1. Purpose and scope
This policy explains how TFG handles personal data under the UK GDPR and Data Protection Act 2018, including data used in cloud, advertising, analytics, automation and approved AI-enabled services. It applies to personnel and third parties processing personal data on behalf of TFG or its clients.
2. Principles
Lawfulness, fairness and transparency.
Purpose limitation and data minimisation.
Accuracy and controlled correction.
Storage limitation and defensible deletion.
Integrity, confidentiality and accountability.
3. AI and prompt data
A prompt, source document, chat history, output, evaluation or feedback item may contain personal data and must be handled according to its content, purpose and classification. Personnel must not enter personal data into an unapproved AI tool. Approved use must have a documented purpose, appropriate lawful basis or client instruction, minimised content, access control and retention treatment.
4. Retention schedule
Data type
Standard retention
Control
Client campaign data
24 months from campaign end
Secure deletion after reporting, benchmarking and audit needs expire.
Third-party platform data
Platform retention window, typically 24 months
Held under platform terms; export aggregated data only unless contractually approved.
Client audience / CRM lists
Delete after activation or upload; maximum 90 days in staging
No local retention beyond operational need; client/platform controls deletion.
Analytics, insight and attribution data
Up to 3 years
Retain aggregated or anonymised form where possible.
AI prompts, outputs and evaluations
Purpose- and system-specific; no longer than the approved service need
Apply platform configuration, contract and data classification. High-risk items may be retained as incident, audit or quality evidence.
Agent configuration and audit logs
Defined by security, contractual and operational need
Protect access; retain sufficient evidence for security, audit and accountability.
Supplier and partner records
6 years after contract end
Legal and financial record keeping.
Incident and breach records
6 years from closure
Governance and accountability.
Client correspondence and contracts
6 years after contract end
Contractual limitation period.
5. Data-subject rights and requests
TFG will support lawful data-subject requests and client controller obligations. Where personal data may exist within prompts, logs, outputs or knowledge sources, the responsible owner must identify relevant systems and coordinate search, correction, restriction, export or deletion with Privacy/Legal and the service provider as applicable.
6. Deletion
Permanent erasure from approved systems and cloud storage.
Secure device wiping or certified physical destruction where relevant.
Deletion or revocation of client-provided audience lists and connectors.
Verified deletion evidence from processors where contractually required.
Removal of data from retrieval indexes, caches and knowledge stores where technically supported and required.
7. Breach management
Suspected breaches must be reported immediately, logged and handled under the Incident Response Plan. Where the reporting threshold is met, notification to the ICO will be made within 72 hours of awareness. Client notification follows legal and contractual duties.
8. Roles and review
The Operations Director / ISMS Lead coordinates policy operation. Information owners and AI/Product Owners define purpose and retention. IT/Security implements technical controls. Privacy/Legal advises on lawful basis, contracts and rights. The policy is reviewed annually and after material legal, process, supplier or technology change.