Data map
SPRA should maintain a record of what data is held, where it is stored, why it is processed, who can access it and which systems or processors are involved.
This page explains how Strategic Policy & Risk Advisory manages data processing and retention across the website, advisory services, intelligence subscriptions, client portal, secure documents, support tickets, events and business records. It is designed to support clear governance, data minimisation, storage limitation and client confidentiality.
SPRA aims to process only the data needed for a defined purpose, keep records for no longer than necessary, restrict access by role and organisation, protect client documents, document consent and audit activity, and delete, return or anonymise data when retention is no longer justified.
This page applies to operational records created or received through SPRA’s website and services, including contact forms, request consultation forms, advisory requests, due diligence requests, tender and funding watch requests, public opinion and research enquiries, executive briefing requests, newsletter records, event registrations, client portal accounts, subscriptions, support tickets, secure documents, report downloads, billing records, consent logs and audit logs.
This page should be read together with the Privacy Notice, Cookie Policy, Terms of Use and any client contract or data processing terms agreed for a specific engagement.
SPRA may act as a controller where it determines why and how personal data is processed, for example when managing website enquiries, subscriptions, events, direct client relationships, billing records, security logs and general business administration.
SPRA may act as a processor where it processes personal data strictly on behalf of a client and under that client’s documented instructions. In that case, processing should be governed by written terms covering the subject matter, duration, nature and purpose of processing, types of personal data, categories of data subjects, confidentiality, security, sub-processors, assistance with rights requests, breach support, deletion or return at the end of the service and audit/inspection rights where applicable.
Where an engagement involves sanctions, integrity due diligence, public opinion research, stakeholder mapping or sensitive client documents, the client instruction and scope should define what data may be used, the permitted sources, access controls, confidentiality level and retention outcome.
SPRA should maintain a record of what data is held, where it is stored, why it is processed, who can access it and which systems or processors are involved.
Processing should be connected to a clear purpose and lawful basis, with additional checks before special category or criminal offence data is processed.
Portal and document access should be role-based, organisation-based and subscription-aware, with administrative access limited to authorised staff.
Key actions such as account access, document upload/download, consent, support activity and material administrative changes should be logged where technically enabled.
SPRA does not keep personal data indefinitely “just in case”. Retention is based on the purpose of the record, client contract terms, legal or accounting requirements, security needs, dispute risk, audit obligations and whether the record is still needed for an active service or relationship.
| Record category | Retention trigger | Retention approach | End-of-retention action |
|---|---|---|---|
| Website enquiries and consultation requests | Submission date or last meaningful contact. | Kept while the enquiry is active and for a justified business follow-up period. | Delete, anonymise or move to client record if an engagement begins. |
| Client contracts, advisory requests and project records | End of engagement, contract closure or final deliverable. | Kept for the period needed to deliver services, manage the client relationship, evidence instructions and handle legal or contractual issues. | Archive under restricted access, delete, anonymise or return where required by contract. |
| Due diligence, sanctions and integrity case material | Case closure or client instruction. | Reviewed carefully because material may be sensitive, source-dependent or subject to client confidentiality requirements. | Delete, return, anonymise or retain only where there is a clear legal, contractual or audit justification. |
| Client portal accounts, permissions and support tickets | Account closure, organisation relationship end or ticket closure. | Kept while the account, organisation or support issue is active, then reviewed for deletion, anonymisation or restricted retention. | Disable account access, preserve necessary audit/security records and remove unnecessary profile data. |
| Reports, alerts and download logs | Subscription end, report archive date or access expiry. | Kept to administer access, evidence delivery, protect intellectual property and maintain security records. | Remove access, anonymise usage data where possible or retain minimal audit evidence. |
| Billing, invoice and accounting records | Financial year, transaction date or statutory record requirement. | Kept in line with applicable UK company, accounting, tax and VAT record requirements. | Delete or securely archive after statutory and audit needs expire. |
| Newsletter and marketing preferences | Subscription, unsubscribe or consent update. | Kept while communications are active and as needed to evidence consent or suppression preferences. | Delete unnecessary profile data; retain minimal suppression record where needed to avoid unwanted contact. |
| Security logs, audit logs and consent logs | Log creation date or security event closure. | Kept only as long as needed for security, audit, compliance, dispute handling and evidence of consent. | Delete, aggregate or anonymise when detailed logs are no longer justified. |
| Backups | Backup creation date. | Kept under a controlled backup cycle and restored only for operational, security or continuity reasons. | Expire through backup rotation or secure deletion process. |
Exact retention periods must be maintained in SPRA’s internal retention schedule and may vary by contract, law, record type, dispute status, audit requirement and client instruction. Where legal retention is required, deletion may be delayed until that obligation ends.
SPRA should protect retained records through proportionate technical and organisational measures, including role-based access, organisation-based portal permissions, private storage for sensitive documents, secure upload validation, signed or controlled downloads where available, audit logging, administrator access controls and regular review of user access.
When data is no longer required, SPRA should delete, anonymise, aggregate, return or archive it under restricted access. Secure deletion should take account of backups and system logs, where deletion may occur through scheduled retention and backup rotation rather than immediate removal from every copy.
SPRA may use third-party systems for hosting, email, storage, security, analytics, payment processing, document handling, client portal operation and professional support. Where such providers process personal data on SPRA’s behalf, SPRA should assess them, maintain appropriate contractual terms and review whether international transfer safeguards are needed.
Individuals may ask SPRA about retention, request access to personal data, request correction, object to certain processing, request erasure where applicable or withdraw consent where processing is based on consent. Some requests may be limited where SPRA must retain records for legal, contractual, security, audit or dispute reasons.
For questions about data processing or retention, contact SPRA at info@strategicpolicyrisk.com or by telephone at +44 204 577 00 16.
Registered office: 4 St. Lukes Yard, London, England, W9 3AN