Data protection and client confidentiality
How we handle voter, survey, call centre and volunteer data during an engagement.
A campaign hands its consultant the most sensitive information it holds. This page sets out what we do with it. It is written to be read by a party official or a candidate’s counsel before an engagement begins, and its commitments are reflected in our contracts.
Purpose limitation
Data collected during an engagement is used only for that engagement. We do not reuse survey responses, voter records or grievance data across mandates, and we do not build a cross-client database.
Access control
Access is granted by role and reviewed through the engagement. Teams working on separate mandates do not share systems, credentials or workspaces.
Encryption and storage
Data is encrypted in transit and at rest, held on access-controlled systems, and backed up under the same controls.
Retention and destruction
Engagement data is retained for the period of the engagement plus any statutory requirement, then returned to the client or destroyed, at the client’s option, with written confirmation.
Staff and devices
Personnel are bound by confidentiality undertakings. Devices used on campaign work are subject to security configuration and periodic audit.
Incident response
Suspected loss or unauthorised access is escalated immediately to the client and to the responsible officer, investigated, and reported in writing with the remedial steps taken.
Client identity
We do not publish or confirm client identities. See our confidentiality and ethics position.