Company: Onward Shift Limited (company number 15583217)
Last updated: 25th August 2026
Website: https://onwardshift.com
Privacy contact: jo*****@*********ft.com
This Policy explains when Onward Shift deletes personal information, how a person can ask for erasure, when information may lawfully need to be retained and how deletion works across active systems, service providers and protected backups. It should be read with our Privacy Policy.
1. About this Policy
1.1 This Data Deletion Policy applies to personal information handled by Onward Shift Limited in connection with our Website, Services, Events, Products, Provider panel, corporate and education work and communications.
1.2 It supports our obligations under the UK General Data Protection Regulation, the Data Protection Act 2018 and the Data (Use and Access) Act 2025, as amended or replaced.
1.3 The legal right is normally called the right to erasure or the right to be forgotten. In this Policy, deletion and erasure have the same general meaning unless the context explains a particular technical method.
1.4 The right to erasure is important but not absolute. Whether information must be erased depends on why it is held, the legal basis, any objection or withdrawal, applicable exceptions and whether Onward Shift is the controller for the record.
1.5 This Policy does not shorten a valid legal or professional retention requirement and does not allow Onward Shift to keep information merely because it may be useful in future.
2. Who we are and how roles may differ
2.1 Onward Shift Limited is a company registered in England and Wales under company number 15583217. Our registered office is 167-169 Great Portland Street, Fifth Floor, London, England, W1W 5PF.
2.2 Onward Shift is normally the controller for Website enquiries, marketing, bookings made with Onward Shift, payments received by Onward Shift, Provider-panel administration, complaints, safeguarding records and its own business administration.
2.3 A counsellor, coach or other independent Provider may be a separate controller for professional notes, assessments, decisions and records they create. A Business Client, education provider, payment service, event platform or other organisation may also be a separate controller for its own use of information.
2.4 Where another controller holds the record, Onward Shift cannot promise to erase it on that organisation’s behalf. We will explain the position and, where appropriate, pass on the request or give the requester the relevant contact details.
2.5 Where a supplier processes personal information only on our documented instructions, we will instruct it to delete or return the relevant information when required under our contract and data-protection law.
3. What deletion means
3.1 Deletion may involve securely removing a record from an active system, deleting an account or file, removing access, destroying a physical record, instructing a processor to erase it or irreversibly anonymising the information so that no person can reasonably be identified.
3.2 Removing information from an ordinary user view is not enough if the information remains available for routine use elsewhere. Deletion actions should cover relevant live systems, shared drives, local exports, email attachments and authorised processor systems.
3.3 Deletion does not necessarily mean that every trace disappears instantly from protected backups, audit logs or disaster-recovery systems. Sections 13 and 14 explain how those records are handled.
3.4 Where only part of a record must be erased, we may redact or separate the relevant personal information while retaining a lawful remainder, provided the erased information cannot continue to be used.
4. When the right to erasure may apply
4.1 Personal information is no longer necessary for the purpose for which it was collected or otherwise used.
4.2 A person withdraws consent and there is no other lawful basis for the relevant use.
4.3 A person successfully objects to processing based on legitimate interests or a public task and there are no overriding grounds to continue, or objects to direct marketing.
4.4 The information has been processed unlawfully.
4.5 Erasure is required to comply with a legal obligation that applies to Onward Shift.
4.6 The information was collected from a child in relation to the offer of an online service, where the relevant legal requirements are met.
4.7 A person may ask for erasure at any time. They do not need to identify which legal ground applies; Onward Shift will assess the request against the circumstances.
5. When information may need to be retained
5.1 We may refuse or limit erasure where retaining the particular information is necessary for exercising freedom of expression and information; complying with a legal obligation; performing a qualifying public-interest task; specified public-health purposes; qualifying archiving, research or statistical purposes with safeguards; or establishing, exercising or defending legal claims.
5.2 We may also retain limited information where a specific safeguarding, professional, regulatory, tax, accounting, insurance or contractual record is required by law or is necessary and proportionate for a legal claim. The reason, scope and review date should be documented.
5.3 A general possibility of a future complaint, a broad reference to safety or a preference to keep complete records is not enough. We will retain only the information needed for the identified purpose and will restrict it from unrelated use where appropriate.
5.4 Withdrawing consent or opting out of marketing stops the relevant future use but does not automatically erase information that must be retained under another lawful basis, such as an invoice, a complaint record or a minimal marketing-suppression record.
5.5 If only an exception or legal hold prevents erasure, the information will be isolated or restricted where appropriate, kept only for the justified period and reviewed when the hold ends.
6. How to make a deletion request
6.1 A request may be made verbally or in writing and does not need to use legal wording. A clear request to delete or erase personal information is enough for us to consider it.
6.2 The simplest route is to email jo*****@*********ft.com with the subject ‘Data deletion request’.
6.3 It helps to provide a name, the email address or telephone number used when dealing with Onward Shift, the relevant service or approximate dates and a short description of the information concerned. A person should not send health, safeguarding or identity documents unless we explain that they are necessary.
6.4 A request received by another member of staff or through another reasonable channel remains valid. We will route it internally rather than requiring the requester to start again.
6.5 A parent, guardian, solicitor or other authorised person may make a request on somebody’s behalf. We may ask for proportionate evidence of authority and, where appropriate, the wishes or best interests of the person concerned.
7. Identity, authority and clarification
7.1 We will not routinely demand formal identification. If we have reasonable doubts about identity, we may ask for the minimum additional information necessary to prevent disclosure or deletion of another person’s records.
7.2 The evidence requested will depend on the sensitivity of the information, the risk of impersonation and what we already know. We will not request a passport, driving licence or other high-risk document where a lower-risk check is sufficient.
7.3 If a request is unclear, we may ask what information or service it concerns. Clarification is intended to help locate the right records; a person is not required to narrow a clear and manageable request merely for our convenience.
7.4 Identity and authority evidence will be used only to deal with the request, protected appropriately and deleted when no longer required, unless a limited record is needed to demonstrate lawful handling.
8. Response times
8.1 We aim to acknowledge a deletion request within three working days. This service aim does not replace the legal deadline.
8.2 We will respond without undue delay and normally within one calendar month of receiving the request or, where permitted, the information reasonably required to confirm identity or authority.
8.3 If the request is complex or the person has made a number of requests, we may extend the response period by up to a further two months. We will explain the extension and the reason within the first month.
8.4 A response will confirm whether the request has been completed, partly completed, refused or remains subject to a justified extension. Where information is retained, we will explain the main reason and any relevant restriction, unless the law prevents us from doing so.
8.5 Completion may include confirmation of action taken in active systems, any processor instruction, the treatment of backups and whether relevant recipients have been notified. We will not disclose another person’s information or sensitive security details in the response.
9. How we assess and record a request
9.1 We will identify the relevant person, services, systems and controller roles; locate reasonably identifiable records; confirm the purpose and lawful basis; consider the erasure grounds and exceptions; and document the decision.
9.2 Where a record contains information about more than one person, we will consider redaction, separation, restriction or another proportionate solution rather than automatically deleting or disclosing the whole record.
9.3 A limited request log may record the date, scope, identity checks, decision, actions, response and any recipient notifications. Keeping this evidence helps demonstrate compliance and does not permit reuse for unrelated purposes.
9.4 If information is scheduled for routine deletion sooner than the legal deadline, we may complete that deletion through the normal process, provided the request is tracked and the person receives a proper response.
10. Retention and routine deletion schedule
10.1 Information is also deleted or anonymised through routine retention controls, without waiting for an individual request. Our standard retention periods are set out below. We may keep information for a shorter or longer period where the circumstances, the law or a professional requirement justify it.
Information | Standard retention period or criterion |
General enquiries not leading to a Booking | Normally up to 12 months after the last meaningful contact, unless an ongoing relationship, complaint or legal issue justifies longer retention. |
Bookings, contracts, orders, invoices and payment records | Normally up to 6 years after the relationship, transaction or relevant accounting period, subject to tax, accounting and limitation requirements. |
Coaching, counselling or therapy administration held by Onward Shift | Normally up to 6 years after the last Service. A Provider’s professional notes are kept under the Provider’s own privacy notice and retention policy. |
Event registration and ordinary attendance data | Normally up to 12 months after the Event. Incident, complaint or safeguarding information may be kept longer under the relevant category below. |
Consent, opt-out and suppression records | Normally up to 6 years for consent evidence. A minimal suppression record may be kept for as long as needed to prevent unwanted contact. |
Unsuccessful Provider applications | Normally up to 12 months after the decision, unless a longer talent-pool period was agreed or a complaint or legal issue requires retention. |
Successful Provider, supplier and due-diligence records | Normally up to 6 years after the relationship ends. Identity and vetting evidence is kept for the shortest justified period. |
Complaints, safeguarding, incidents and legal claims | Normally up to 6 years after closure, or longer where necessary for a child or vulnerable person, regulator, insurer, or active or anticipated legal proceedings. |
Marketing contacts | Until consent is withdrawn, the person objects, or the record is removed after an appropriate inactivity review. A minimal suppression record may remain. |
Website logs, analytics and technology identifiers | For the period stated in the Cookie Policy or relevant tool setting, normally no longer than 24 months unless a shorter setting or a justified security need applies. |
Photographs, recordings, podcasts and testimonials | For the agreed publication or archive period. Withdrawal normally stops new consent-based use but may not require recall of material already lawfully published where recall is not reasonably practicable. |
Protected backups | Deleted information may remain beyond ordinary use until it is overwritten through the normal backup cycle, normally within 90 days, unless it must be isolated for security or legal reasons. |
10.2 A stated period is an upper guide rather than a promise to keep every record for that long. Information may be deleted sooner when it is no longer needed.
10.3 A specific law, professional standard, safeguarding need, insurer requirement or legal claim may justify a different period. Any departure should be limited, documented and reviewed.
11. Professional records, Providers and Business Clients
11.1 Onward Shift normally controls the booking, matching, payment, complaint and safeguarding information needed to administer a professional service. We do not need routine access to a counsellor’s or coach’s detailed professional notes merely because a Booking was arranged through us.
11.2 An independent Provider may need to retain professional records under their own legal, ethical, regulatory or insurance obligations. They must assess a deletion request under their own privacy notice and should not keep records indefinitely without a defined reason.
11.3 Where Onward Shift and a Provider each control different records, a request to one organisation does not automatically erase the other’s records. We will help the person understand where a separate request may be needed.
11.4 A Business Client or education provider may remain the controller for employee, learner or attendee information it supplied. We will delete information we control and follow documented processor instructions where Onward Shift acts only on that organisation’s behalf.
12. Marketing, cookies and published content
12.1 An objection to direct marketing will be honoured. We may retain a minimal suppression record, such as an email address and opt-out date, solely to ensure the person is not added back to marketing lists.
12.2 Withdrawing cookie consent stops future use of the relevant non-essential technologies. A visitor may also remove device-stored information through browser or device settings. Our Cookie Policy explains the available controls.
12.3 Where personal information has been made public by Onward Shift and must be erased, we will take reasonable steps, taking account of available technology and cost, to inform relevant controllers processing copies or links where the law requires this.
12.4 A request concerning a testimonial, photograph, podcast or recording will be assessed against the agreed basis, publication context, third-party platforms, freedom of expression and whether withdrawal or recall is reasonably practicable. We will stop new consent-based use where consent is withdrawn.
13. Processors, recipients and third parties
13.1 Where personal information has been disclosed to a recipient, we will communicate an applicable erasure to that recipient unless this proves impossible or involves disproportionate effort. We will tell the requester about relevant recipients if they ask and the law requires it.
13.2 Processors acting on our instructions must support deletion, return and restriction under their contracts. We will use available administrative controls or a documented instruction and keep suitable evidence of completion.
13.3 A separate controller may have its own lawful reason to retain information and must decide the request for its records. Onward Shift will not describe a third party’s general retention schedule as proof that our own obligations have been met.
13.4 If a recipient cannot be reached or a deletion instruction fails, we will assess the risk, take proportionate follow-up action and explain any material limitation to the requester where appropriate.
14. Backups, archives and technical deletion
14.1 Protected backups are designed for security and disaster recovery rather than ordinary access. It may not be possible or proportionate to edit an individual backup immediately without undermining its integrity.
14.2 Information subject to deletion will be removed from live use and allowed to expire from protected backups through the normal overwrite cycle, intended to be within 90 days. Until then, it will remain beyond ordinary use and protected against restoration for unrelated purposes.
14.3 If a backup containing deleted information must be restored, the deletion will be reapplied before the information is returned to ordinary use, unless a documented legal or security reason temporarily prevents this.
14.4 A backup, immutable security log or archive may be retained longer where necessary for cybersecurity, fraud investigation, legal claims or another lawful purpose. Access will be restricted and the retention reviewed.
14.5 Deletion methods should be appropriate to the medium and risk. They may include secure application deletion, encryption-key destruction, verified overwrite, physical destruction, access revocation or irreversible anonymisation.
15. Anonymised and pseudonymised information
15.1 Genuinely anonymised information is information from which no person is identified or reasonably identifiable, taking account of the means reasonably likely to be used. It is no longer personal information and the right to erasure does not apply to it.
15.2 Removing a name or replacing it with a code does not necessarily anonymise information. Pseudonymised information that can be reconnected using other data remains personal information and must still be considered in a deletion request.
15.3 We may fulfil an appropriate deletion action by irreversibly anonymising the information, provided the result cannot reasonably be linked back to the person and no identifiable copy remains in ordinary use.
15.4 We will not convert identifiable information into an inadequately anonymised dataset merely to avoid an erasure request. Any retained anonymous statistics must be protected against reidentification, including risks arising from small groups, rare characteristics or free text.
16. Children, safeguarding and serious risk
16.1 Particular weight is given to erasure requests concerning information collected from a child, especially where the child may not have understood the long-term consequences of providing it.
16.2 Safeguarding or serious-risk information is not automatically exempt from erasure. We will identify a lawful and proportionate reason for any retention, keep only the relevant information, restrict unrelated use and review the record when the risk or duty changes.
16.3 A record may need to be retained to protect a child or vulnerable person, meet a legal or professional duty, cooperate with a competent authority or establish or defend a legal claim. Where safe and lawful, the requester will be told the main reason.
16.4 A deletion request is not an emergency service. Anyone facing immediate danger should call 999 or use the urgent-help information available at https://onwardshift.com/urgent-help/.
17. Fees and refusal
17.1 A deletion request is normally free. We may charge a reasonable fee based on administrative costs or refuse to act only where the request is manifestly unfounded or excessive, taking account of all the circumstances.
17.2 A request is not manifestly unfounded or excessive merely because it is inconvenient, repeats a previous request for a legitimate reason, overlaps with another right or concerns a large amount of information.
17.3 If we refuse, charge a fee or need further identity information, we will explain the position without undue delay and within one month. A refusal response will give the reasons, the right to complain to the Information Commissioner’s Office and the ability to seek a judicial remedy.
17.4 Onward Shift bears responsibility for demonstrating why a request is manifestly unfounded or excessive.
18. Complaints
18.1 A person who is dissatisfied with a deletion decision or how their request was handled may complain to jo*****@*********ft.com. They do not have to use a particular form or legal language.
18.2 We aim to acknowledge a complaint within three working days and will always acknowledge it within 30 days. We will take appropriate steps to investigate, keep the complainant informed and communicate the outcome without undue delay.
18.3 A person may also complain to the Information Commissioner’s Office at https://ico.org.uk/make-a-complaint/ or by calling 0303 123 1113. Contacting Onward Shift first is not a condition of the right to complain.
19. Changes, related policies and contact
19.1 We may update this Policy when the law, regulatory guidance, Services, systems, Providers or retention practices change. The latest version will be published on the Website with a revised date.
19.2 Our Privacy Policy explains what personal information we use, why we use it, who it is shared with, how long it is kept and the full range of data-protection rights: https://onwardshift.com/privacy-policy/.
19.3 Our Cookie Policy explains Website technologies and consent controls: https://onwardshift.com/cookies-policy/.
19.4 Our Terms and Conditions explain the rules for using the Website and purchasing or receiving Onward Shift services, events and products: https://onwardshift.com/terms-of-use/.
19.5 Our Code of Ethics sets privacy, confidentiality and record-handling standards for Providers: https://onwardshift.com/code-of-ethics/.
19.6 Deletion requests, questions and complaints may be sent to jo*****@*********ft.com.
We use cookies to make our website work properly, improve performance and personalise your experience. You can accept all cookies or manage your preferences.