Skip to main content
Bibeno

Bibeno product

Everything your team needs to run each sale.

Explore Bibeno’s point-of-sale, product, stock and reporting tools.

Software overviewSee what Bibeno includes.Point of saleTake orders and complete sales at the counter.Products & menusManage products, prices and selling options.Inventory managementTrack stock movement and complete stock takes.Backoffice & reportingManage access and review business performance.Download for WindowsInstall Bibeno on a supported device.
Bibeno product catalog interface.Inside BibenoSee the full Bibeno product.Explore

Made for independent businesses

Software that fits the way your business works.

See how Bibeno supports food-service and specialty retail teams.

Industries overviewSee which businesses Bibeno is built for.CafésManage orders, products, stock and daily reporting.Takeaways and quick-serviceKeep service fast and every order organised.Boutiques and specialty retailManage checkout, products and stock together.
A café team serving a customer at the counter.Find the right fitTell us how your business operates.Explore
Pricing

About Bibeno

A South African team focused on independent business.

Learn about Bibeno, how we help businesses get started and how to contact us.

About BibenoOur story, purpose and product principles.How we workSee what to expect from setup and rollout.Contact usSpeak to sales, support or our general team.Get startedTell us about your business and what you need.
A team of independent bakery operators working together.Meet BibenoBuilt locally. Supported by real people.Explore
Sign inBook a demo
Legal/Data Retention and Deletion Schedule

Data Retention and Deletion Schedule

Category, trigger, period, legal-hold, backup, anonymisation, deletion, and evidence rules for information processed through Bibeno.

Status: Effective 14 August 2026Version: 1.0.0Content hash: 5b5a944aa09837e145f81cd347d117cacb0df93d4009560263a477f3d5320c12
1. Purpose and status0% read

On this page

Data Retention and Deletion Schedule

  1. 1. Purpose and status
  2. 2. Retention principles
  3. 3. Customer instructions and mandatory law
  4. 4. Active account and operational data
  5. 5. Account closure and customer-controlled data
  6. 6. Trials, pilots, and sandboxes
  7. 7. Tax, financial, invoice, and corporate records
  8. 8. Sales, consumer, warranty, and gift-card records
  9. 9. Payment, refund, fraud, and chargeback evidence
  10. 10. Workforce, time, payroll-input, and advance records
  11. 11. Contracts, legal acceptance, billing, and complaints
  12. 12. Privacy, PAIA, and regulator records
  13. 13. Support, access, security, and incident evidence
  14. 14. Marketing consent, sends, and suppression
  15. 15. Devices, offline queues, and technical telemetry
  16. 16. Transient exports, imports, notifications, and media
  17. 17. Backups and disaster-recovery copies
  18. 18. Legal holds
  19. 19. Anonymisation and deletion
  20. 20. Disposal control and evidence
  21. 21. Changes and retention requests

1. Purpose and status

In plain language: Bibeno does not keep every record for the same period. It keeps the minimum record needed for the relevant service, law, transaction, security event, complaint, or dispute; removes unnecessary raw detail earlier; pauses deletion only for a valid hold; and does not call data deleted until the approved purge or irreversible anonymisation process is complete.

This schedule explains Bibeno's default retention and deletion rules for customer data, personal information, platform evidence, and Bibeno business records. It supplements the Privacy Notice and Data Processing Agreement. It applies only to systems and processing included in the approved service boundary; any system without a verified inventory, owner, retention trigger, deletion method, backup treatment, and evidence remains outside the enabled production boundary.

2. Retention principles

  • Retain a record only for an identified service, contract, legal, tax, employment, consumer, security, fraud, dispute, audit, or legitimate operational purpose.
  • Apply the most specific approved category and trigger rather than one account-wide deletion date.
  • Separate active access, restricted archive, quarantine, anonymisation, and irreversible purge.
  • Preserve immutable evidence needed to explain a transaction or decision without retaining unrelated raw personal information.
  • Suspend disposal under a valid legal hold and document the hold owner, scope, reason, authority, review, and release.
  • Use two-person approval and an immutable completion report for destructive production operations.

3. Customer instructions and mandatory law

Where Bibeno acts as operator, it follows the customer's lawful documented retention and deletion instructions within the supported service. Bibeno may retain a limited record where law requires it or where reasonably necessary for a legal claim, security, fraud, tax, or dispute, and will inform the customer of that boundary where legally permitted.

4. Active account and operational data

Current configuration, users, products, customers, orders, inventory, suppliers, workforce, support, and related operational records are retained while the account and purpose are active, subject to category-specific minimisation, user deletion, correction, and archive controls. An active account is not authority to retain every historical raw payload indefinitely.

5. Account closure and customer-controlled data

Account closure first suspends operational access and starts the approved export and reconciliation window. Customer-controlled data that is not allocated to a longer category is quarantined for up to 90 days after the effective closure date, then anonymised or purged following inventory, legal-hold, approval, and completion-report checks.

Closure does not erase tax, consumer, contract, payment, workforce, gift-card, security, acceptance, dispute, or other records that remain subject to a specific period. Those records are restricted to the minimum fields and authorized purposes required for the remainder of that period.

6. Trials, pilots, and sandboxes

Synthetic sandbox data may be quarantined 30 days after the sandbox ends and purged after approval if no hold applies. A live pilot or trial follows the account-closure process and is never hard-deleted as one undifferentiated tenant because it may contain financial, consumer, payment, employee, support, or security records with longer obligations.

7. Tax, financial, invoice, and corporate records

Final invoices, credit notes, accounting entries, settlement and reconciliation evidence, tax classifications, financial approvals, and related source references are retained for seven years after the end of the financial or tax period to which they relate, unless a longer period applies because a return is outstanding, an audit, objection, appeal, investigation, prescription period, or legal hold remains open.

This seven-year policy is a conservative business-record period and does not claim that every underlying raw payload must be retained for seven years. Redundant personal fields are removed or tokenised where the evidential purpose can still be met.

8. Sales, consumer, warranty, and gift-card records

Sale, online order, supplier and policy-version disclosure, acceptance or rejection, item and option, collection or delivery, receipt, refund, return, substitution, warranty, complaint, gift-card issue, value, redemption, reversal, closure, and related consumer evidence is retained for five years after the later of final performance, final redemption, complaint closure, or the end of the applicable warranty or statutory validity period. Tax or active dispute records follow the longer applicable category.

Delivery instructions, order notes, and optional allergy or safety information are separated from the minimum transaction evidence and removed or irreversibly anonymised earlier when they are no longer needed for fulfilment, a food-safety or consumer issue, a legal obligation, or an active dispute. A five-year transaction record is not permission to keep the full free-text order payload for five years.

9. Payment, refund, fraud, and chargeback evidence

Tokenised payment references, provider events, refund and reversal evidence, fraud decisions, chargebacks, disputes, and settlement links are retained for seven years after final settlement or closure of the last related dispute where needed for finance, fraud, contract, tax, or legal claims. Bibeno does not retain full payment-card data outside an expressly approved PCI scope.

10. Workforce, time, payroll-input, and advance records

Employee identity, agreement, time, attendance, leave, remuneration input, payroll export, tip or service-charge allocation, advance, deduction, correction, and termination evidence is retained for five years after the later of the relevant payroll or tax period, settlement of the amount, or termination of employment, unless a longer labour, tax, injury, dispute, collective, prescription, or legal-hold period applies.

Unsuccessful applicant or unneeded monitoring data uses a shorter approved purpose-specific period and is not retained under the employee-record period by default.

11. Contracts, legal acceptance, billing, and complaints

Orders, contract versions and hashes, presentation and acceptance evidence, billing choices, cancellation, notices, material changes, complaints, and final decisions are retained for seven years after the later of contract end, final payment, or closure of the matter, subject to a longer dispute, prescription, regulator, or court requirement.

12. Privacy, PAIA, and regulator records

Privacy-rights and PAIA requests, identity-verification decisions, searches, disclosures, refusals, fees, communications, complaints, and regulator correspondence are retained for five years after final closure, or longer while a review, complaint, enforcement action, litigation, or legal hold remains open. Identity evidence is minimized and removed earlier where it is no longer needed to prove verification.

13. Support, access, security, and incident evidence

Ordinary support content is retained for up to three years after ticket closure. Privileged-access, security, fraud, incident, breach-notification, audit, and material correction evidence is retained for up to seven years after final closure where necessary for accountability, claims, regulator, or security learning. Attachments and raw diagnostics are reviewed for earlier removal when their evidential purpose ends.

14. Marketing consent, sends, and suppression

Consent, existing-customer basis, notice, audience, NCC cleansing, content, send, delivery, opt-out, and complaint evidence is retained for five years after the last reliance or closure of the related complaint. A minimal suppression record is retained while the responsible party conducts the relevant marketing and for five years thereafter so that a withdrawal or objection is not silently lost.

15. Devices, offline queues, and technical telemetry

Raw device, offline queue, synchronization, delivery, and operational telemetry is retained for no longer than two years after final processing unless it is quarantined for a specific incident, dispute, fraud, or legal hold. Normalized sale, payment, financial, inventory, acceptance, and security evidence follows its own longer category.

16. Transient exports, imports, notifications, and media

  • Generated export download files expire within 24 hours; the request and delivery audit may be retained under its applicable evidence category.
  • Import staging, validation, and error payloads are removed within 180 days and earlier where the configured plan and support purpose permit; final imported records follow their own category.
  • Notification trash and ordinary delivery payloads are removed within 30 days unless linked to a complaint, security event, marketing proof, or legal hold.
  • Unreferenced temporary media is removed within seven days after verification that it is not required by an active record, incident, dispute, or legal hold.

17. Backups and disaster-recovery copies

Backups are protected, access-restricted, and expire through the approved rolling cycle within 90 days unless a tested recovery, incident, or legal-hold need requires a controlled exception. A deleted record is not restored to active use merely because it exists in a backup. If a backup is restored, applicable deletion and suppression instructions are re-applied.

18. Legal holds

A legal hold overrides ordinary disposal only for the identified people, systems, records, dates, and purpose. The hold record identifies authority, owner, reason, start, scope, review date, access, and release. Holds are reviewed periodically and released promptly when no longer justified.

19. Anonymisation and deletion

Anonymisation is used only when re-identification is not reasonably likely using available means and the remaining data no longer relates to an identifiable person. De-identification, tokenisation, masking, archive, or disabled access is not described as deletion. A purge removes the approved primary records and expires from backups through the documented cycle.

20. Disposal control and evidence

Production disposal uses a dry-run inventory, policy version, category and trigger, hold check, record count, dependency check, authorized requester, independent approver, idempotency key, item-level result, error handling, and immutable completion-report hash. A failed or partial operation is not represented as complete.

21. Changes and retention requests

Periods are reviewed when law, product purpose, vendor, territory, customer instruction, litigation exposure, or system design changes. A material reduction or expansion is versioned and approved. A person may ask about retention or exercise a privacy right through the verified contact in the Privacy Notice, subject to lawful exceptions and preservation duties.

Book a demo
Bibeno

Point of sale and business management software for South African food-service and independent retail businesses.

Book a demo

Product

Software overviewIndustriesPricingDownload for WindowsBook a demoGet started

Company

AboutContact usSign in

Legal

Legal centreTermsPrivacyData processing agreementRefunds and cancellation
BIBENO (PTY) LTD · Reg. 2026/355321/07© 2026 Bibeno POSsupport@bibeno.co.za+27 60 659 1848

Choose your cookie preferences

Essential storage is always active. Optional analytics and marketing tools remain off unless you allow them. Read more.

Cookie preferences

Control optional website technologies

Necessary technology is always active. Optional categories remain off until you enable them. You can change these choices from the website footer.

Strictly necessary

Remembers your consent choice and supports essential website security and forms. This category cannot be switched off.

Currently used: Bibeno consent storage; Cloudflare Turnstile on protected demo forms.

Functional

Would remember optional site preferences that are not needed for core features.

Not currently used.

Analytics

Would help us understand website use and improve performance through approved measurement tools.

Not currently used.

Marketing

Would support approved advertising, campaign measurement or personalised marketing.

Not currently used.

Your browser is sending a Global Privacy Control signal. Optional categories remain off unless you actively change them here.