# Task26 service withdrawal and deletion procedure

## Binding

- Full candidate: `4e9962be49b72951c3b9ed7e1a4fe36d0ca03e757872ae03364c1ab7a790f32b`
- Customer: `task26_live_2e_r2_20260815_8527916639`
- Profile: `/home/cube/.hermes/profiles/dualcoachtest`
- Scope: the bounded Task26 rehearsal only

## Customer-facing handling

When the customer requests service withdrawal, consent withdrawal, or deletion, the operator first disables new coaching delivery, scheduled jobs, and retries. The operator acknowledges the request and stop time no later than the next business day without requesting new sensitive information.

The operator confirms whether the request covers service stop only, processing-consent withdrawal, or deletion of deletable customer information. Deletion scope is processed within seven days after scope confirmation.

If law, payment, security, or misdelivery investigation requires retaining a record, the operator tells the customer the retained category, reason, access boundary, and retention end date before completing the request. Retained records are not reused for coaching generation or customer delivery. Backup copies receive a stated rotation and deletion date.

The completion response states:

- service and schedule stop time;
- deleted data categories;
- retained categories, reasons, and end dates;
- backup deletion date;
- failed items and their follow-up deadline.

## Operator procedure

1. Record the request time, customer key, and a digest of the request.
2. Disable the customer and verify that delivery, scheduled jobs, and retries cannot run.
3. Verify the request actor against the existing Telegram route and customer key.
4. Delete or de-identify active onboarding answers, check-ins, nutrition plans, scheduled work, pending outbox entries, and customer-derived data within seven days.
5. Isolate required retention exceptions with least-privilege access, a reason, and an explicit end date. Never restore them for coaching or delivery.
6. Record the backup rotation date and block retained backup copies from operational restoration.
7. Produce a completion receipt containing request, stop, and completion times; deleted scope; retained exceptions; backup date; failures; and follow-up deadline.
8. Revalidate that the customer is disabled, no future work or pending delivery remains, and unrelated profiles are byte-identical.

## Activation assertion

This document satisfies only the `withdrawal_deletion_doc` operational-document assertion. It does not assert that a withdrawal or deletion has occurred.
