LEGAL

Data retention & deletion.

Last updated: 9 August 2026. How long each category of data is kept, why, and how deletion works.

Controller TMMA SRLS
Review cycle Annual
Last updated 9 August 2026

1. Principles

Personal data is kept only for as long as it is needed for the purpose it was collected for, or for as long as a legal obligation requires. When a period ends, data is deleted or irreversibly anonymised.

Where MessageMind acts as processor, the customer sets the retention period within the limits below and may instruct deletion at any time. Where we act as controller, the periods below apply directly.

2. Retention schedule

Data categoryRetention periodWhy
Account, contract and billing records10 yearsItalian accounting and tax law (art. 2220 Civil Code) requires retention of accounting records.
Conversation content (default)24 months (configurable down to 30 days)Service delivery, conversation history and dispute handling. Customers can set a shorter period per workspace.
Guest / end-user messages from connected booking or travel platforms12 monthsLimited to what is needed to answer, evidence and resolve the stay. Shorter than the platform default because the reservation itself is the system of record.
Reservation records from connected booking or travel platforms24 monthsDispute, chargeback and complaint windows. Limited to booking reference, dates, guest name and status.
Voice recordings and transcripts12 monthsQuality assurance and dispute evidence. Deleted earlier where the customer disables recording.
Knowledge-base content supplied by the customerLife of the accountRequired for the agent to answer. Deleted when the customer removes it or closes the account.
Support tickets and correspondence24 monthsFollow-up on recurring issues and contractual evidence.
Security, access and audit logs12 monthsSecurity monitoring, incident investigation and accountability under Article 32 GDPR.
Website analytics events14 monthsMeasurement window for campaign and funnel analysis.
Marketing contacts and prospect dataUntil objection, or 24 months of inactivityLegitimate interest in B2B outreach, ended immediately on objection.
Encrypted backupsRolling 35 daysDisaster recovery. Backups are rotated and overwritten on a fixed cycle.

3. Connected booking and travel platforms

Data received through a connected booking or travel platform is subject to a stricter schedule than the general default, because the platform itself remains the system of record for the reservation.

  • Guest message content is retained for 12 months from the last message, then deleted.
  • Reservation records are limited to booking reference, stay dates, guest name and status, and retained for 24 months from checkout to cover dispute, chargeback and complaint windows.
  • Guest contact details obtained through a platform are used only to service that stay. They are not added to marketing audiences and are not retained for outreach.
  • Disconnecting the integration triggers deletion of the associated platform data within 30 days, except where a legal obligation requires longer.

A customer may set shorter periods, or request immediate deletion of specific reservations or conversations, by writing to [email protected].

4. Deletion on termination and on request

When an account closes, the customer has 30 days to export their data. After that window we delete or anonymise customer data within 90 days, except records we must keep by law.

Deletion requests received while the account is active are actioned without undue delay and in any case within 30 days. Where we act as processor we forward end-user requests to the customer and assist them in responding.

Backups are encrypted and rotated on a rolling 35-day cycle. Data deleted from live systems persists in backups until that cycle completes, after which it is overwritten. Backups are never used to restore individually deleted records.

5. Contact

Retention questions, deletion requests and vendor security reviews: [email protected]. TMMA SRLS, Via Durazzo 28, 00195 Roma (RM), Italy.