SAYDO

Effective 31 August 2026 · version 2026-08-31.1

Data Retention & Deletion Schedule

This schedule explains how long the current SAYDO application is designed to keep different categories of information, what causes deletion, what remains after a control is used, and which provider or infrastructure limits sit outside an immediate record-by-record purge. It forms part of the Privacy Notice.

1. How to read this schedule

A “default” is the current production configuration or schema default, not an unconditional promise that every copy disappears at the same second. Automated cleanup is bounded and runs in batches. A record can be kept longer where it is still needed for an active job, payment reconciliation, fraud or security investigation, a dispute, a legal hold or another lawful purpose. Provider-controlled copies follow the provider's own controls. When an exception ends, SAYDO should delete or de-identify the record during the next applicable cleanup or review.

“Delete” can mean secure removal of the content-bearing record, cryptographic erasure by removing its encrypted payload or key-bound fields, or de-identification where the remaining transaction or security record must no longer identify the customer directly. The method depends on the record and its legal/operational purpose.

2. Current retention matrix

3. What each user control currently does

4. Provider-controlled retention

Meta and WhatsApp

Messages and media travel through Meta's WhatsApp Business Platform. Meta controls delivery infrastructure, service logs, safety processing, backup and legally required retention under its applicable terms and privacy materials. Deleting SAYDO's database copy does not delete a message from the user's WhatsApp device, another recipient's device or Meta-controlled records that SAYDO cannot erase through the available business API.

OpenAI

OpenAI states that API data is not used for model training by default unless the API customer opts into data sharing. Its standard abuse-monitoring logs may retain request/response content for up to 30 days, subject to provider exceptions. OpenAI Conversations and conversation items persist until deleted. Uploaded files persist until SAYDO deletes them or another provider rule applies. SAYDO issues deletion calls for conversation/file objects in the product paths described above, but OpenAI controls final provider-side deletion, backups, legal/safety exceptions and any approved data-control configuration.

PayFast, Google, email and hosting

PayFast retains payment, fraud, recurring authority and settlement information under its financial/legal obligations. Google retains consented analytics or advertising data under the configured Google account and its policies. Email and hosting providers retain delivery, access, security and backup records under their service settings. A SAYDO deletion request removes the live application data that SAYDO controls but cannot bypass those independent duties or systems.

5. Business accounts and ownership changes

All linked numbers on a business account contribute to the business's shared pool and retained workspace. The account holder can search and export the combined history. If a staff member leaves or loses access to a number, removing the number stops future SAYDO use but keeps existing history available to the business account. The business should decide, under its own lawful retention duties, whether that history should remain until expiry or be cleared sooner. Transferring or closing a business must not transfer personal information to a new controller without a lawful basis, notice and appropriate access changes.

6. Account deletion sequence and exceptional failures

  1. SAYDO verifies the active basic account, current password and exact deletion phrase.
  2. It marks deletion as requested, revokes approved WhatsApp access and places linked senders into a deleting state so no new AI work is admitted.
  3. It requests deletion of each linked OpenAI conversation and cancellation of any active, past-due or locked recurring PayFast subscription.
  4. After provider boundaries succeed, a transaction deletes local sender content, memory, archive, context, ownership mappings, credits, saved views, sessions and authentication tokens; pending orders are cancelled and the portal identity is pseudonymised.
  5. Validated billing evidence remains, but it no longer contains the live email, username, display name, password or linked phone mapping.

A provider timeout or rejection can stop the workflow before the final transaction. This is deliberate: the system should not tell the customer that provider deletion/cancellation succeeded when it did not. The request can be retried after investigation. A delayed PayFast notification may still be retained for reconciliation, but it cannot reactivate the closed account or grant credits.

7. Holds, complaints and disputes

SAYDO may suspend ordinary deletion of a narrowly scoped record where it must preserve evidence for a payment dispute, fraud or security investigation, court/regulator request, legal claim or another duty. The hold should identify the reason, owner, scope and review date. It must not be used to keep unrelated customer content. When the hold ends, the record returns to the applicable deletion or de-identification process.

8. Retention requests and questions

Use the dashboard and WhatsApp controls described above, or contact info@saydo.co.za. State the account email or linked number and what you want accessed, corrected, cleared or deleted, but do not email a password, verification code or full card number. SAYDO may ask for proportionate identity or authority verification before changing or disclosing records.

Where a deletion is delayed by a provider, backup, investigation or legal requirement, SAYDO should explain the category and reason as far as security and law permit. The rights and complaint channels in the Privacy Notice remain available.

9. Schedule review and known control gaps

This schedule is versioned because retention must match the deployed code and provider settings. It should be reviewed whenever a new data table, provider, export, backup process, log destination, account type or AI feature is introduced.

The current public disclosure deliberately records three boundaries that require ongoing operational/legal ownership rather than implying a control that the application does not prove:

These boundaries do not authorise indefinite retention. They identify where restricted schedules, monitoring, deletion verification and legal review must remain part of SAYDO's operating controls.