Data Retention & Deletion Overview

Aleverum retains information only for as long as reasonably necessary to provide and secure its services, maintain auditability, meet contractual and legal obligations, resolve disputes and support legitimate product-record and Digital Product Passport requirements.

This is a public overview. Specific retention periods may be stated in an Order Form, Data Processing Agreement, product configuration or internal retention schedule.

1. Retention principles

  • Purpose limitation: retain information for defined business, contractual, security, legal or product-governance purposes;
  • Data minimisation: avoid retaining personal information or duplicate records longer than necessary;
  • Auditability: preserve records needed to demonstrate authorised changes, review outcomes and evidence history;
  • Security: maintain logs and incident records for detection, investigation and protection;
  • Contractual control: apply customer-specific retention or deletion commitments where agreed;
  • Legal preservation: suspend deletion where records are subject to a legal hold, investigation, dispute or mandatory retention obligation;
  • DPP persistence: account for product-specific obligations that may require long-term availability of Digital Product Passport information.

2. General Retention Categories

Category Public Retention Approach
Website enquiries and business contacts Retained while the relationship or enquiry remains active and for a reasonable follow up and record keeping period.
Customer accounts and administration Retained during the customer relationship and for a reasonable period afterwards for contract, billing, security and dispute purposes.
Platform activity and security logs Retained for security, troubleshooting, audit and investigation purposes according to risk and technical capability.
Product, supplier, evidence and verification records Retained according to customer instructions, contractual requirements, workflow status and any applicable product or Digital Product Passport persistence obligations.
Support communications Retained while required to resolve issues, maintain service history and manage disputes or security matters.
Backups Deleted or overwritten through scheduled backup cycles, subject to technical feasibility, legal holds and disaster recovery requirements.
Marketing preferences Retained as needed to honour opt outs and manage lawful communications.

3. Deletion and de-identification

When information is no longer required, Aleverum may delete, anonymise or de-identify it, subject to technical constraints, backups, legal obligations, security records and agreed Digital Product Passport persistence requirements.

Deletion from active systems may not immediately remove information from encrypted backups. Backup copies are ordinarily isolated from normal use and are overwritten according to the applicable backup cycle unless restoration is required.

4. Customer requests and termination

Customer export, return and deletion rights are governed by the Platform Terms and applicable Order Form or Data Processing Agreement. Customers should request export before the end of any agreed retrieval period.

5. Personal information requests

Individuals may request access or correction, and in some circumstances deletion or restriction, subject to applicable law and Aleverum’s role. Requests should be sent to privacy@aleverum.com. Where Aleverum acts only on a customer’s instructions, the request may need to be directed to that customer.

6. Changes and contact

This overview may be updated as legal obligations, platform capabilities and product-specific DPP requirements evolve.

Privacy and retention enquiries: privacy@aleverum.com

Effective date: August 6, 2026 | Last updated: August 6, 2026

Scroll to Top