← Policies & standards

GDPR, Information Deletion & Data Retention Policy

Updated for cloud, prompts, agents and generated outputs

Version: 2.0 Updated: 06 August 2026

1. Purpose and scope

This policy explains how TFG handles personal data under the UK GDPR and Data Protection Act 2018, including data used in cloud, advertising, analytics, automation and approved AI-enabled services. It applies to personnel and third parties processing personal data on behalf of TFG or its clients.

2. Principles

Lawfulness, fairness and transparency.

Purpose limitation and data minimisation.

Accuracy and controlled correction.

Storage limitation and defensible deletion.

Integrity, confidentiality and accountability.

3. AI and prompt data

A prompt, source document, chat history, output, evaluation or feedback item may contain personal data and must be handled according to its content, purpose and classification. Personnel must not enter personal data into an unapproved AI tool. Approved use must have a documented purpose, appropriate lawful basis or client instruction, minimised content, access control and retention treatment.

4. Retention schedule

Data type

Standard retention

Control

Client campaign data

24 months from campaign end

Secure deletion after reporting, benchmarking and audit needs expire.

Third-party platform data

Platform retention window, typically 24 months

Held under platform terms; export aggregated data only unless contractually approved.

Client audience / CRM lists

Delete after activation or upload; maximum 90 days in staging

No local retention beyond operational need; client/platform controls deletion.

Analytics, insight and attribution data

Up to 3 years

Retain aggregated or anonymised form where possible.

AI prompts, outputs and evaluations

Purpose- and system-specific; no longer than the approved service need

Apply platform configuration, contract and data classification. High-risk items may be retained as incident, audit or quality evidence.

Agent configuration and audit logs

Defined by security, contractual and operational need

Protect access; retain sufficient evidence for security, audit and accountability.

Supplier and partner records

6 years after contract end

Legal and financial record keeping.

Incident and breach records

6 years from closure

Governance and accountability.

Client correspondence and contracts

6 years after contract end

Contractual limitation period.

5. Data-subject rights and requests

TFG will support lawful data-subject requests and client controller obligations. Where personal data may exist within prompts, logs, outputs or knowledge sources, the responsible owner must identify relevant systems and coordinate search, correction, restriction, export or deletion with Privacy/Legal and the service provider as applicable.

6. Deletion

Permanent erasure from approved systems and cloud storage.

Secure device wiping or certified physical destruction where relevant.

Deletion or revocation of client-provided audience lists and connectors.

Verified deletion evidence from processors where contractually required.

Removal of data from retrieval indexes, caches and knowledge stores where technically supported and required.

7. Breach management

Suspected breaches must be reported immediately, logged and handled under the Incident Response Plan. Where the reporting threshold is met, notification to the ICO will be made within 72 hours of awareness. Client notification follows legal and contractual duties.

8. Roles and review

The Operations Director / ISMS Lead coordinates policy operation. Information owners and AI/Product Owners define purpose and retention. IT/Security implements technical controls. Privacy/Legal advises on lawful basis, contracts and rights. The policy is reviewed annually and after material legal, process, supplier or technology change.