Data Deletion Instructions
Last updated: 30 June 2026
We keep these instructions under regular review; the version published here is the one that currently applies.
This page explains how to request deletion of personal data held in connection with the IFTI.AI platform at os.ifti.ai, including data associated with messages sent or received through WhatsApp and other channels.
1. How to Request Deletion
To request deletion of your data, email privacy@ifti.ai with the subject line “Data Deletion Request”. Please include:
- Your full name.
- The email address and/or phone number associated with your data (including the WhatsApp number you used to contact the firm, if applicable).
- The name of the law firm you interacted with, if known.
- A brief description of what you would like deleted.
We may need to verify your identity before actioning a request, to make sure we do not disclose or delete data on the wrong person's instruction.
2. Controller vs Processor — Who Handles Your Request
For most client data, the law firm is the data controller and IFTI is the firm's data processor. This means:
- If you are a client of a law firm, your request is ultimately decided by that firm. If you contact IFTI, we will forward your request to the relevant firm and assist them in carrying it out. You may also contact the firm directly.
- If you are a firm user (a solicitor or staff member with an IFTI login), IFTI acts as controller for your account data and will handle your request directly.
Because firms have professional and legal record-keeping duties, the controller may need to retain certain records even after a deletion request (see Section 4).
3. What Gets Deleted
Where a deletion request is approved and no legal retention obligation applies, we will delete or irreversibly anonymise:
- Account and profile data.
- Client contact and matter details entered into the platform.
- Message content and metadata, including WhatsApp, SMS, and email communications stored in the workspace.
- Uploaded documents, identity/KYC documents, audio, notes, and intake responses.
- Associated diagnostic and usage records tied to your identity, where feasible.
4. What May Be Retained
Some data may need to be retained even after a deletion request, where required or permitted by law — for example:
- Anti-Money-Laundering (AML) and KYC records the firm is legally required to keep for a set period.
- Records needed to comply with legal, regulatory, tax, or professional obligations.
- Minimal records needed to establish, exercise, or defend legal claims.
- Backups, which are cycled out on a rolling schedule and then permanently overwritten.
Where data is retained on one of these bases, we will restrict its use to that purpose and delete it once the obligation ends.
5. Timeframe
We aim to acknowledge deletion requests within 7 days and to complete them within 30 days, in line with UK GDPR. If a request is complex or the controlling firm needs more time, we will let you know and explain why. Data held in backups is removed as those backups expire on their normal rotation.
6. Contact
To make a request or ask a question about deletion, email privacy@ifti.ai. For more detail on how we handle personal data, see our Privacy Policy. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.