Comiine
Legal

Comiine Data Retention and Deletion Policy

How long we keep data, how you delete your account, and what happens to records your employer controls.

Last updated
29 August 2026
Version
1.0

This policy explains how long Comiine keeps personal information, how you delete your account and your data, and what happens to records your employer controls.

Comiine is operated by Millyjoy & Co (Proprietary) Limited, company registration BW00009256082, of Plot 7414, Mogoditshane, Botswana. It gives effect to the storage limitation principle in the Botswana Data Protection Act, 2024 (Act No. 18 of 2024), which says personal data must not be kept longer than the purpose needs.

This policy was prepared in-house and has not yet been reviewed by a legal practitioner admitted in Botswana.

Two roles, two answers. Where Comiine is the controller, being account data, diagnostics and our own product measurement, the periods below are our own and we apply them. Where Comiine is the processor for a customer organisation's operational and workforce records, the customer sets the retention period as controller, and the periods below are our defaults when the customer has given no instruction.


1. How to delete your account and your data

You do not need to be logged in to make this request.

Option A: in the app

Open Comiine and go to More, then Privacy and Consent, then Delete My Data. Confirm the request. It runs immediately.

Option B: by email

Email privacy@comiine.com from the address on your account, or from any address if you tell us which account you mean. Write "Delete my account" in the subject line. We may need to verify your identity before we act. We will confirm in writing when it is done.

We complete an in-app request within minutes. We complete an emailed request as soon as we can and, in any event, within 30 days of verifying who you are.

What gets deleted

When you delete your account, we do the following straight away:

  • your sign-in account is deleted, so you can no longer log in. If a database reference prevents outright deletion, the account is stripped of all personal details and permanently blocked, which has the same practical effect;
  • your name, email address, phone number, profile photo, job title, pay rate, skills, notification preferences and any custom fields are overwritten on your user record, which is then marked deleted and inactive;
  • your device push registrations are deleted;
  • any pending invitation carrying your email address is deleted;
  • notifications addressed to you personally are deleted; and
  • if you also clear the app, the local copy of data on that device is wiped.

We keep a record that a deletion request was made and completed. That record is our evidence that we honoured your rights, and it is kept for that purpose.

What is kept, and why

We cannot delete your employer's records, and you should know that before you ask.

Work orders, inspections, safety sign-offs, signed records, audit log entries, photographs and attachments belong to the organisation that keeps them in Comiine. That organisation is the controller of those records, not you and not us. Deleting your Comiine account does not delete them. Many of them are records your employer must keep in order to meet mining and occupational health and safety duties, and some of them are the tamper-evident audit trail that proves who signed off what.

What we do instead is remove you from them. After erasure, every one of those records points at an anonymous, person-shaped record labelled "Deleted user". Your name, email address and contact details are gone from our systems. The work history remains, unattributed.

If you want your employer's records about you changed or removed, ask your employer. If you ask us, we will pass the request to them without undue delay and tell you that we have.

One thing that can block a deletion

If you are the only administrator of your organisation, we will refuse the request and explain why. Erasing the sole administrator would leave the organisation with nobody able to manage it, restore access or export its data. Promote another administrator first, then repeat the request.

Your employer can also erase an account

An administrator of your organisation can erase an account in that organisation. The same rules apply: personal details are erased, organisation records remain.

2. Retention schedule

DataWho decidesHow long we keep it
Account and identity data (name, work email, organisation, role, credentials)Comiine, as controllerWhile the account is open, and for 90 days after it is closed, then deleted or anonymised. If you ask us to erase it, we act on the request rather than waiting for the 90 days
Service and access logs (connection metadata, IP addresses, timestamps)Comiine, as controllerThese sit in our hosting providers' service logs and are deleted on those providers' own log retention cycles. We do not keep a separate long-term access log
Customer operational data (work orders, assets, readings, downtime, inventory, purchasing)The customer organisation, as controllerFor the term of the customer agreement, as the customer instructs. On termination, the customer can export for 30 days, and we return or delete within 90 days of termination
Safety and audit records (signed inspections, lock-out tag-out, job safety analysis, work order signatures, prestart and daily checks)The customer organisation, as controllerWe do not set a period for these. They are the customer's records and the customer decides, including any minimum period that mining or occupational health and safety law places on it. We keep them for the term of the customer agreement and then return or delete them on the customer's instruction. We do not represent that keeping a record in Comiine satisfies any statutory record-keeping duty
Photographs and attachmentsFollows the record they belong toThe same period as the work order, inspection or record they are attached to
Digital signatures and audit ledger entriesThe customer organisation, as controllerKept with the record they sign. Once signed off, these are frozen and cannot be altered, which is what makes them worth having
Crash and error diagnosticsComiine, as controllerOnly as long as we need them to diagnose and fix the problem, then deleted on our error monitoring provider's retention cycle. Crash reporting is off unless you switch it on, and switching it off stops any further collection
Product usage eventsBoth. The customer for its adoption view, Comiine for product measurement24 months, then deleted automatically by a monthly job that runs in our database. Statistics aggregated from them that identify nobody may be kept longer
Support correspondenceComiine, as controller24 months from the last message in the conversation
Contracts, invoices and accounting recordsComiine, as controllerFor as long as Botswana tax and company law requires us to keep them, and no longer than necessary after that
BackupsBothBackups run on a rolling cycle. Deleted data ages out of existing backups as that cycle turns

3. How deletion actually works

We would rather tell you the mechanics than imply something cleaner than the truth.

Deletion is a two-step process on the server. A record is first marked deleted and disappears from view everywhere in the product, then it is removed from the live database.

Backups are not edited. When something is deleted from the live system it stays inside backups that were already taken, until those backups age out on the ordinary cycle. We do not go into a historic backup to erase a single record, and we do not restore a backup in order to bring deleted personal data back.

Devices catch up when they sync. Comiine works offline, so each device holds a working copy of the data. A deletion made on the server, or by someone else, disappears from a given device the moment that device next synchronises. Until then a local copy can still exist on that device. Clearing the app data or wiping the device removes it immediately. This is a property of every offline-first product, and we would rather say it than pretend deletion is instant everywhere at once.

4. Requests about data your employer controls

If your request is about operational or workforce records where your employer is the controller, email privacy@comiine.com and we will forward it to your employer without undue delay, and confirm to you that we have done so. Your employer decides the outcome. We will help them action it.

If we are required by law, or reasonably need to, in order to establish, exercise or defend a legal claim, we may keep specific data beyond the periods above. Where that happens and it affects you, we will tell you what we are keeping and why, unless the law prevents us.

6. Review

We review this policy at least once a year, and whenever the Act, our processing, or our sub-processors change.

7. Contact

Data protection contact: privacy@comiine.com Millyjoy & Co (Proprietary) Limited trading as Comiine, Plot 7414, Mogoditshane, Botswana. Company registration BW00009256082.