Data Retention Schedule
How long Merion retains personal information and operational data — and when it is destroyed or de-identified.
Why retention periods matter
Retaining personal information for longer than necessary creates privacy risk and increases the potential impact of a data breach. Destroying data too early, however, may prejudice legitimate legal proceedings, prevent Merion from responding to regulatory inquiries, or deprive the parties of a record they are legally required to maintain.
Merion's retention schedule is designed to balance these competing obligations. Retention periods reflect general law limitation periods for contract actions (typically six years in most Australian jurisdictions), ATO record-keeping guidance (generally seven years), obligations under the Fair Work Act 2009 (Cth), and the requirements of the Privacy Act 1988 (Cth).
Retention categories and periods
Active case files
Case files — including debtor contact details, account correspondence, payment records, and case outcome documentation — are retained while the case is active and for seven years after case closure. The seven-year period reflects general law limitation periods for contract actions and ATO record-keeping guidance. At the end of the retention period, case files are destroyed or de-identified.
Creditor client records
Records relating to creditor clients — including onboarding documents, referral records, and remittance records — are retained for the duration of the client relationship and for seven years after the last transaction. This period reflects the same general law limitation period and ATO guidance that applies to case files.
Debtor portal access logs
Debtor portal access logs — which are audit logs of authentication events and payment actions, not records of communications — are retained for seven years. These logs exist to support security review, fraud investigation, and regulatory response. They are not chat-style communication logs.
Website enquiry form submissions
Submissions made through Merion's public website enquiry forms are retained for 12 months after receipt, unless the enquiry becomes the basis of an ongoing engagement, in which case it is treated as part of the relevant client or case file and retained accordingly.
Employee records
Employee records are retained for seven years after the end of the employment relationship, in accordance with the record-keeping obligations under the Fair Work Act 2009 (Cth).
Application and server logs
Technical server and application access logs — which record system-level events and are used for security monitoring and incident investigation — are retained for 90 days. These logs are not personal data logs in the APP sense; they record system events, not individual user communications.
De-identification
In some cases, Merion de-identifies records rather than destroying them — for example, to preserve anonymised data for internal analytics or to maintain aggregate case outcome statistics. De-identification removes name, contact details, and any other direct identifiers. De-identified data is not subject to the Australian Privacy Principles.
Requests to delete
Individuals may request the deletion of personal information Merion holds about them. Merion will comply where there is no legal obligation to retain the information. Where retention is required — for example, because the case file is within its seven-year retention window — Merion will advise the individual of this and indicate how long the information will be held before it is destroyed.
Deletion requests may be submitted by email to [email protected].
Related pages
For Merion's obligations around the security of retained information, see Security of Personal Information. For Merion's approach to destruction and de-identification, see also Data Handling.
Ready to talk to Merion?
Whether you have accounts to recover or a question about a notice, the first conversation is always obligation-free.