Legal

Account and data deletion

Last updated 31 August 2026

You can ask us to delete your iqava account at any time, and you do not have to give a reason. This page sets out how to ask, what happens next, what is removed, and the narrow set of records that are kept afterwards because the law requires it.

Customers — the wallet and the iqava app

This covers a personal account at my.iqava.com or in the iqava Android app: the account you use to buy cover, hold policies and report a claim.

To delete it, do one of the following:

We reply within 5 working days to confirm the request came from you, and to tell you exactly what will be removed and what has to be kept. Deletion is completed within 30 days of that confirmation. Nothing is deleted until you confirm, so a request sent in error can simply be withdrawn.

What is deleted

  • Your sign-in credentials, and every active session and device.
  • Your profile: name, email, phone, date of birth, ID and tax numbers, address.
  • Assets you saved for pre-filling applications, such as vehicle details.
  • Documents you uploaded that are not part of a policy or claim record.
  • Applications and quotes that never became a policy.
  • Notification and marketing preferences, and any pending messages.

What is kept, and why

Some records are not ours to erase. Where you actually bought cover, the insurer or broker who issued it is the controller of that record and is required by insurance and anti-money-laundering law to retain it — typically for seven years after the policy ends or a claim closes, depending on the country.

  • Policies that were in force, and their schedules and certificates.
  • Claims that were made, and how they were settled.
  • Payments and refunds, which are accounting records.
  • Audit entries recording that an action happened. These are what make the system trustworthy; deleting them on request would defeat their purpose.

These are held by the provider you bought from, under their own privacy policy. After your iqava account is deleted they are no longer linked to a login, and you would deal with that provider directly about them. We will tell you which providers these are as part of confirming your request.

Get a copy first

Deletion is final. If you want your documents, ask for an export in the same message and we will send it before deleting anything — you do not have to make a second request.

Businesses — closing a workspace

This covers an organisation's workspace on console.iqava.com or at {slug}.iqava.com.

Write to [email protected] from an administrator address on the account. Because a workspace holds records belonging to the organisation's own clients, we will not act on a request from a single member without administrator authority.

We take a final export and hand it to you, confirm what your regulator obliges you to retain, and then remove the workspace. Your data is deleted within 30 days of that hand-over. Deleting an individual user of a workspace is different and is done by your own administrator, in the console under Administration.

If we cannot delete something

We will say so, name the record and the obligation that requires it, and give you the date it can be deleted. You can also complain to your data protection authority — in Kenya, the Office of the Data Protection Commissioner.

See also our Privacy Policy and Customer Terms.