Strategy&Consult

Data Retention Notice

Public retention principles and default schedule

Effective: 4 August 2026 | Version: 1.0

Principles

We retain personal data only as long as necessary for the purpose collected, legal/accounting obligations, security, complaints and claims. The schedule below states defaults, not automatic minimums. Shorter periods apply where data is no longer necessary; longer retention requires a documented law, contract, legal hold or defensible need.

Record Category Default Period Start / Disposal Rule
General website enquiries 24 months From last meaningful contact; delete sooner if resolved and no relationship/claim need
Prospect, proposal and business-development records 24 months From last activity or decision; suppression record retained separately
Marketing consent and suppression Consent evidence: consent life plus 6 years; suppression: while needed to honour opt-out Minimise suppression to contact identifier and preference
Cookie consent records Configuration/consent life plus up to 6 years Delete or anonymise when no longer needed to demonstrate compliance
Website/security logs Typically 12 months Shorter where operationally sufficient; longer only for active security investigation
Unsuccessful recruitment 6 months From recruitment decision; delete unless claim/complaint or separate talent-pool choice
Recruitment talent pool 24 months Separate optional choice; renew before extension
Successful recruitment Move relevant records to personnel file Delete duplicate/non-relevant application material
Client contracts, core deliverables and engagement correspondence 7 years From completion/termination, subject to contract, professional/local law and legal hold
Invoices, tax and accounting records 7 years From end of relevant accounting period or longer if law requires
Client data processed only on instruction Contract/instruction period Return or delete at end of service unless law requires retention
Rights requests and privacy complaints 6 years From closure; retain decision trail and identity evidence only as necessary
Security incidents and breach decisions 6 years From closure; longer for litigation/regulatory action
Backups Controlled rotation, typically 35–90 days Expire automatically; restoration re-applies deletion controls

How decisions are made

  • Purpose and current relationship; volume, sensitivity and risk of harm.
  • UK, EU, Saudi and other legal/accounting requirements; contractual and insurance terms.
  • Limitation periods, complaints, audits, investigations and expected claims.
  • Ability to anonymise or aggregate instead of retaining identifiable data.
  • Backup constraints and verified secure deletion methods.
Legal holds and deletion

An authorised legal hold suspends routine deletion for identified records and custodians. The hold is documented, access-restricted, reviewed and released promptly when no longer required. At expiry, data is securely deleted, destroyed or irreversibly anonymised across active systems; backup copies expire through rotation and are protected from ordinary use.

Requests and contact

A retention period does not override applicable rights. Contact info@strategyandconsult.com to ask about a specific record or request deletion. We may retain limited information where a lawful exemption, claim, legal duty or suppression need applies and will explain this where permitted.