ITB Data Deletion

Last Updated: 28.07.2026

Purpose

The purpose of this Data Deletion Policy is to establish a structured process for handling requests from individuals seeking the deletion of their personal information maintained by ITB.

This Policy aims to ensure compliance with applicable privacy and data protection laws, uphold individuals’ privacy rights, and define the Company’s responsibilities regarding the deletion, anonymization, retention, and disposal of personal data.

The Policy further ensures that data deletion requests are processed in a timely, secure, and consistent manner while balancing legal, regulatory, contractual, operational, and security requirements.

Scope

This Policy applies to all personal information, formally classified as Confidential data, collected, processed, stored, transmitted, or maintained by ITB through its websites, software applications, cloud-based platforms, mobile applications, customer support channels, and third-party integrations, including Facebook, Instagram, and WhatsApp Business services.

The Policy applies to all employees, contractors, consultants, third-party service providers, and other authorized individuals who manage or process personal information on behalf of ITB.

1.      Data Deletion Requests

ITB must provide standardized mechanisms for data subjects to exercise their right to data deletion.

Users may request deletion of their personal information via email.

ITB will process verified deletion requests within 30 days of identity verification, subject to legal and operational requirements.

For users accessing our services through third-party platforms, data deletion requests may also be submitted through the privacy controls provided by those platforms, where applicable.

2.      Verification

ITB will verify the identity of the requester before processing any data deletion request.

Validation steps

  • Verify the request originates directly from the email address registered to the user account.
  • Request confirmation from the user mobile no. if the email address cannot be validated.

If identity verification fails, the deletion process will be terminated and the requester will be notified.

Record all unverified requests in the centralized deletion audit log and close the ticket. ITB will not execute data deletion without positive identity confirmation.

3.      System Backups and Immutable Data

Data deletion applies immediately to active production systems. Personal data residing in automated system backups is handled under the following constraints:

  • Backup archives are immutable. Individual records cannot be manually extracted or deleted from encrypted backup files.
  • Personal data within backups will be systematically overwritten in accordance with the standard ITB backup retention schedule.
  • ITB prohibits the restoration of deleted personal data to active systems. If a system-wide backup restoration is required for business continuity, any previously processed deletion requests will be re-executed immediately upon system recovery.

4.      Subprocessor Data Cascading

ITB utilizes third-party sub-processors and integrations to deliver its services. Personal data deletion requests will be cascaded to all applicable external systems.

  • Authorized personnel must transmit verified deletion requests to relevant third-party vendors (e.g., cloud hosting providers, Meta platforms) within 72 hours of identity verification.
  • ITB requires sub-processors to confirm the execution of data deletion or anonymization within their respective systems.
  • ITB remains accountable for verifying sub-processor compliance through established contractual obligations and routine vendor audits.

5.      Audit Trail Requirements

ITB will maintain a secure, centralized audit log of all data deletion requests to demonstrate regulatory compliance and ensure accountability.

  • The audit log will record the Request ID, date of receipt, identity verification status, executing personnel, sub-processor notification status, and the final completion timestamp.
  • The log will utilize anonymized or hashed identifiers. It will not store the actual personal data requested for deletion.
  • Access to the deletion audit log is strictly restricted to the Internal Audit and authorized ITB management to enforce segregation of duties.
  • System administrators will configure the audit log to prevent unauthorized modification or manual deletion of entries.

6.      Request Denials and Legal Holds

ITB may partially or fully deny a data deletion request under specific legal or regulatory conditions.

Grounds for Denial:

  • Active litigation or documented legal holds.
  • Ongoing fraud investigations or security incidents.
  • Financial and tax record-keeping compliance mandates.

Notification and Appeal:

  • The ITB management must notify the requester in writing within 15 days if a request is denied.
  • The notification must explicitly state the legal or regulatory justification for data retention.
  • Requesters may appeal the decision by submitting a formal request letter to the Internal Audit Department within 30 days of receiving the denial notice.

7.      Exceptions and Retention Limits

Retention of personal data overriding a deletion request is strictly governed by the official ITB Data Retention Schedule. Authorized exceptions include:

  • Financial transactional data required for regulatory tax compliance.
  • System audit logs required for security monitoring and fraud prevention.

Indefinite storage of personal data is prohibited. All retained data must be securely purged upon the expiration of its designated retention period as defined in the Data Retention Schedule.

8.      Responsibilities

ITB technical manager: Responsible for executing the technical deletion of personal data from all active ITB systems and databases, and for transmitting verified deletion requests to third-party sub-processors and securing confirmation of execution.

ITB management:

  • Responsible for managing the identity verification process and communicating decisions to the data subject.
  • Responsible for regulatory oversight and restricting access to deletion audit logs.

9.      Public Instructions

Public instructions for data deletion listed under Appendix A

Appendix A: Public Instructions

Requesting Data Deletion

If you would like us to delete your personal information associated with our services, you may submit a request using one of the following methods:

A. Email Deletion Request

Send an email to: info@ITB-me.com

Include:

  • Your full name
  • Business name (if applicable)
  • Email address associated with your account
  • Mobile Number
  • Description of your deletion request

B. Account Deletion

If available within the application, users may delete their account directly through the account settings section.

What Data Will Be Deleted

Upon verification of your request, we will delete or anonymize:

  • User profile information
  • Customer records associated with your account
  • Stored communications where applicable
  • Data obtained through third-party platform integrations, such as social media networks, messaging applications, authentication services, or other external platforms

 Exceptions to Data Deletion

While we strive to honour all deletion requests, ITB may be legally required to retain certain information. Exceptions include:

  • Data required for tax, accounting, or financial regulatory compliance.
  • Information necessary to investigate fraud, security incidents, or to protect our legal rights.
  • Data subject to active legal holds or ongoing litigation.

Any retained data will be securely stored and automatically deleted once the mandatory legal retention period expires. ITB does not store personal data indefinitely.

Third-Party Platform Data

Users who have connected accounts from third-party platforms, social networks, messaging services, authentication providers, or other external services to our platform may request deletion of data obtained through such integrations.

Instructions to request deletion:

  • Remove the application, integration, or connection from the applicable third-party platform account settings.
  • Navigate to the platform’s privacy, security, connected apps, or integrations settings (as applicable).
  • Locate and disconnect or remove the application or service connection.
  • Submit a data deletion request through the platform’s available privacy controls, where applicable.
  • Send a deletion request to: info@ITB-me.com

Processing Time

Verified deletion requests are generally processed within 30 days, subject to legal and operational requirements.

Contact Information

If you have questions regarding data deletion, please contact us using the information below: