
- Terms-acceptance records keep the name, email address, IP address and browser details captured when you accepted the end-user terms, as evidence of that acceptance.
- Document acknowledgements keep the name you acknowledged a document under, together with any typed initials and any signature you drew. Signature images are not deleted - they are the acknowledgement evidence itself.
- Attendance records - for example a toolbox talk or training sign-in sheet - keep your name as captured on the sheet, and the name of whoever recorded the attendance.
- Meeting attendee records keep the name you were recorded under as having attended a health & safety meeting.
- Document authorship and invitation records keep the display name of the person who created a document or sent an invitation, together with the invitation's dates, as provenance. Invitations addressed to you are cancelled so they can no longer be used; the record itself is kept.
If you delete your own account using the in-app option above, your email address and sign-in identifier are also removed from invitation records. If your deletion is actioned by an administrator on your behalf, invitation records keep the invited address as part of your organisation's record of who was invited and by whom. Email privacy@menovia.co.uk if you want those removed too.
Retention periods
- Your account: personal data is deleted or anonymised at the point you delete your account, or when we action a verified request.
- Whole-organisation termination: customer personal data is deleted within 90 days of the service agreement ending, unless retention is required by law.
- Audit trail entries are kept for a further 12 months after the service agreement ends, so that we can answer compliance enquiries and resolve any dispute about what was recorded.
- Backups: encrypted database backups are naturally purged as their retention window expires, within up to 35 days.
For full detail see our Platform Privacy Policy (sections 8 and 9).
