Last updated: June 2026
This policy sets out how Gem Roberts, trading as Gem Roberts – Systems Strategist, manages and deletes personal data in compliance with UK GDPR and the Data Protection Act 2018. It applies to all personal data processed in the course of running this business and delivering services to clients.
The table below sets out each category of personal data, the lawful basis for retention, the retention period and the deletion process.
Data Category | Lawful Basis | Retention Period |
|---|---|---|
Client project files (emails, notes, scope docs, deliverables) | Contract performance / Legal obligation | 6 years from project completion |
Financial records (invoices, Stripe records) | Legal obligation (HMRC) | 6 years from end of relevant tax year |
Signed scope confirmation documents | Legal obligation / Legitimate interests | 6 years from contract date |
Intake form submissions (Tally) | Contract performance | Duration of project + 6 years |
Booking records (Tidycal) | Contract performance / Legitimate interests | 6 years from booking date |
Session recordings (Boom) | Contract performance | 21 days from session date then permanently deleted. Clients have 14 days to download. See Section 3 below. |
Email marketing list (MailerLite) | Consent | As long as consent is active. Removed within 30 days of unsubscribe. |
Unconverted enquiry data (email, contact form) | Legitimate interests | 12 months from last contact |
Google Analytics data (planned) | Consent | 26 months (GA default) |
Mouseflow session recordings | Consent | 30 days (Mouseflow free tier default) |
Testimonial and project win consent records | Consent | As long as material is in active public use, then 1 year after removal |
Session recordings made during Power Hours, Diagnostic Consultation and any other live session products are subject to the following retention timeline. Full terms relating to session recordings are set out in our Client Terms of Service.
Under UK GDPR you have the right to:
To exercise any of these rights, contact legal@gemroberts.co.uk. We will response within one calendar month.
If you have booked a session via Tidycal and wish to request erasure of your booking data, you can also submit a direct erasure request at tidycal.com/gdpr, or contact us, and we will request it on your behalf
If you are unhappy with how we have handled your personal data, you have the right to complain directly to us at legal@gemroberts.co.uk. We will acknowledge your complaint within 30 days of receipt and fully respond with undue delay.
If you remain unhappy following our response, you have the right to complain to the Information Commissioner’s Office (ICO):
In the event of a personal data breach affecting you data, we will notify the ICO within 72 hours where the breach is likely to result in a risk to your rights and freedoms. Where a breach is likely to result in a hugh risk to you personally, we will notify you directly without undue delay with details of what happened and the steps we are taking to address it.
The policy will be reviewed annually and updated whenever the business changes its platforms, services or data handling policies. That date at the top of the page reflects the most recent update.