AI Springboard Client Data Protection Policy
Last updated: 09/09/2026 | Version 1.2
About This Policy
This policy explains how AI Springboard handles personal data belonging to client organisations and their people, for example employees, workshop attendees and survey respondents, during the course of an engagement. It is written for prospective and current clients carrying out due diligence before or during working with us.
This is a summary. It sits alongside our Privacy Policy, which covers all personal data we process in full detail and takes precedence over this document on lawful basis, data subject rights and processing purposes. A fuller version of our data handling practices, including specific security and sub-processor arrangements, is available on request as part of contracting with us.
What This Covers
This policy applies to personal data provided to us, or collected by us, in the course of delivering our services, including:
- AI Readiness Snapshot survey responses and the resulting Report
- Workshop, training and coaching delivery, including attendance, feedback and assessment records
- Documents and information shared with us as part of a consultancy or strategy engagement
Our Role
For the personal data we collect directly through our own tools, such as Snapshot survey responses, we act as a data controller, since we decide how that data is used to produce your Report. Where an engagement requires us to process data under your specific instructions, for example analysing a data set you provide, we act as a data processor on your behalf, under the terms agreed for that engagement.
How We Keep Client Data Safe
- Client data is stored within Microsoft 365 and SharePoint, protected by Microsoft’s security and encryption controls
- Access is limited to those directly involved in delivering your engagement
- Where AI tools are used to support delivery, personal data is not used to train third-party models
- The service providers we may share data with are the same as those listed in our Privacy Policy, including Microsoft 365, OpenAI and Anthropic
How Long We Keep Engagement Data
We keep personal data only for as long as necessary for the purpose it was collected for. The table below sets out our current retention approach by category.
| Data category | Suggested retention | Basis |
|---|---|---|
| Enquiry or initial contact details that don't become a client engagement | 12 months from last contact, then deleted | No longer necessary once the enquiry goes cold |
| AI Readiness Snapshot survey responses and generated Report | 2 years from delivery of the Report | Supports follow-up discussion and any re-assessment comparison |
| Workshop and training records: attendance, feedback, assessment results | 2 years from the session | Supports reference and any accreditation needs |
| General engagement correspondence and records | 6 years from the end of the engagement | Limitation Act 1980 time limit for contract-related claims |
| Contracts, invoices and financial records | 6 years from the end of the relevant tax year | HMRC and Companies Act record-keeping requirements |
Your Right to Erasure
You can ask us to delete your personal data at any time. In many cases we will. However, the right to erasure under UK GDPR is not absolute: we may need to retain some information despite a deletion request, for example financial records we are legally required to keep, or information needed to establish or defend a legal claim. Where this applies, we will tell you what we are retaining and why.
We will respond to any request to exercise your data protection rights, including erasure, within one calendar month of receiving it. Where a request is complex, we may extend this by up to a further two months, and we will explain why within the first month if that happens.
Breach Notification
If a breach affecting your data occurs, we will assess it without undue delay, notify you where it is likely to affect you, and notify the Information Commissioner’s Office where we are required to do so.
Request the Full Policy
If you would like more detail on our data handling practices ahead of engaging us, including our approach to data processing agreements, contact us and we will provide our full Client Data Protection Policy as part of the engagement process.
Related Policies
This Client Data Protection Policy forms part of a wider set of website policies, including our Privacy Policy, Cookie Notice and Terms of Website Use. Where any of those documents addresses a topic in more detail, that document takes precedence on that specific point.
Changes to This Policy
We may update this policy from time to time. The most recent version will always be available on our website and will include the latest revision date.
Contact
AI Springboard Ltd: info@aispringboard.co.uk. If you have any questions about this policy, please contact us using the details above.