Status: This page was generated from Intuitus_AudienceLens_Data_Retention_Statement.docx. Check document version and legal status before relying on it.

AudienceLens Data Retention Statement

Intuitus Ltd | Working draft | 23 May 2026 | Version 0.2

Prepared for practical customer/procurement use. Working draft for legal and technical review before signature or publication.

Status and use
This is a customer-facing retention statement and internal schedule baseline. It should be checked against the final production stack, database, backups, analytics tools, support/CRM, AI/model provider terms, customer contract and legal/accounting advice before publication.

1. Summary position

AudienceLens is designed primarily for communications material that is intended to become public or externally distributed. This reduces the typical confidentiality risk compared with systems for safeguarding, health, donor financial, HR or case-management records. However, AudienceLens may still process personal data, pre-publication drafts, user account data, organisation context, support records, technical logs and incidental personal data contained in customer-submitted content.

Intuitus Ltd therefore keeps personal data only for as long as needed to provide AudienceLens, support customers, maintain security, meet legal/accounting requirements, resolve disputes and improve service reliability where permitted.

2. Scope

3. Customer-facing retention schedule

Data categoryRetention periodNotes
Demo and sales enquiries24 months after last meaningful contactShorten/delete sooner where no active pipeline exists. Honour opt-outs.
Customer account/contract recordsContract term + 6 yearsUsed for contract, billing, tax, limitation and dispute records. Confirm with accountant/solicitor.
Authorised user profile/account dataContract term + 90 days after account closureMinimal audit/security records may be retained longer where needed.
Customer message drafts and workspace contentContract term + 60 days after terminationCustomer admins should be able to delete sooner where technically supported.
Reports, scenarios, comparisons and version historyContract term + 60 days after terminationCore product history. Delete sooner on customer instruction where technically supported.
Autosave snapshots and collaboration eventsContract term or shorter operational rolling periodConsider shorter rolling retention for autosaves once product behaviour is final.
AI prompts, outputs and related metadataSame as related customer content unless provider terms require shorter operational retentionConfirm model provider retention, deletion and training terms before publication.
Security and audit logs12 months by default; up to 24 months for security, fraud, abuse or investigation needsKeep access restricted; minimise content in logs.
Support tickets3 years after closureRedact or delete customer content/screenshots where no longer needed.
Analytics/product usage events24 months, with aggregation or anonymisation earlier where feasibleNon-essential analytics require cookie/privacy review.
Cookie consent records12 months after consent choice or until renewedAlign with consent management platform configuration.
Backups90 days rolling overwriteDeleted in ordinary course; not restored solely to delete individual records unless required and feasible.
Legal/regulatory/accounting recordsAs required by law or legitimate business needRetain only what is necessary and restrict access.

4. Deletion and return on termination

5. Customer deletion controls

Recommended product position: customer admins should be able to delete projects, scenarios, message drafts, reports and user accounts where technically supported. Where deletion is not available in-product, customers should be able to request deletion via support.

Implementation note
Before publication, confirm the actual product controls for deleting projects/scenarios/reports/users, export options, backup overwrite behaviour and whether deleted records remain in logs, analytics or model-provider systems.

6. AI/model provider retention

Before launch/publication, Intuitus Ltd should confirm and document the following for each AI/model/API provider:

Default customer position: customer content is not used to train third-party or Intuitus Ltd models unless expressly agreed in writing.

Intuitus Ltd may suspend routine deletion where necessary for:

Where a hold applies, Intuitus Ltd should retain only what is necessary, restrict access, document the reason, and remove the hold when no longer needed.

8. Security of retained data

9. Annual review

This schedule should be reviewed at least annually and whenever AudienceLens changes materially, including changes to hosting, database, backups, analytics, AI/model providers, customer deletion controls, support tooling, or target customer sectors.

10. Short website/security-pack wording

Customer-facing wording
AudienceLens is primarily used for communications material intended for publication or external distribution. Intuitus Ltd keeps personal data only for as long as needed to provide the service, support customers, maintain security, meet legal/accounting requirements and resolve disputes. Customer workspace content is normally retained for the contract term and deleted or returned within 60 days after termination, with backups overwritten in the ordinary course, normally within 90 days. Users should not upload special category data, children data, safeguarding records, health records, donor financial records, HR files or confidential case-management data unless this has been expressly agreed and assessed.