Account Deletion Policy
Reading note. This Policy describes the deletion lifecycle as implemented. Where the intended 30-day automated deletion is not yet wired, it is flagged; the deletion request, deactivation, hiding, session revocation, grace window, anonymisation, and restoration are all implemented.
1. Purpose
Purpose. To explain how you delete your Tirvea account, what happens to your data when you do, how long anything is kept, and how you can restore an account during the grace window. WiseWave Limited is the Data Controller.
2. Scope
Purpose. To state what this Policy covers. It covers voluntary account deletion and the related deactivation, anonymisation, and permanent-deletion steps. It does not cover enforcement removals (bans), which are governed by the Account Suspension Policy (/legal/account-suspension), although both end in deletion of personal data as described here.
3. Definitions
Purpose. To define deletion terms. Data-protection terms are defined in the Privacy Policy (/legal/privacy).
- "Deactivation" / "soft deletion" - a reversible state in which the account is hidden and scheduled for deletion during a grace window.
- "Anonymisation" - irreversibly removing or de-identifying personal data.
- "Tombstone" - an anonymised account shell that remains after anonymisation, pending final cleanup.
- "Permanent deletion" - removal of the tombstone shell so no account record remains.
4. Deletion Types
Purpose. To describe the deletion states. Tirvea uses three:
- Soft deletion (deactivation): on a deletion request, the account is deactivated, hidden, and sessions are revoked, during a grace window in which it can be restored (§7, §17).
- Anonymisation and tombstoning: personal data is anonymised and the account is reduced to a tombstone shell, and the email is freed for re-registration (§9).
- Permanent deletion: the tombstone shell is removed (§10).
5. How to Request Deletion
Purpose. To explain how to delete your account. A signed-in member can request deletion from their privacy settings. On request, the account is deactivated and scheduled for deletion (§8). This is your right to erasure under the GDPR (GDPR & Your Rights, /legal/gdpr).
6. Identity Verification
Purpose. To protect your account from wrongful deletion. A deletion request requires you to be signed in (session-authenticated), so only the account holder can request deletion. Requests made by other means are verified before we act (GDPR & Your Rights §14, /legal/gdpr).
7. Grace Period
Purpose. To give you time to change your mind. After a deletion request, there is a 30-day grace window. During this window your profile is hidden and your account is inactive, but it can be restored by signing in (§17). If you do not restore it, the account proceeds to anonymisation and deletion.
8. What Happens on a Deletion Request
Purpose. To explain the immediate effects. When you request deletion, we: set your account to a deactivated state; record the deletion-request time; hide your profile immediately so you are not shown to others; and revoke all your sessions, signing you out. The request is recorded in audited records.
9. Anonymisation and Tombstoning
Purpose. To explain how personal data is removed. When deletion is finalised, a teardown routine anonymises your personal data, reduces the account to an anonymised tombstone shell (a tombstone identifier, no personal profile data), and frees your email so you can register again in future. Identifiers used for security are held only as salted hashes, which are removed with the account.
10. Permanent Deletion
Purpose. To explain final deletion. At the end of the 30-day grace window, a daily scheduled cleanup job automatically erases any account whose deletion request is older than 30 days and that was not restored by signing in. This is enforced by a timer, not only by an authentication-identity deletion (§11). The job permanently erases your personal data - profile, photos, messages (subject to legal/safety holds), device records, notifications, settings, and identity/photo-verification records - deletes your biometric face reference at our provider (an AWS Rekognition DeleteFaces call), purges your stored images, and removes your login identity. The account row is then an anonymised tombstone that contains no personal data (§9). This is consistent with the Data Retention Policy (/legal/data-retention): erasure completes within 30 days of your deletion request.
11. Immediate Deletion
Purpose. To explain when personal data is anonymised immediately. Anonymisation and tombstoning happen immediately when the account's authentication identity is deleted (for example, through the authentication provider or the auth webhook) or is freed for a new registration. In those cases personal data is anonymised and the email is freed right away.
12. Retention Exceptions
Purpose. To explain what may be kept after deletion. Some records are retained after deletion where the law or a legal hold requires, or for safety and fraud-prevention reasons. These exceptions and their periods are set out in the Data Retention Policy (/legal/data-retention); this Policy does not redefine them. Retained records are held for no longer than necessary.
13. Legal Holds
Purpose. To explain holds that suspend deletion. Where data must be preserved for a legal obligation, a valid legal request, or a safety or child-safety reason, it is placed on a legal hold and retained beyond the normal period, for no longer than the hold requires. Legal holds are currently a manual, organisational process; there is no dedicated legal-hold system (an implementation gap). Cooperation with authorities is described in the Law Enforcement Guidelines (/legal/law-enforcement). [Legal review required before publication - confirm legal-hold obligations and process.]
14. Fraud Prevention
Purpose. To explain deletion in the context of abuse. Deletion frees your identity so you can re-register. It does not remove enforcement against banned accounts: a banned account is not restored by signing in, and ban-evasion signals used to prevent a banned person from returning are handled separately, as described in the Account Suspension Policy (/legal/account-suspension). Limited records may be retained for fraud prevention per the Data Retention Policy (/legal/data-retention).
15. Moderation and Safety Records
Purpose. To explain retention of safety records after deletion. Moderation outcomes, cases, and violation records may be retained after account deletion as long as necessary to enforce our rules, handle appeals, and meet legal obligations, as set out in the Data Retention Policy (/legal/data-retention) and Trust & Safety Policy (/legal/trust-safety). Such records are minimised and, where practicable, hold no directly identifying data.
16. Backups
Purpose. To explain deletion and backups. Backups are managed by our infrastructure providers on their own cycles; deleted data expires from backups as those cycles roll over. Tirvea does not operate a separate backup archive or a defined backup-retention schedule (an implementation gap). [Legal review required before publication - confirm and document the provider backup-retention cycle.]
17. Restoration
Purpose. To explain how to restore an account. During the 30-day grace window, you can restore a deactivated account by signing in; this returns the account to active and clears the deletion request. After anonymisation and tombstoning, the account cannot be restored; you may register a new account. A banned account cannot be restored by signing in (§14); enforcement is challenged through the Appeals Policy (/legal/appeals).
18. Appeals
Purpose. To explain how to challenge a deletion-related decision. Voluntary deletion is your choice and is not an enforcement action, so it is not appealed. Enforcement removals (bans) are appealable under the Appeals Policy (/legal/appeals). If you believe your account was deleted in error, contact us at info@tirvea.com.
19. Data Subject Rights
Purpose. To connect deletion to your rights. Deletion is how you exercise your right to erasure; your other rights (access, rectification, portability, and the rest) are explained in GDPR & Your Rights (/legal/gdpr). Before deletion, you can export your data (GDPR & Your Rights §10, /legal/gdpr).
20. Security
Purpose. To confirm deletion is handled securely. Deletion, anonymisation, and any retained records are handled under the safeguards in the Security Policy (/legal/security) and Privacy Policy (/legal/privacy). Sessions are revoked on a deletion request so the account cannot be used while deactivated.
21. Updates
Purpose. To explain how this Policy changes. We update this Policy to reflect changes in our practices or the law - including when we wire the scheduled deletion job so the 30-day commitment is automatically enforced. We update the "Last Updated" date and, for material changes, take reasonable steps to communicate them.
22. Contact
Purpose. To tell you how to reach us about deletion.
- Data Controller: WiseWave Limited (Company Number 762171)
- Registered office: 39 Cooley Park, Dundalk, Co. Louth, A91 AP2V, Ireland
- Email: info@tirvea.com
For your rights, see GDPR & Your Rights (/legal/gdpr); for retention periods, the Data Retention Policy (/legal/data-retention).