Legal
Data Protection & Retention
Creative work means handling unreleased footage, artwork and channel analytics. This page sets out the safeguards we apply, the roles we take, how long we keep each type of record, and how you can ask us to delete it.
Last updated: 26 August 2026
1. Roles: controller and processor
For website enquiries, our own correspondence and our business records, Click Hive is the controller. For material a client shares so we can produce packaging — footage, stills, analytics exports, audience data — we generally act as a processor on that client's instructions. Where we act as a processor, we only process the material for the agreed purpose, do not use it for our own purposes, and delete or return it at the end of the engagement in line with the retention schedule below.
2. Data minimisation
We ask only for what a project needs. We do not need audience-level personal data, subscriber lists or raw viewer records to produce packaging — aggregated analytics are enough — and we ask clients not to send them. We do not request payment card details, government identifiers or special category data.
3. Technical and organisational safeguards
- Access is limited to the team members actively working on your project.
- Data is encrypted in transit (TLS) and stored with reputable hosting, storage and database providers with encryption at rest.
- Enquiry submissions are stored in a database with row-level access rules, so records are not publicly readable.
- Administrative accounts use unique credentials and multi-factor authentication where the provider supports it; shared logins are not used.
- Unreleased content is shared through access-controlled, expiring links, and is removed from working folders once a project closes.
- Collaborators in our creator network are bound by confidentiality terms and given per-project access only, revoked on completion.
- Access is reviewed when someone joins or leaves a project, and devices used for client work are encrypted and screen-locked.
- Backups are encrypted and cycle out on the schedule below.
4. Retention schedule
- Contact enquiries — up to 24 months from your last message, then deleted.
- Proposals and quotes not taken up — 12 months, then deleted.
- Project files and working assets — 12 months after a project closes, so we can support reuse and iteration, then deleted.
- Unreleased or embargoed content — deleted from working storage within 30 days of publication or project close, whichever is earlier, unless the client asks us to hold it.
- Approved portfolio material — kept while it remains relevant to our case studies, and removed on request where no other obligation applies.
- Project correspondence — 24 months after project close.
- Invoices, contracts and tax records — the period required by tax and company law, typically six years.
- Website logs and error diagnostics — up to 12 months.
- Encrypted backups — rotated on a rolling 90-day cycle, so deleted items can persist in backups for up to 90 days before being overwritten.
Where a record is subject to a legal hold, dispute or statutory obligation, we retain it until that obligation ends, then delete it.
5. Sub-processors and international transfers
We use third-party providers to run our website and operations, in the following categories: website and application hosting; database and file storage; large-file transfer; email and calendar; project management; invoicing and payments; and privacy-respecting website analytics. Each is bound by contract to process data only on our instructions, to maintain appropriate security measures, and to support deletion requests. We can provide a current named list to clients on request.
Some providers and collaborators operate outside the UK and EEA. Those transfers rely on an adequacy decision where one applies, or on Standard Contractual Clauses with the UK Addendum where relevant, alongside encryption and access controls.
6. Incident response
If we detect a breach affecting personal information or unreleased content, we contain and investigate immediately, assess the risk, and notify affected clients without undue delay with what we know, what we have done and what we recommend. Where a breach is notifiable, we report it to the relevant supervisory authority within 72 hours of becoming aware of it, and we keep a record of every incident and its outcome.
7. Deletion, access and export requests
You can ask us to delete enquiry records or project material at any time through our contact page, and you can ask for a copy or export of what we hold. We may ask for information to verify the request. We confirm completion within 30 days — noting that deleted items may persist in encrypted backups for up to 90 days — except where we are legally required to retain specific records, in which case we will tell you what we are keeping and why.
8. Related pages and review
Read this alongside our Privacy Policy, Terms of Service and Cookie Preferences. We review these practices at least annually and whenever we change a core provider or introduce a new type of processing.