Data Deletion Policy
Updated 11 August 2026You can ask us to close your account and delete the personal data we hold about you. This policy explains what you can request, how to request it, what happens, and the limited cases where we may need to keep some information. It forms part of, and should be read with, our Privacy Policy and Terms & Conditions.
Who is responsible
The Joint Operations App is operated by Joint Operations Ltd (company number 11817255), registered office Unit 11 Bincknoll Lane, Royal Wootton Bassett, Swindon, England, SN4 8SY. We are the data controller for your personal data and are registered with the UK Information Commissioner’s Office (ICO). Our data-protection contact is support@jointoperations.co.uk.
What you can ask us to delete
You can request closure of your account and erasure of the personal data associated with it, including your profile details (name, workplace, role, areas and product interests), your preferences, your AI interactions, and your messages and support requests.
How to request deletion
- Email support@jointoperations.co.uk, use the in-app support/account options, or contact us by the email we use to communicate with you.
- Tell us the email address associated with your account so we can verify the request.
- We will confirm your identity before acting, to protect your data from unauthorised deletion.
Making a deletion request is free of charge.
What happens next
We aim to acknowledge your request promptly and to complete it within 30 days, and in any event within one month, in line with the UK GDPR. If a request is genuinely complex we may extend this by up to a further two months and will tell you why within the first month. Once completed, your account is closed and your personal data is deleted or irreversibly anonymised from our active systems.
Backups. Deleted data also leaves our backups as they age out: our production backups are retained for 30 days (held redundantly across two UK regions), so once a deletion completes in our active systems, every backup copy is gone within a further 30 days — in the worst case, roughly 60 days in total from the deletion completing. We do not read personal data back out of backups except to restore service after a failure (see “Backups and restores” below).
What is erased, what is anonymised, and what is retained
- Account identifiers and credentials — erased: sign-in credentials, sessions and password-reset records are deleted; profile details, contact details and preference records are deleted or scrubbed.
- Your core account record — anonymised in place: the underlying account row is kept (so historical references stay consistent) but its email, name and identifiers are replaced with non-identifying values that cannot be traced back to you.
- Audit trail — retained up to 12 months, including one named exception: the audit record of the deletion itself notes the erased account’s email address, kept as evidence that we honoured your request (lawful basis: evidencing erasure compliance); it is deleted with the audit record at the 12-month cap.
- Marketing suppression record — retained as hashes: a hashed marker that lets us honour “do not contact me again” without keeping your readable details.
- Complaints and vigilance records — retained under the complaints/vigilance regime, for up to 6 years (Limitation Act 1980), where a record involves a complaint, product issue or legal matter.
- Aggregated or anonymised analytics — retained: data that can no longer identify you.
Workforce accounts — a carve-out
If you use the app as a representative, member of staff or tenant administrator (a workforce user) rather than as an invited healthcare professional, your account and identity data is not deleted on the 30-day cycle when you close your account. As your employer or engaging organisation, our tenant partner (or we) must retain employment-related records, so workforce account and identity data is retained for up to 6 years from the end of your engagement, in line with the Limitation Act 1980. This carve-out covers account and identity data only — it does not extend anything else: your AI interaction records still purge at 25 months and your messages at 24 months, the same as every other user.
When we may keep some data
We may retain a limited amount of information where we are required or permitted to, for example:
- To comply with a legal, regulatory, audit or security obligation (for example, security and access logs, kept up to 12 months as described above).
- To establish, exercise or defend legal claims, which we may keep for up to 6 years (the limitation period under the Limitation Act 1980).
- The hashed suppression record and the named audit exception described above.
- Aggregated or anonymised data that can no longer identify you, which we may keep for analytics.
In addition, historical copies of limited operational data in our version-control system are access-restricted and being minimised.
Where we keep anything, we keep only what is necessary and for no longer than needed.
Backups and restores
If we ever restore a database backup to recover from a failure, the restore is followed by a retention re-run before service resumes — deletions and retention windows are re-applied so that a restore cannot resurrect data you asked us to erase.
Related rights
Deletion is one of several rights you have over your data. For the full list — including access, correction and objection — and for how long we keep different categories of data, see our Privacy Policy. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk).
This document is provided for transparency and is kept under review. If anything here is unclear, contact us through the support form on the sign-in screen.