bindro.

Privacy

How long we keep things, and how to have yours removed

Every window below is the number the software actually runs on. A background job enforces each one on a schedule; none of this depends on anybody remembering.

WhatKept forWhat happens, and why
Personal answers and attendee identities 24 months Measured from the last event that address attended, not from the booking — a returning attendee keeps their history until they stop coming. Name, email and answers are then removed and the booking record is kept without them.
Health-classed answers 12 months A shorter window than anything else on this page, for the class of answer that never leaves the platform and is never sent to an AI model.
Registrations for someone under 18 Until asked No timer runs on a minor’s registration. The window that would apply depends on when they reach majority, which we would have to keep a date of birth to calculate — so instead these are kept until you or their guardian ask, from the booking’s own privacy page, and then erased like any other. Guardian names and addresses are held the same way.
Operational logs (requests, errors, timings) 30 days Deleted outright. Each record holds a request id, method, route pattern, status, duration and error code — never a request body, a header, a query string, an email address or a registration answer.
Financial and audit records Retained Orders, payments, ledger entries and the audit trail are kept for as long as the law requires them for accounting and dispute resolution. The audit trail is append-only: it cannot be edited or deleted, which is what makes it worth anything.

Doing it yourself, from your booking

Open the link in your confirmation email — your booking page carries a “Your data and your rights” link, and that page (/order/your-booking/privacy) shows everything that booking’s organiser holds about you and gives you the four things you are entitled to: read it, download a copy, correct it, or erase it. The signed link in that email is what proves it is you, which is why we cannot offer the same buttons on this page.

Anything the buttons do not cover goes on the record from the same page, and we answer it within 30 days. Each organiser answers for the bookings you made with them; they are separate, and so are their records.

Erasure and deletion requests

You can also ask us to delete your details before the window above runs out. Email privacy@bindro.io from the address you booked with, or from any address if you tell us which booking you mean.

An attendee identity is tombstoned rather than deleted: your name, email address and answers are removed and the booking row stays behind without them. That is not a hedge — the row carries the order, its ledger entries and its attendance count, and deleting it would make the organiser's accounts for that event wrong. What is destroyed is everything that identifies you.

Three boundaries, stated plainly rather than left for you to discover. The contact address on the order is part of the sale record and is kept with the financial records above, because a receipt, a refund and a chargeback all need it. The append-only audit trail records that an erasure happened, by whom and why — it does not keep a copy of what was erased. And a request you make is itself recorded, with your address and its deadline, because that record is how we can show your request was answered on time; it holds the address and the dates, never your answers.

Data we never collect and never send anywhere

Health-classed answers are never sent to an AI model. Registration answers never reach an operational log: the logger works from a fixed list of seven permitted fields and drops everything else, so a field a new event type adds tomorrow is excluded by default rather than by somebody noticing.