Help centre · Setup
GDPR
Consent, retention, and getting a person's data out — the rights the regulation names, each its own headed section on one page, plus the queue of actual requests. Not a purchasable module: every firm can reach this, whatever their plan.
When you would use this: someone has asked what you hold on them, asked you to delete it, or you are setting up the wording and rules your firm uses to stay compliant in the first place.
General: the two settings behind every consent record — the sentence a person is shown, and its version number. Every consent event copies both at the moment someone agrees, so changing the wording here never rewrites what an earlier consent actually said.
Consent, Right to be informed, Right to erasure, Right to data portability, Right of access / rectification: one section per right — jump straight to it from the links at the top of the page — each with its own on/off switches for what your customer portal offers a contact directly (a copy of their own data, a request to be forgotten) and, where relevant, a link to the page that explains your practices in plain language.
Retention: ours alone, with no counterpart in the reference product — automatic clean-up of old data, off by default; the first run on a real account gives you a report, not an action, so you see what it would touch before anything happens.
Subject requests: the actual queue — every access, portability or erasure request, whoever raised it, with status (Open, In progress, Completed), whether it is overdue against its own due date, and where it came from. Filter, search and page through it the way any list in the product works.
Erasure, specifically: always anonymises the person and keeps the ledger intact — invoices and payments stay real financial records; it is never automatic, and never something the product decides to do on its own.
A narrower view: none — everyone who holds the GDPR permission sees and can act on all of it; there is no separate view-only tier.
When it refuses: no GDPR item in your menu means you lack the permission to manage GDPR — by default this is an Admin-and-above screen, ask one of them.