Trigger: cancellation, non-renewal, deletion request, or end of an agency engagement. Owner: Jonny Allum. Policy anchors: POL-02, POL-10.
1. BizOS tenant offboarding
- Confirm intent — cancellation via the Stripe portal is intent; reply within 2 working days: sorry-to-see-you-go, the export offer, and the 90-day deletion date stated plainly. One retention question is allowed ("what would have kept you?" — log the answer); no dark patterns, no guilt loops.
- Export (offered always, before deletion): module CSVs from the product's export surfaces plus Xero/QuickBooks/CSV finance exports; for a full workspace, a per-table export of the tenant's rows. Delivered securely (no email attachments of special category data — use an expiring link or agreed secure channel).
- The 90-day clock (POL-10): access restricted at subscription end; workspace data held intact for 90 days (reactivation = flip the tenant back on); then deleted: tenant rows purged across owned tables, auth users removed, the deletion date logged. Backups age out on the provider cycle.
- Early deletion on request: a controller (tenant owner) may demand deletion before 90 days — verify the requester is the workspace owner, get it in writing, delete within 30 days, confirm in writing.
- What survives deletion: billing records (6 years, legal), the suppression list entry, audit of the deletion itself, and any DPA/contract (6 years). Nothing else.
2. Agency engagement offboarding
- Deliverables + credentials handover: client-owned accounts hold their own assets (domains, hosting, ad accounts, socials) — transfer anything created in JonnyAI accounts, then remove JonnyAI's access.
- Licences transferred or re-purchased in the client's name where the licence requires it (POL-09 §4).
- Final invoice, engagement record archived (6 years), access register updated (POL-04 §2).
3. Checklist per offboarding
- ☐Intent confirmed in writing; dates communicated (access end, deletion date)
- ☐Export offered / delivered securely
- ☐Stripe subscription ended; no further charges possible
- ☐Deletion executed on date + logged (or reactivation noted)
- ☐Access revoked both directions (their users, our access)
- ☐CRM updated with reason code — churn reasons reviewed quarterly (POL-11)