Data Deletion Request
How to have your personal data erased from our services, and what happens after you ask.
Last updated: 5 September 2026
1. Overview
Lemorange Ltd ("Lemorange", "we", "us", or "our") is a company registered in Cyprus and based in Nicosia. We operate the website at lemorange.com, the client portal, the LemDesk remote desktop service, the Lemorange Admin mobile application, and related services (collectively, the "Services").
Under Article 17 of the General Data Protection Regulation, you have the right to ask us to erase the personal data we hold about you. This page explains how to make that request, what we delete, what we are legally obliged to keep, and how long the process takes.
This page sits alongside our Privacy Policy, which describes everything we collect and why. If the two documents ever appear to disagree, the Privacy Policy governs and we will correct this page.
2. Who Can Make a Request
- Portal users: Anyone with a Lemorange account, whether you registered directly or accepted an invitation to a company account.
- Website visitors: Anyone who submitted our contact form or corresponded with us by email, even without an account.
- Mobile application users: Anyone who signed in to the Lemorange Admin application.
- Client company administrators: An authorised representative may request closure of an entire company account and erasure of the data associated with it.
We only act on requests we can verify. Please send your request from the email address registered on the account. If you cannot, we will ask for other reasonable proof of identity before we act, and we will not use that proof for any other purpose.
3. What You Can Remove Yourself
Some data is under your direct control and does not require a request to us:
- Profile details: Update your name, email address, and phone number in your portal settings at any time.
- Push notifications: Turn notifications off in the portal, or revoke the permission in your browser or device settings. The stored subscription is removed when you do.
- Uploaded files: Delete project files you uploaded, subject to the permissions on your account.
- Browser storage: Clear cookies and local storage through your browser to remove your session and saved preferences from your device. See our Cookie Policy.
- Mobile application: Sign out and uninstall the application to remove the locally cached session from your device.
Full erasure of your account and its history is not a self service action. It must be requested from us so that we can verify the request and check our retention obligations first.
4. Request Deletion
Complete the form below and we will action your request. There is no charge, we will not ask you to justify it, and we will not treat you differently for making one.
You can also email [email protected] with the subject line "Data Deletion Request", or raise a ticket from inside the client portal.
5. What We Delete
Once your request is verified, we permanently remove the following from our production systems:
Account and profile
Your name, email address, phone number, password hash, role assignments, login timestamps, and any profile details you added in portal settings.
Support tickets and messages
Tickets you opened, your replies, internal notes that identify you, and chat messages you sent, unless the ticket forms part of a contractual or billing record we are required to keep.
Files and documents
Files you uploaded, documents you authored, and collaborative editing history attributed to you, unless the file is a project deliverable owned by the company account.
LemDesk devices and sessions
Device registrations linked to your account, including device identifier, hostname, operating system, and last seen timestamp, together with the connection metadata for your sessions.
Notification subscriptions
Push notification endpoints and cryptographic keys stored when you opted in to browser or mobile notifications.
Contact form submissions
Enquiries you submitted through our website contact form, including the company name, budget, timeline, and requirement details you provided.
Where a record cannot be removed without breaking a legitimate business record, we anonymise it instead. Your identifiers are replaced with a placeholder that cannot be reversed, so the remaining entry can no longer be linked to you.
6. What We Are Required to Keep
The right to erasure is not absolute. GDPR allows us to keep certain data where we have a legal obligation, or a legal claim to establish or defend. We will tell you which of the following applies to your request:
Invoices and payment records
Minimum 7 yearsCyprus tax and accounting law requires us to keep accounting records. These contain the billing name, address, amounts, and transaction identifiers. They cannot be deleted on request.
Signed agreements and NDAs
Term of the agreement plus 7 yearsContracts, signed non disclosure agreements, and their audit trail are kept so we can establish, exercise, or defend legal claims.
Project delivery records
Up to 7 years after the engagement endsSource code, technical documentation, and delivery evidence belong to the client company rather than to an individual, and are retained under the client contract.
Security and audit logs
Up to 12 monthsAuthentication events and administrative audit entries are kept so we can investigate misuse and unauthorised access. Identifiers in these logs are reduced to the minimum needed.
Record of your deletion request
3 yearsWe keep a minimal record showing that a request was made and actioned, so we can demonstrate compliance to a supervisory authority.
Retained records are restricted to the minimum number of staff who need them, and are deleted once the retention period expires.
7. Company Accounts and Colleagues
Most of our users work inside a company account, which matters for two reasons.
First, deleting your personal account does not delete the company account or the work delivered under it. Projects, documents, invoices, and tickets that belong to your employer or client remain with that organisation. Your name is removed or anonymised on the entries that identify you.
Second, if you only want to leave a company account rather than erase your data, an administrator on that account can remove your access directly. This is usually faster than a deletion request, and it keeps your account available for other work.
Where an entire company account is closed, we erase the account, its members, and its content according to sections 5 and 6, after confirming the request with an authorised representative of that company.
8. Third Party Services
A small number of providers process data on our behalf. When we action a deletion, we handle each of them as follows:
- Stripe: Payment records are kept by Stripe under its own regulatory obligations and cannot be deleted on request. We remove the link between your account and the Stripe customer record where the underlying transaction is not part of an accounting record we must keep.
- Email delivery provider: Delivery logs that contain your email address expire on the provider's own schedule, within 2 years. We do not reuse them after deletion.
- Zoho Books: Contact records synchronised for accounting are treated as accounting records and follow the 7 year retention rule in section 6.
- Google Analytics: Website analytics are collected in anonymised form and are not linked to your account. You can opt out at any time by clearing cookies or by using a browser blocker. See our Cookie Policy.
We do not sell, rent, or trade personal data, and we do not pass it to advertising or remarketing networks, so there is no further chain of recipients to unwind.
9. Backups and Recovery Copies
We take encrypted backups of our databases so that we can recover from failure. A backup taken before your deletion will still contain your data until that backup expires.
Backups are replaced on a rolling schedule and the last copy containing your data expires within 90 days. During that window your data sits in backup storage only. It is never used to serve the application, and it is only ever touched in a disaster recovery event. If a restore were ever required, we would reapply your deletion immediately afterwards.
10. Timeline
- Within 3 working days: We acknowledge your request, and confirm your identity if we need to.
- Within 30 calendar days: We complete the deletion and write to you with a summary of what was removed, what was anonymised, and anything we had to keep together with the reason why.
- Extension: If a request is unusually complex we may extend by a further 60 days, as GDPR permits. We will tell you before the first 30 days expire and explain why.
- Within 90 days: The last backup containing your data expires.
11. What Happens After Deletion
Deletion is permanent and cannot be undone. Once it is complete:
- You lose access to the client portal, your project history, your documents, and your ticket history.
- LemDesk devices registered to your account stop being reachable and must be registered again if you return.
- The Lemorange Admin mobile application can no longer sign in.
- You stop receiving invoice, ticket, and project notifications from us.
- If you later want to work with us again, you will need to open a new account.
If an active project or an unpaid invoice is open, we will tell you before we proceed so that you or your organisation can settle it first. We will not use an open matter as a reason to refuse your request.
12. If You Are Not Satisfied
If we refuse all or part of your request, we will explain the legal ground we are relying on. You may ask us to review that decision at any time.
You also have the right to complain to the Office of the Commissioner for Personal Data Protection in Cyprus, or to the supervisory authority in the country where you live or work. Exercising that right does not affect any other remedy available to you.
13. Contact Us
To make a deletion request, or to ask a question about this page, contact us: