13. Retention
We retain personal data only while reasonably necessary for the relevant purpose and thereafter where required for law, audit, tax, accounting, security, insurance, dispute management or legal claims. We consider the amount, nature, sensitivity, risk, purpose, relationship, applicable limitation periods and legal retention duties.
Our typical target periods are:
| Record | Typical target period |
| Unsuccessful general inquiry | Up to 24 months after the last substantive interaction |
| Client and supplier contracts, key approvals and project business records | Contract term and normally 7 years after it ends, or longer where law or a dispute requires |
| Invoices, tax and accounting records | Period required by applicable tax, accounting and commercial law, normally at least 7 years where applicable |
| Website and security logs | Normally up to 12 months, unless required for an active security event or claim |
| Marketing records | Until opt-out, invalidity or prolonged inactivity; limited suppression data may be retained to honour the opt-out |
| Recruitment records for an unsuccessful applicant | Normally up to 12 months after the process, unless consent or law supports a different period |
| Client-controlled project data | The SOW, Data Processing Addendum and documented client instructions; backup deletion may follow a defined cycle |
| Cookie and consent records | The duration stated in the Cookie Notice and as needed to demonstrate and respect choices |
These are target periods, not promises to retain every record for the maximum period. Data may be deleted earlier when no longer needed, or retained longer where a legal hold, investigation, unpaid account, complaint or claim applies. At the end of retention, data is deleted, securely destroyed or irreversibly anonymised.