Data Retention & Deletion Policy

Last updated: December 2025

At Beyond (“we”, “us” or “our”), we are committed to protecting your personal data while you use the Makermint platform. This Data Retention and Deletion Policy (the “Policy”) explains how long we keep different categories of personal data and the circumstances in which we delete or anonymise them.

This Policy forms part of our Privacy Policy. Capitalised terms not defined here have the meanings given in the Privacy Policy and the Terms of Service.

By using Makermint, you agree to this Policy.

Retention Periods

We retain data only as long as necessary to fulfil the purposes described in the Privacy Policy.

Retention periods may vary depending on the data type and their purposes. Where local law requires longer retention, we will comply with that law. For U.S. Users, Beyond retains personal data for only as long as reasonably necessary for the disclosures listed in the U.S. State Privacy Notice and applicable U.S. law. State Privacy Laws may require honoring deletion requests unless an exception applies (e.g., AML/KYC, fraud prevention, tax obligations).

Account Data

We retain Account Data for as long as your Account is active. If you close your Account, we generally retain core Account Data for up to 5 years from closure to:

Device & Usage Data

We retain routine usage logs for up to 3 years from collection, after which they are anonymised or aggregated, unless we need them longer for security or legal reasons.

Certain analytics logs may be considered “personal information” under U.S. state laws; Beyond may anonymize or aggregate such data to meet state-law data-minimization requirements.

Wallet & Transaction Data

Because Makermint processes payments and Payouts, we retain Wallet and Transaction Data for at least 7 years from the end of the financial year in which the transaction occurred, or longer if required by tax, accounting or AML laws.

Payout & Identity (KYC) Data

Where identity verification is required, we retain KYC and related documents for the duration of your relationship with us and for up to 10 years after your last transaction or Payout, as required by AML laws or regulatory guidance.

Support & Communication Data

Support tickets and complaint records are typically retained for up to 5 years after resolution, unless applicable law or ongoing disputes require longer retention.

Technical & Security Data

Security logs and data relating to suspected fraud or abuse may be retained for up to 10 years from the incident, or longer where necessary for ongoing investigations or legal proceedings.

Deletion and Anonymisation

When data is no longer required for the purposes set out above, we will:

Delete it; or

Anonymise it so that it can no longer be linked to an identified or identifiable individual.

Anonymous or aggregated data may be retained indefinitely.

Legal and Contractual Requirements

In some situations, we cannot delete data on request because we are legally required to retain it. This includes data necessary for:

User Requests

You can request deletion of your personal data, including under applicable U.S. State Privacy Laws, as described in our Privacy Policy. We will comply where we are not required to keep the data and where no overriding legitimate interests apply. For U.S. Users, Beyond will honor valid deletion requests unless an exemption applies (e.g., detecting fraud, completing transactions, complying with law, maintaining security, or AML/KYC obligations). Users may appeal denied requests as described in the Privacy Policy.

Changes to This Policy

We may update this Policy periodically. Material changes will be notified via the Platform or other appropriate means. The “Last Updated” at the top indicates when the latest version took effect.