Privacy by design

Customer Data Lifecycle

A plain-English view of how customer information should move through a consulting engagement. Exact systems, subprocessors, retention and transfers depend on the contracted service.

1. Define

Purpose, data categories, roles, confidentiality and minimum necessary access are agreed for the engagement.

2. Receive

Customer information enters approved systems/channels appropriate to the scope; unnecessary copies should be avoided.

3. Use

Authorised people and systems process data only for the agreed delivery purpose, subject to least privilege and contractual controls.

4. AI boundary

AI use is governed by approved environment/provider, data sensitivity, retention/training settings, human review and client/contract requirements. Client data is not silently repurposed for Raeburn research or model training.

5. Suppliers

Where a subprocessor or specialist is genuinely required, the processing purpose, data, safeguards and contractual status are assessed for the actual service.

6. Retain

Retention follows purpose, contract, security, record-keeping and legal requirements rather than indefinite storage by default.

7. Return / export

At handover or exit, agreed data and deliverables are returned/exported in practical formats where appropriate and client access/ownership is preserved.

8. Delete / close

Deletion, anonymisation, access removal and residual backup/legal-retention obligations are handled according to the agreed terms and applicable requirements.