Exit, Data Destruction & Litigation Hold Procedure
SyncMate — WYHEN Pty Ltd (ABN 57 688 078 999) Version 1.0 · Effective 31 August 2026 · Owner: Founder/Technical Operator · Review: annually
Part A — Retention
A.1 During the contract
Customer data is retained for the life of the active workspace so the customer can meet its own record-keeping obligations. Customers may delete individual documents, statement batches, transactions or entire workspaces at any time through the application.
Shared audit packs created for external recipients expire automatically at the expiry date set by the customer, after which the download link ceases to function.
Retention periods can be varied contractually — including immediate deletion on processing, or extended retention to match a customer's statutory record-keeping period.
A.2 After termination
By default, data is retained for 30 days after termination to allow the customer to complete its export, after which it is permanently deleted. The customer may instead instruct immediate deletion, or an extended retention period, in writing.
Part B — Return of data (customer exit)
B.1 What the customer can retrieve, self-service
- Full transaction export (CSV) — all extracted transactions, line items, tax lines, account codes and status for the workspace.
- Audit Pack (ZIP) — the transaction register as CSV together with an
attachments/folder containing every original source document exactly as uploaded. This is the primary exit and eDiscovery artefact. - Bank statement export (CSV) — all imported bank transactions.
- Reports (CSV) — Profit & Loss, Balance Sheet and account transaction listings for any selected period.
All of the above are available from within the product throughout the contract and for the full 30-day post-termination window. No fee applies and no request to WYHEN is required.
B.2 Assisted export
Where a customer prefers, WYHEN will produce the same exports on written request within 5 business days at no charge.
B.3 What is outside our control
Data already published into the customer's own Xero organisation belongs to and remains with the customer in Xero; it is not affected by exit from SyncMate.
Part C — Destruction
C.1 Procedure
On written instruction, or at the end of the retention period:
- Confirm the instruction and the scope (specific workspace, or the whole account) with an authorised customer contact.
- Delete all database records for the scope: documents, extracted transactions, line items, ledger entries, bank data, reports, memberships and settings.
- Delete all stored objects for the scope: original source documents and generated packs.
- Revoke and delete all third-party tokens for the scope, including Xero OAuth access and refresh tokens.
- Invalidate any outstanding shared audit-pack links.
- Record the deletion in the audit log with date, scope and authorising contact.
- Issue a Certificate of Destruction to the customer on request, stating what was deleted, when, by whom, and the residual backup position below.
C.2 Residual backups — disclosed honestly
Deleted data may persist in the hosting provider's automated backup rotation for approximately 7 days after deletion, after which it ages out and is unrecoverable. During that window the data is not accessible through the application and is not used for any purpose. This is a property of the managed backup service and cannot be shortened for an individual record; it is disclosed rather than obscured.
C.3 Physical media
WYHEN operates no physical servers, no local storage of customer data and no removable media. There is therefore no physical media sanitisation or destruction step. Printing is not part of the service; if material were ever printed it would be cross-cut shredded and the disposal recorded.
Part D — Litigation hold
D.1 Trigger
A litigation hold is initiated when WYHEN receives a written hold instruction from the customer, or becomes aware of actual or reasonably anticipated litigation, regulatory investigation or law-enforcement request affecting identified data.
D.2 Effect
On initiation, for the identified workspace or records:
- Scheduled deletion and retention age-out are suspended.
- Post-termination deletion is suspended.
- Automatic expiry of shared packs relevant to the hold is suspended.
- The hold, its scope, its instructing party and its date are recorded.
The hold applies only to the identified scope. Other customers and other workspaces are unaffected, and the service continues normally for everyone.
D.3 Collection and production
Data under hold is produced using the standard exports in Part B — the Audit Pack ZIP (transaction register plus every original source document) supplemented by an extract of the in-product audit log showing who did what and when. Documents are produced as uploaded, without alteration.
D.4 Release
A hold is released only on written instruction from the party that instructed it, or on written confirmation that the matter has concluded. On release, normal retention and deletion resume and the release is recorded.
D.5 Third-party and law-enforcement requests
Requests for customer client data received directly by WYHEN are referred to the customer as Data Controller, unless WYHEN is legally prohibited from disclosing the request. WYHEN does not volunteer customer data without either the customer's instruction or valid legal compulsion.