Retention, deletion and exports
What remains after disconnecting, deleting a login or removing a record.
Source reviewed Security and privacy documentation
Retention depends on the kind of record and the practice's instructions. The Privacy Policy contains the maintained retention schedule. Do not interpret a deletion in one system as deletion in every other system.
Common actions
| Action | What it changes | What it does not automatically erase |
|---|---|---|
| Disconnect an Outlook mailbox | Removes the connection and mailbox index | Mail or attachments already filed as client/case documents; Outlook itself |
| Remove a firm member | Removes that person's practice membership | Practice records and practice API keys |
| Client deletes their mobile-app account | Deletes the sign-in and firm connections | Documents and messages already held by the accounting firm |
| Replace or void a signing/check link | Invalidates access or cancels the open request | Evidence and completed actions already recorded |
| Delete data held by BeforeMay | Applies the relevant record-deletion flow | A provider's copy governed by its retention terms |
Record schedule
The policy describes uploaded documents and extracted fields being retained while the client/job is active, then under the firm's retention requirements. Identity-check results remain while the firm keeps the client record. Didit holds its own images under the period configured with that provider; BeforeMay does not hold those biometric images.
Some operational records have automated cleanup: rate-limit events after 7 days, settled invitation metadata under the defined cleanup period and audit events after 18 months. Other deletion depends on the record flow or a firm request; there is no blanket daily purge of all client financial records.
Provider copies
Files sent for AI processing can be retained by the provider under its own agreement. The policy expressly distinguishes provider retention from deletion in BeforeMay and describes immediate post-job provider file deletion as work in progress. This guide does not present that plan as implemented.
Export before closing
Retain the records your practice needs: delivered/current workbooks, source files, signed PDFs and certificates, and applicable CDD record exports. Check the files open and relate to the intended client and period. An individual product export is not a promise of a one-click full-practice migration archive.
Clients can follow account deletion. Firm users should ask the Owner to remove their membership; contact support@beforemay.com.au for practice closure. Privacy requests go to privacy@beforemay.com.au.
Backups and recovery
Deletion from active records and expiry from retained backups are separate questions. No recovery-time, recovery-point or backup-erasure guarantee is established by this guide. If those are adoption requirements, request the current backup policy and a dated restore-test result before relying on them.