Policies and Agreements
Retention and Deletion Policy
Last updated: 20 August 2026
Review date: 20 August 2027
1. Why this document exists
The Localscript Data Processing Agreement promises, at clause 3.2(n), that recordings and transcripts are deleted within 30 days of delivery — including from backups.
This policy is how that promise is kept, and how it can be evidenced when a client or an ethics committee asks. It is the policy referred to at Annex D, paragraph 10 of that Agreement and at section 10 of the Localscript Information Security Policy.
Owner: Montagu Franks, Director.
Order of precedence. Where this policy and a signed Data Processing Agreement differ, the Agreement prevails. Where a client instructs a shorter retention period in writing, that instruction prevails over both.
2. The principle
Two things follow from being a processor rather than a controller:
I keep client material for as long as it takes to do the job, plus a short window to correct it, and no longer. There is no business reason to hold a research recording after the researcher has it back. Keeping it would create risk for the client and no value for either of us.
Deletion means deletion. A file removed from a working directory but still present in a backup has not been deleted. Every retention period below applies to every copy — working files, intermediate files, exports and backups.
3. Client material — the 30-day schedule
| What | Retained | Deleted |
|---|---|---|
| Recordings supplied by the client | 30 days from delivery of the Deliverables | Securely erased, including from backups |
| Transcripts and Deliverables | 30 days from delivery | Securely erased, including from backups |
| Anonymisation logs | 30 days from delivery | Securely erased, including from backups |
| Re-identification keys | Delivered to the client with the Deliverables, then 30 days | Securely erased, including from backups |
| Intermediate processing files — audio segments, diarisation output, draft transcripts | 30 days from delivery, and ordinarily removed as soon as the final Deliverable is produced | Securely erased, including from backups |
| Partial work on a cancelled order | 30 days from cancellation | Securely erased, including from backups |
| Files a client asked me not to start, or that were too poor to transcribe | Deleted on notifying the client, within 7 days | Securely erased, including from backups |
Why 30 days and not immediately. The Terms and Conditions offer free corrections within 14 days of delivery, and correction requires the original audio. Thirty days covers that window with room for a client who is slow to look.
Why 30 days and not twelve months. It is common in this industry to delete audio after a month but retain the transcripts for a year or more by default, with earlier deletion available on request. A transcript of a qualitative interview is not a low-risk artefact — even pseudonymised, it carries the substance of what a participant said. Localscript applies the same 30-day period to recordings, transcripts, logs and keys alike, by default, without the client having to ask.
Why not longer for convenience. I do not keep a copy in case a client loses theirs. Clause 4.4 of the Terms and Conditions asks clients to retain their own copy of every recording, precisely because I will not have one.
4. Earlier deletion on request
A client may instruct deletion at any point before the 30 days expire, in writing, and I will carry it out promptly and confirm in writing.
If deletion is requested before delivery, work stops at that point and the client is charged only for the proportion completed, in accordance with clause 9.2 of the Terms and Conditions.
I do not require a reason.
5. Business records — my own controller-side data
These are records about clients and enquirers, not about research participants. They are held under the Localscript Privacy Policy, not under any Data Processing Agreement.
| What | Retained | Why |
|---|---|---|
| Enquiries that did not become work | 12 months from last contact | Legitimate interests; no reason to hold longer |
| Contact details of people I emailed who did not reply | 12 months | Legitimate interests |
| Suppression list — people who asked not to be contacted | Indefinitely | It only works if it is permanent. Email address only, nothing else |
| Client correspondence and project records — excluding recordings and transcripts | 6 years from the end of the engagement | Limitation Act 1980; contractual claims can be brought within six years |
| Signed Data Processing Agreements and Data Sharing Agreements | 6 years from the end of the engagement | Evidence of the basis on which processing was carried out |
| Invoices, payment and accounting records | 6 years from the end of the accounting period | Companies Act 2006 and HMRC requirements |
| Anonymisation and processing records maintained under Article 30(2) UK GDPR | 6 years, with participant identifiers removed | Statutory record of processing activities |
| Security incident records | 6 years | Accountability under Article 5(2) UK GDPR |
| Complaint records | 6 years from resolution | Limitation Act 1980 — evidence of how a complaint was handled |
Note on the six-year categories. These are business records — who commissioned what, when, for how much. They do not contain recordings, transcripts, anonymisation logs, re-identification keys, or any research participant's personal data. The thirty-day rule in section 3 is not affected by anything in this table.
6. How deletion is carried out
- Working files are deleted from the processing machine and the deletion verified, not simply moved to a trash folder and forgotten.
- Encrypted media. Because storage is encrypted at rest, secure erasure is achieved through deletion of the data together with destruction of the relevant encryption keys — the cryptographic erase method described in NIST SP 800-88 (Guidelines for Media Sanitization) and in National Cyber Security Centre guidance on secure sanitisation. This is the recognised method for verifiably destroying data on modern solid-state storage, where overwriting individual files is unreliable.
- Backups are on a rolling 30-day cycle, so a deleted file ages out of backup within the same window rather than persisting. Backup media that is retired is cryptographically erased or physically destroyed.
- Third-party copies. There are none to delete. Client recordings and transcripts are never transmitted to any external service, so no cloud provider, sub-processor or transcription pool holds a copy that would need to be chased.
- Email. Recordings are never sent or received as email attachments, so no copy exists in any mailbox.
7. Evidence of deletion
On written request, I provide a Certificate of Erasure — a signed written confirmation identifying the files, the date deleted, the method used, and confirmation that backup copies were included. This is a commitment under clause 3.2(n) of the Data Processing Agreement.
There is no charge for it, and there is no charge for early deletion. Both are part of the service rather than an extra.
A short internal deletion record is kept for each engagement — what was deleted and when — for six years, containing no participant data. That record is what makes the confirmation verifiable rather than merely asserted.
8. What happens on termination
On termination or expiry of a Data Processing Agreement, all client material is either returned to the client or securely deleted, at the client's election, and deletion is certified in writing. Any remaining copies are deleted within 30 days. This is clause 6.1 of the Agreement.
Where I become unable to continue — through illness, incapacity or hardware loss — the client chooses between return and destruction, and no other person is given access to their material in order to complete the work. This is clause 3.4 of the Agreement and section 13 of the Information Security Policy.
9. Exceptions
Retention beyond the periods above happens only where:
- the law requires it — for example a court order, or a statutory obligation to preserve records; or
- the client instructs it in writing, in which case the instruction, its reason and its duration are recorded.
Where a legal obligation prevents deletion, I notify the client unless prohibited from doing so.
I do not retain client material because it might be useful, because a project might resume, or for any research, benchmarking, training, marketing or portfolio purpose. That last point is a contractual prohibition at clause 3.2(o) of the Data Processing Agreement, not a preference.
10. Review
Reviewed annually, and additionally whenever the Data Processing Agreement changes, the backup arrangement changes, an incident occurs, or a client identifies a gap.
Questions about this document? Email {{ contactEmail }}.