ABOUT DÆTRAX
BUILT FOR THE WORLD
AS IT IS.
DÆTRAX is a personal data accountability ledger: a dated record of which companies hold your personal data, what you asked them to do about it, and what they claimed in reply. Four facts about the data economy we won't pretend otherwise about; the ledger is designed around them.
Retention is likely.
Most companies keep some version of your data after you ask them to delete it: legal holds, fraud prevention, accounting, backups, suppression lists, training corpora. That's not a bug in the system. It is the system. Companies keep ledgers of you to protect themselves. You should keep one too.
Brokers continuously re-enrich.
Data isn't a one-time gift. It's bought, sold, re-aggregated, joined to other data, and resold. A deletion that works today holds only as long as the suppression list that enforces it. The data economy keeps running whether you opt out or not.
Data fragments below the deletion line.
Backups expire on their own schedules. Cross-border transfers leave copies no single regulator covers. Training corpora include what was already absorbed. Full erasure is not a promise any company can keep, and the honest ones say so in their policies if you read closely.
DÆTRAX is the receipts.
We don't sell deletion. We sell standing: a dated record of what you gave, when, where, what you asked for back, and what they said. The value isn't that your data disappears. The value is that you hold the evidence, on your own timeline.
THE TWO-HANDED REGULATOR.
One hand gives you rights. The other lets them keep it anyway.
Modern compliance regimes convert ordinary users into persistent risk records. The default assumption baked in is that any user might commit fraud, evade tax, or break platform rules, so the company retains data on those grounds whether you've done anything or not. The privacy regulator hands you rights with one hand; the financial regulator, the criminal-justice system, and platform-integrity rules hand the company retention duties with the other. Both are enforced. The company sits between them and tells you what it had to keep.
No third party can make the carve-outs go away; they override a service's requests the same way they override yours. What changes is whether you have a record of what was kept, why, and when each retention period should actually expire. Only you know where your data went and what you handed over.
THE RIGHT HAND
What you can ask for.
- See what they have on you
- Ask for deletion
- Object to processing
- Ask how long they keep it
THE LEFT HAND
Why they keep it anyway.
- Anti-fraud and criminal-investigation retention
- “Legitimate interest”, the catch-all
- Tax and accounting obligations
- Know-your-customer compliance
- Safety, abuse and moderation logs
- Legal hold and defence of claims
- Suppression lists, kept to honour your opt-out
THE MOMENT PASSES. THE FILE DOESN'T.
The heaviest collection happens at moments you could not refuse: proving who you are, interviewing for a job, verifying your age. What the moment collects, the file keeps.
The identity check.
Proving your age or identity is a checkpoint: the document scan, the selfie, the liveness video. The checkpoint ends; the copies often don't. Identity data collected to pass one gate has a way of finding second jobs: fraud systems, shared databases, verification providers you never dealt with directly. The pattern is mission creep, and the only way to see it is to ask the company what it still holds.
THE FINE PRINT · IDENTITY VERIFICATIONThe video interview.
A video interview collects your face, your voice, your setting, and an hour of how you think under pressure. Of ten video-interview policies we read in 2026, five never say whether AI analyses the recording, including vendors that advertise AI scoring on their marketing pages, and stated retention runs from eight weeks to two years, hired or not. The reply to an access request is the only instrument that answers what the policy won't.
FROM THE DISPATCH · IT ASKED YOU EVERYTHINGThe closed account.
Closing an account ends the relationship, not the record. Policies keep what defends the company: the ban you disputed, the messages that led to it, the device and network identifiers that stop you coming back. Deleting the app deletes the icon.
The anonymisation exit.
When a deletion request is answered with “we will anonymise it instead”, the data is not gone: it is kept, with the obvious identifiers stripped. Re-identification of supposedly anonymised records is proven, not theoretical. The ledger logs the claim as made; if the company insists its anonymisation is irreversible, that insistence goes on the record too, dated, in their own words.
None of these moments can be un-lived. All of them can be asked about.
WHY KEEP A RECORD.
For when things eventually break.
Companies tell you they deleted. The data persists in backups, suppression lists, fraud systems, training corpora. Then one day it resurfaces:
- A breach years later.
- An unsolicited contact from a partner you've never heard of.
- A marketing email after you cancelled.
- A regulator complaint that needs evidence.
Your record is the proof of what you asked, what they confirmed, and what they kept. Most people have no record. That's the gap.
The right to ask: where did you get my data?
Your contact details flow through broker markets at pennies per record. That's the cold calls, the cold emails, the “personalised” ads from companies you've never spoken to. When a company you didn't sign up to contacts you, you can ask: where did you get my data, who else has it, and on what grounds.
The right exists in most modern data-protection law, clearest in the UK, EU, California, Brazil, and Canada. DÆTRAX makes it usable without thinking about statutes.
The reply is a claim. Log it like one.
You cannot see inside a company's systems. When it writes back “deleted”, that is a claim, not an observation, and no service on earth can verify it from the outside. What you can hold is the claim itself: what they said, when they said it, in writing, in your own inbox.
The law was never a promise that your data is gone. It is the power to make them answer you, on a date, in writing. DÆTRAX is where the answers accumulate.
WHAT IT DOES. WHAT IT WON'T.
Drafts the request.
Plain English, no jargon. The wizard writes a letter that asks what they hold, what they kept, and for how long. You copy it into your own inbox and send.
Holds the outcomes you log.
Log what came back: the reply, the refusal, or the silence. The dates stay intact even when your inbox doesn't.
Keeps their claims on file.
Retention grounds, anonymisation assurances, deletion dates: whatever a company states in reply is logged as its claim, dated. If the data resurfaces later, their own words are already on file.
Sends the monthly record.
Once a month: what you logged, what's still open, and which response deadlines are coming up.
Send anything for you.
The right is yours, and so is the context that makes it useful. A request from your own inbox carries weight an automated submission never will. We draft the words; you press send.
Promise deletion.
We record what you asked, what they said, and what they kept. If anyone tells you your data can simply be wiped from the economy, read the carve-outs.
Dress up as your lawyer.
The company already knows what law applies to you. Plain English asking for a dated answer is what gets a useful reply.