Legal
Data deletion
How to have your information removed from Exhibitio, what we can delete, and what the law requires us to keep.
Last updated August 6, 2026
1. About this page
Exhibitio is operated by Wiktis Pty Ltd. This page explains how to have personal information deleted, what happens when you ask, and the limits that apply.
It sits alongside our privacy policy, which explains what we collect in the first place.
2. Who to ask
It depends on whose data it is, and this trips people up, so it is worth a moment.
- If you hold an Exhibitio account, ask us. We control that information.
- If you bought a ticket or a booth from an organizer, ask the organizer first. They decided what to collect and they control it. We hold it on their behalf.
- If you applied to exhibit and were not approved, the organizer still holds your application. Ask them.
Tell us either way. Where we are the processor we will pass the request to the organizer, help them action it, and delete on their instruction.
3. What you can delete yourself
You do not need to ask us for these. In your workspace you can:
- Delete events, ticket types, booth types, and sponsorship packages you created.
- Delete contacts, budget lines, and uploaded documents.
- Remove team members, which ends their access immediately.
- Disconnect any connected account, which deletes its stored tokens.
- Revoke an assistant access key, which cuts that access immediately.
4. Disconnecting a connected account
Go to Settings, then Integrations, and press Disconnect on the connector. The stored access token is deleted at that moment and we can no longer reach that account.
Data already imported, such as historical advertising spend figures, stays in your workspace until you delete it or close the workspace, because it forms part of your own reporting. Ask us and we will remove it.
Disconnecting here does not remove the app on the provider's side. To be thorough you can also revoke Exhibitio in your Meta, Google, or Xero account settings.
5. How to make a deletion request
Contact us through our company page and include:
- The email address associated with the data.
- What you want deleted: everything, a specific event, a specific order, or a particular record.
- If you are asking as a buyer, the order number from your confirmation email.
You do not have to give a reason. We may need to verify who you are before acting, because deleting someone else's data on an unverified request would be its own privacy failure.
6. What happens when we receive it
- We acknowledge the request.
- We verify your identity, usually by confirming control of the email address.
- We identify what we hold, and whether we hold it as controller or on an organizer’s behalf.
- We delete what we can, and tell you specifically what we cannot delete and why.
- We confirm when it is done.
7. What we delete
- Your account, profile, and sign-in credentials.
- Events, listings, uploaded images, floor plans, and application forms.
- Contacts, budgets, and documents you uploaded, including supplier invoices.
- Access tokens and API keys for connected accounts.
- Analytics events associated with your workspace.
- Support correspondence, where no dispute is open.
8. What we have to keep, and why
Some records cannot be deleted on request, and we would rather say so than promise otherwise.
- Financial records of completed transactions: orders, amounts, tax, and payouts. Australian tax and corporations law requires these to be kept for at least seven years, and that obligation survives account closure.
- Records needed to establish or defend a legal claim, for as long as that claim is live.
- Records we must keep to meet anti-money-laundering, fraud prevention, or sanctions obligations.
- A minimal record that a deletion request was made and actioned, which is how we prove we honored it.
Where we must keep a financial record, we retain the minimum required, and we do not continue to use it for anything other than that obligation.
9. If you bought a ticket
Your purchase created a record in the organizer's workspace and a payment record with Stripe. Ask the organizer to delete your details from their records.
The transaction itself, being a financial record, is kept under section 8. In practice that means your name and email can be removed from an organizer's contact list while the record that an order was placed and paid remains.
Deleting your details will not refund a ticket, and it may prevent the organizer supporting you at the door.
10. If you are an organizer closing a workspace
Before you close, export what you need. Once deleted, we cannot restore it, and neither can our backups after the cycle in section 11.
Closing a workspace does not end obligations to buyers who have already paid. If you have sold tickets to an event that has not happened, deal with those buyers first: run the event, or refund them.
We keep the financial records described in section 8, and delete the rest.
11. Backups
Deleting from the live system does not instantly remove data from backups, because backups exist precisely so they cannot be edited. Backups are purged on a rolling cycle, normally within 90 days, after which the deleted data is gone from those too.
Backups are not used for anything except restoring the service after a failure. If a restore were ever performed, we would re-apply completed deletions.
12. Data held by third parties
Some data necessarily sits with our providers, and deleting from Exhibitio does not delete it from them:
- Stripe holds payment records, and its own retention rules apply. Card details were never held by us.
- Email delivery logs sit with our email provider for a limited period.
- Where you connected Meta, Google, or Xero, those platforms hold their own records under their own policies.
We will tell you which providers are involved in your case so you can approach them directly if you want to.
13. How long it takes
We aim to complete deletion requests within 30 days, which is the outer limit under Australian and European law. Most are done much sooner. Self-serve deletions in your workspace are immediate, as is revoking a token or key.
If a request is complex and we need longer, we will tell you before the 30 days is up, and explain why.
14. If we cannot delete something
We will tell you what we are keeping, the specific reason, and how long we must keep it. We will not simply decline.
If you disagree, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, or to your local supervisory authority. We will cooperate with either.
15. Contact
Deletion requests, and questions about this page, go through our company page. They are handled by Wiktis Pty Ltd as operator of Exhibitio.