Subscribe to GEN
Login to GEN
This Policy sets out how long GEN keeps each category of record it holds, when that period starts, why the period is what it is, and what happens at the end of it. It applies to records GEN holds as controller in its own right and, where stated, to records GEN holds as processor on a Customer's behalf.
It carries the retention periods that Article 13(2)(a) of the UK GDPR requires the Privacy Notice to state, and it supplies the periods that Step 4 of Section 10.3 of the Framework Agreement applies to what GEN keeps after exit. It is an Incorporated Policy and forms part of the Framework Agreement under Section 12.6.
This Policy is the single source for retention periods. The Framework Agreement, the Privacy Notice and the Data Processing Policy and Schedule state no retention periods of their own; each refers to this Policy, and Section 10.3 of the Framework Agreement expressly provides that this Policy governs what GEN keeps after exit. Retention is stated in one place so that it can be read, checked and changed in one place, rather than being reconstructed from three documents that can drift apart.
The periods in this Policy are GEN's standard periods and apply to every Customer alike. A Statement of Work does not vary them. Where a Customer needs a different period, it is agreed separately and only under the Variations section below.
One distinction matters throughout. This Policy governs GEN's own records: the records GEN creates and holds about the Customer, the work and the environment. It does not govern the Customer's own content which GEN merely holds as processor, such as the data on a hosted platform, the files in shared storage, or call recordings the Customer has enabled on its own voice service. For that content the Customer is controller, the retention decision is the Customer's to make and record in the Statement of Work, and GEN implements it. That is not a variation of this Policy, because this Policy never set a period for it. The entries below say which of the two applies in each case.
Where the parties have signed a separate data processing agreement, that agreement prevails for the Services it covers, as provided at Section 5.8.10 of the Framework Agreement.
The retention periods in this Policy are periods that begin when the commercial relationship ends. They are not a limit on how long GEN holds the records of a live Customer.
So the rule has two parts. While a Customer is with GEN, GEN maintains their records. A Customer of twenty years has twenty years of records, and should have, because the environment GEN supports today is the product of every decision taken about it since the relationship began. Deleting the first fifteen years of that history while still being responsible for the system it describes would be a straightforward act of self-harm. When the relationship ends, the six-year period begins, measured from the end of the relationship, and on its expiry the records are deleted.
The reason for six years is the same throughout. A claim on a simple contract may be brought for six years under section 5 of the Limitation Act 1980. For that whole period a former Customer may bring a claim against GEN, and GEN may need to bring or defend one. GEN cannot establish or defend such a claim without the records showing what was asked for, what was agreed, what was done and when. A retention period shorter than the period in which a claim may be brought would leave GEN unable to answer it, and would equally leave the Customer unable to prove it.
Three things qualify that rule, and each entry in the Schedule states which apply to it:
Anything not listed in the Schedule. The general rule is the default, and it applies to every record GEN holds whether or not the Schedule names it. Where a record relates to a Customer, it is maintained for the life of the relationship and retained for six (6) years from the end of it. Where it relates to no Customer, it is retained for six (6) years from its creation or last material update.
This cuts both ways, deliberately. The absence of an entry is not a reason to keep something longer, and it is not a reason to delete it sooner. There is no category of record held by GEN to which no period applies, and no record falls outside this Policy for want of a heading. Where GEN comes to hold a new kind of record regularly, an entry is added to the Schedule at the next revision, and until then the period above is the one that applies to it.
On expiry of the period stated for a category, the record is deleted from the live systems that hold it.
Copies held in backups, archives, snapshots and disaster recovery systems are not deleted individually. They are overwritten on the expiry of their ordinary retention cycle, and remain subject to the same confidentiality and security obligations for as long as they exist. This is the position stated at Step 3 of Section 10.3, and it is a practical consequence of how backup media work rather than a policy choice.
Legal hold. Where a period has expired but the material is subject to a legal hold because a claim, investigation or regulatory enquiry is live or reasonably anticipated, the material is retained until that matter concludes and is deleted immediately afterwards.
What this covers: invoices, credit notes, payment and remittance records, the
accounting entries supporting them, bank and reconciliation records, expense records, and credit
control correspondence.
Period: six (6) years from the end of the accounting period to which the record
relates. Note that this runs from the end of the accounting period and not from the date of the
transaction, so a record may in practice be held for up to seven years.
Why: GEN is required to keep these records by the Value Added Tax Act 1994 and by
HMRC's record-keeping requirements applying to a partnership. This is a legal obligation under
Article 6(1)(c), not a matter of GEN's discretion, and a request for erasure cannot displace
it.
What this covers: the customer relationship management system: account and
organisation records, named contacts and their business contact details and roles, quotations,
orders, opportunity and pipeline records, notes of conversations, and correspondence recording what
was asked for and what was agreed. It also covers complaints and compliments, and the record of
marketing preferences and of any consent given.
Period: the general rule. Maintained in full for the duration of the relationship,
then six (6) years from the end of it. Individual records are not aged out while the Customer is
live, however old the quotation, order or conversation they record.
Why: the general rule. These are the records of the contractual relationship
itself, and a quotation from eight years ago may still be the document that settles what was agreed
about a system still in service. Contact records are retained for the same period because a record
of what was agreed is of no evidential use without a record of who agreed it and in what
capacity.
Complaints and compliments: retained for the same period and on the same basis. A
complaint about the Services is frequently the first step towards a claim about them, and GEN cannot
answer the claim without the record of what was complained of, what GEN found and what it did about
it. A complaint that GEN resolved to the Customer's satisfaction is exactly the record GEN will want
if the matter is raised again years later.
Marketing preferences and consent: retained for the same period and on the same
basis. Where GEN relies on consent for electronic marketing it must be able to demonstrate that the
consent was given, by whom and when, and an individual has the same six years in which to bring a
claim that it was not. Deleting the evidence sooner than the period in which it can be challenged
would leave GEN unable to answer precisely the allegation the record exists to answer.
Note: where an individual leaves the Customer's employment, GEN retains the
historical record of what that person asked for and was told, because it evidences work, but the
contact is marked inactive and is not used for any current purpose.
What this covers: enquiry and marketing records for individuals and organisations
that are not GEN customers: website enquiries, event and campaign contacts, purchased or researched
business contact data, and the record of GEN's contact with them.
Period: twelve (12) months from the last meaningful interaction, after which the
record is deleted. A meaningful interaction means an enquiry, a reply, a meeting, a quotation
request or a comparable positive engagement. Opening an email is not a meaningful interaction.
Why: the general rule cannot apply here. There is no relationship for a period to
run from, and no contract, so there is no claim under section 5 of the Limitation Act 1980 for GEN
to defend and therefore no basis on which to hold the data for six years. The lawful basis is
legitimate interests under Article 6(1)(f), which is weaker than a legal obligation and which fails
the necessity test once a prospect has gone cold. Holding non-customer marketing data for six years
would breach the storage limitation principle at Article 5(1)(e).
Why twelve months and not less. A quotation is frequently accepted long after it is
issued. A prospect who takes a proposal to a board, waits for a budget cycle, or defers a project to
the next financial year is a live prospect months later, and the sales conversation resumes from the
record of what was already quoted and discussed. Anything shorter than a year would delete that
context while the opportunity is still real, and would oblige GEN to ask a returning prospect for
information they have already given. Twelve months covers a full budget cycle, which is the period
that actually matters, and is comfortably within what legitimate interests supports.
No consent record arises at this stage. GEN does not seek or rely on consent from a
prospect. A prospect approaches GEN, and the enquiry itself is what justifies GEN's response and the
conversation that follows. Formal consent is taken at onboarding, when a prospect becomes a
Customer, and the record of it is held in the CRM for the period stated in that entry. There is
accordingly nothing at the prospect stage for GEN to evidence, and nothing to keep once the twelve
months have run.
Exception, suppression records. Where an individual objects to marketing,
unsubscribes, or asks not to be contacted, GEN retains the minimum record necessary to honour that
objection, being the contact identifier and the fact and date of the objection, indefinitely
. This record is never used to contact the person. It exists so that GEN does not contact
them, which regulation 22 of the Privacy and Electronic Communications Regulations 2003 and Article
21 of the UK GDPR require. Deleting a suppression record would cause the very contact the person
asked GEN to stop making.
What this covers: support tickets, their correspondence and attachments, the record
of work performed against them, and the associated authentication and access records.
Period: six (6) years from the completion of the ticket, on a rolling basis.
This category does not follow the general rule. The HelpDesk is the one place where
records expire while the Customer is still with GEN. A ticket closed seven years ago is gone,
whether or not the Customer remains a Customer today. Every other category in this Schedule is held
in full for the life of the relationship and only then begins its six years.
Customer access: access to ticket history through the HelpDesk portal is limited to
the most recent three (3) years. Records older than that are held by GEN for its own legal,
accounting and evidential purposes and are not routinely available through the portal.
Why: tickets are the primary evidential record of what was asked for and what was
done, so the six-year Limitation Act period applies to each of them. But a ticket is a record of a
discrete, completed event rather than a cumulative account of the environment, so once the period in
which a claim could be brought on that particular piece of work has passed, there is nothing left
that Article 5(1)(e) permits GEN to keep it for. The cumulative account of the environment is the
Site Record, and that is retained for the life of the relationship.
A different period may be agreed. HelpDesk retention is configured for each organisation, so this is the one category where a variation requires no bespoke work. Some Customers are subject to regulatory or internal retention limits that require support correspondence to be destroyed sooner, and that is a request GEN can accommodate readily. It is still a variation, and it is agreed under the Variations section below and nowhere else.
The period agreed is genuine retention and not a display setting. If a period of ninety (90) days is agreed, the record is deleted on day ninety-one, and cannot afterwards be produced by GEN or by the Customer. The full consequences, and the acknowledgement the Customer gives, are set out in the Variations section.
GEN recommends in all cases that the Customer retains its own copies of any important communications or tickets.
What this covers: recordings and transcriptions of telephone calls made to or by
GEN, where recording is in operation and has been notified.
Period: six (6) months from the date of the call, save that a recording which
requests, describes, varies or evidences work is retained under the general rule, being the life of
the relationship plus six (6) years.
Why: the shorter default reflects that most calls establish nothing that needs
proving later, and Article 5(1)(e) does not permit keeping them on the chance that they might. Where
a call is the instruction, or is the record of advice given, it is evidence of the contractual
relationship and the general rule applies to it.
Where GEN is processor: for managed voice services with Customer-enabled recording,
the Customer is controller. The Customer sets the retention period, is responsible for the
notification and any consent required, and the period is recorded in the Statement of Work. GEN does
not impose or reduce that period, and Section 10.3 governs what happens to the recordings at
exit.
What this covers: surveillance camera footage recorded at GEN premises and at
facilities GEN controls.
Period: thirty (30) days, on a rolling overwrite. Footage is not individually
deleted; the recorder overwrites the oldest material as it records new material, so footage expires
continuously rather than on a scheduled purge.
Why: the purpose is the security of premises, personnel and equipment, and the
investigation of incidents, under legitimate interests at Article 6(1)(f). An incident is
ordinarily identified within days. Retention beyond the point at which footage could still be needed
for the purpose that justified recording it would fail Article 5(1)(e), and the Information
Commissioner's guidance on surveillance is explicit that footage should be held for the shortest
period that meets the purpose.
Exception: where footage is relevant to a specific incident, an insurance claim, a
criminal investigation or a lawful request by the police or another competent authority, the
relevant sequence is extracted before it is overwritten and is retained until that matter concludes,
then deleted.
Limits on use: CCTV is not used to monitor the performance or productivity of GEN
personnel, and footage is not used for any purpose other than those stated above.
What this covers: recordings of video meetings, screen-sharing sessions and remote
training delivered by GEN.
Default position: video calls are not recorded. Recording takes
place only where it has been agreed in advance and all participants have been notified at the start
of the session.
Period: where a recording is made, thirty (30) days, save that a recording which
requests, describes, varies or evidences work is retained under the general rule, being the life of
the relationship plus six (6) years.
Training sessions: where GEN consents to the Customer recording a session under the
Technical Training
Policy, the recording is the Customer's, is held by the Customer, and this Policy sets no period
for it. Its use remains limited to the Customer's internal purposes and subject to the
confidentiality and intellectual property restrictions in that Policy. Where GEN itself records a
session, GEN's copy is retained for twelve (12) months from delivery, being long enough to cover a
request to re-supply it or a question about what was delivered.
Why: a video recording is a substantially more intrusive record than a written note
of the same meeting, capturing image, voice, surroundings and incidental third parties. The
necessity test under Article 5(1)(e) is correspondingly harder to satisfy, so the default period is
short and the default practice is not to record at all.
What this covers: messages exchanged on GEN's messaging platform, both internally
between GEN personnel and in channels shared with a Customer, together with any files shared through
it.
Period: twelve (12) months for ordinary operational messages, save that a message
which requests, describes, varies or evidences work is retained under the general rule, being the
life of the relationship plus six (6) years. Where a message of that kind arises in a channel, GEN's practice is to
record the substance of it against the relevant ticket or Site Record rather than to rely on the
channel as the evidential store.
Why: messaging is used for coordination, and the great majority of it evidences
nothing that survives the week. Retaining all of it for six years would be disproportionate. Where a
message does carry an instruction or a decision, it falls within the general rule and Step 4 of
Section 10.3 treats chat messages accordingly.
Note: a message sent in a channel shared with a Customer is not a substitute for a
ticket. Where an instruction is given by message, it should be raised as a ticket so that it is
recorded where both parties can find it later.
What this covers: the Site Record maintained for each Customer, comprising the
record of the environment, its configuration, the equipment in it, the decisions taken about it, and
the Site Notices issued under the Framework Agreement together with the Customer's responses to
them.
Period: the general rule, and this is the clearest illustration of it. The Site
Record is maintained in full for as long as the Customer is with GEN, and is never aged out or
trimmed during the relationship. A Customer of twenty years has a twenty-year Site Record. The
six-year period begins only when the relationship ends.
Why: the Site Record is a cumulative document, not a series of dated entries that
stop being relevant. A configuration decision taken in year three explains the behaviour of a system
in year eighteen, and the engineer attending that system needs it. Trimming the Site Record of a
live Customer would degrade the service GEN is contracted to provide, quite apart from its
evidential value.
Its evidential value is the second reason. A Site Notice and the Customer's response to it are
directly evidential of the parties' respective positions, frequently on precisely the questions a
later dispute would turn on: what GEN advised, what the Customer decided, and when. That is the
basis stated at Step 4 of Section 10.3, and it is why the record survives the end of the
relationship for a further six years.
Exception, credentials and secrets. The Site Record is where credentials for a
Customer's environment are held. Credentials, keys, certificates and comparable secrets are
removed on termination or expiry as part of the exit process and are not
retained for the six-year period. They are operational access material and evidence
nothing about what was agreed, so there is no basis for keeping them and every reason not to. What
is retained is the record that a credential existed and what it was for, never the credential
itself.
What this covers: shared file storage GEN provides to a Customer, and the shared
storage GEN uses internally for working files.
Customer shared storage: the content is the Customer's and the Customer determines
what is placed there and how long it is kept. GEN does not impose a retention period on the
Customer's own content and does not delete it on its own initiative except as the Statement of Work
provides or as Section 10.3 requires at exit. Where the Customer requires a defined period, or
automatic expiry, that is agreed in the Statement of Work and configured accordingly.
GEN internal shared storage: working files are retained for six (6) years where
they evidence work, and are otherwise deleted when the purpose for which they were created has been
fulfilled. Working copies of Customer material taken for a specific task are deleted on completion
of that task and are not a second, parallel store of the Customer's data.
Why: for Customer content, GEN is processor and retention is the controller's
decision, not GEN's. For GEN's own files, the general rule applies to anything evidential and the
storage limitation principle applies to everything else.
What this covers: hosted and cloud platforms GEN operates for a Customer, the
Customer's systems, applications and data on them, and the operational records the platform
generates.
Customer data and content: retention is determined by the Customer and by the
applicable Statement of Work. As Section 9 of the Framework Agreement states, GEN gives no
undertaking to retain, preserve or reproduce Customer data or content beyond the period and in the
manner expressly set out in the Statement of Work, and may delete, purge, compress, migrate or
overwrite data in the ordinary operation of the platform. The Customer has no right to require GEN
to preserve any particular copy, snapshot or version, save where a retention obligation is expressly
stated in a Statement of Work.
Platform logs: access, authentication and resource usage logs are retained for
twelve (12) months. This supports security monitoring, incident investigation and capacity
planning, and twelve months is long enough for an intrusion discovered late to still be traceable
while remaining proportionate to the volume of personal data involved.
Backups: backup copies are retained for the cycle configured for the service and
are overwritten on expiry rather than deleted individually.
At exit: Section 10.3 governs. Live data is returned or deleted under Steps 1 to 3;
backup copies are overwritten on their ordinary cycle.
Why: the Customer is controller for the content it places on the platform. GEN
cannot make retention decisions about data whose purpose and lawful basis are the Customer's to
determine, and does not attempt to.
What this covers: records kept under the Anti-Bribery and Corruption
Policy: third-party due diligence files, approvals, the gifts and hospitality register, training
records, risk assessments, and records of concerns raised.
Period: six (6) years, in line with the general rule.
Why the general rule and not something longer. The Bribery Act 2010 prescribes no
retention period. Offences under it are indictable and carry no limitation period, so a prosecution
is not time-barred however long ago the conduct occurred. That cuts against the assumption that a
longer retention period buys protection: against a risk with no expiry date, seven years and thirty
years are equally arbitrary, and neither is a defence.
GEN's position is that a single retention period, applied consistently across every category of
record and published in advance, is more defensible than an arbitrary longer one. It can be
explained: records were kept for the period stated in a policy that applied to everything alike, and
were deleted when it expired. An organisation that holds records, and particularly personal records
about identifiable individuals, for longer than its own general period has to explain why it singled
those people out, and Article 5(1)(e) makes that a question it must be able to answer. GEN would
rather be able to say that a record is gone because a published and uniformly applied policy said it
should be.
What this covers: the records created when GEN investigates an allegation, being
misconduct by GEN personnel, abuse or misuse of the GEN Network, breach of an Incorporated Policy by
a Customer or a user, and suspected fraud. It includes the allegation itself, the investigation
file, evidence gathered, interview and meeting notes, the finding, and the record of any action
taken.
Material gathered under the monitoring and auditing provisions of the Acceptable Use Policy falls into
this category once it forms part of an investigation, and is subject to the periods below rather
than to any period of its own.
The periods differ by outcome, not by the type of allegation. What matters is
whether anything was found, because an allegation that was not made out is not evidence of
anything.
Where the allegation is not substantiated: twelve (12) months from the conclusion of
the investigation, after which the file is deleted. GEN retains only a minimal note that an
investigation took place, when, and that it concluded without a finding.
Why: the file must survive long enough for the investigation itself to be
challenged, whether by the person investigated or by the person who raised the concern, and twelve
months comfortably covers the periods in which such a challenge can be brought. Beyond that, holding
a detailed file of unproven allegations about an identifiable person fails the necessity test at
Article 5(1)(e) and is unfair to someone against whom nothing was found.
Where the allegation is substantiated and action is taken: six (6) years from the
conclusion of the investigation.
Why: the general rule. Where GEN dismisses a member of personnel, suspends or
terminates a Service, or acts against a Customer or user, that action can be challenged for as long
as a claim can be brought, and GEN must be able to show what it found and why it acted.
Where the matter is referred onward, to the police, a regulator or another competent authority, or where it becomes or is likely to become litigation: retained until that matter finally concludes, and then for six (6) years from its conclusion. The legal hold described above applies for as long as the matter is live.
Suspected fraud: six (6) years, but running from the date the fraud was discovered,
or could with reasonable diligence have been discovered, rather than from the date of the conduct
itself.
Why the different starting point: section 32 of the Limitation Act 1980 postpones
the limitation period where an action is based on fraud, or where a fact relevant to it has been
deliberately concealed, until the claimant has discovered it or could reasonably have done so.
Concealment is what fraud consists of, so a period running from the conduct would routinely expire
before anyone knew there was anything to investigate. This is not a longer period than the general
rule. It is the same six years, measured from the point at which the six years can sensibly be said
to start.
Monitoring material that leads nowhere. Logs, traffic records and audit material collected under the Acceptable Use Policy which do not become part of an investigation are deleted on their ordinary cycle and are not retained separately. This category does not operate as a reason to keep monitoring material indefinitely against the possibility that it might one day be useful.
The periods in this Policy are hard rules. They apply to every Customer alike and they are not negotiable in a Statement of Work, an order, a purchase order or a supplier questionnaire. Nothing in any of those documents varies a retention period, whatever it purports to say. This section concerns GEN's own records. Retention of the Customer's own content on a platform GEN operates for it is the Customer's decision as controller, is recorded in the Statement of Work in the ordinary way, and is not a variation at all.
The reason is practical rather than obstinate. A retention period is not a per-Customer setting. GEN's systems implement one set of periods, once, and apply them to everything they hold. A different period for one Customer means building and maintaining a mechanism that identifies that Customer's records across every system that holds them and applies a separate rule to them. That mechanism then has to keep working, correctly, for years, through every subsequent change to those systems. It is engineering work with an indefinite tail, not a checkbox.
A Customer with a genuine need should raise it, and GEN will discuss it properly. The needs that ordinarily justify a variation are a regulatory retention obligation of the Customer's own, a sector requirement, a group-wide records policy the Customer is bound by, or a specific contractual commitment the Customer has given its own clients.
GEN is not obliged to agree, and will decline where the variation would put GEN in breach of a legal obligation. Financial records are the clearest case: the period for those is set by the Value Added Tax Act 1994 and by HMRC, it is not GEN's to give away, and no agreement can shorten it.
Where a shorter period would leave GEN unable to defend a claim that could still be brought against it, GEN will ordinarily agree only against the written acknowledgement described below.
A variation takes effect only when recorded in writing and signed by both parties, stating the categories varied, the period applying to each, the date it takes effect, and the acknowledgement below. Nothing less will do: not an email exchange, not a term buried in a Statement of Work, and not a verbal assurance.
Where the variation shortens a period, the Customer acknowledges in that document that:
A variation is chargeable. GEN will quote before any work begins, and the quotation will separate:
GEN may require payment in advance, and may decline a variation whose cost is disproportionate to the Service it relates to.
The HelpDesk is the exception to the charge, not to the rule. HelpDesk retention is natively configurable for each organisation, so a variation there requires no bespoke work and attracts no implementation charge. It still requires the written agreement and the acknowledgement above, because the consequences of a shorter period are identical.
Material retained under this Policy is held only for the purpose stated against its category. It is not used to provide any Service, is not used for marketing, profiling, product development or analysis, is not disclosed except where the purpose requires it or the law compels it, and access to it is restricted to those who need it for that purpose.
A record retained for evidential reasons is, in effect, in storage rather than in use. Retained personal data remains subject to Section 5 and Section 5.8 of the Framework Agreement for as long as it is held.
An individual may ask GEN to erase their personal data, and GEN will do so where it is required to. Retention under this Policy does not automatically defeat that request, but it does limit it in two specific circumstances that the UK GDPR itself provides for.
Where GEN holds a record to comply with a legal obligation, principally the financial records described above, Article 17(3)(b) applies and the record is retained. Where GEN holds a record for the establishment, exercise or defence of legal claims, which is the basis for the six-year rule generally, Article 17(3)(e) applies and the record is retained for the remainder of its period.
In both cases GEN will say which exception it is relying on and for what period, rather than simply declining. Material outside those exceptions is erased on request in the ordinary way, and a request for erasure of prospect data is honoured in full.
This Policy is an Incorporated Policy and is updated in accordance with Section 12.6 of the Framework Agreement. The version published on this page is the authoritative one; any printed or saved copy is for convenience only.