Skip to main content

Privacy and Data

Get your data out whenever you want it, and use the workspace's privacy tooling to record consents, publish privacy notices, log processing activities, and work through requests from the people whose data you hold. These pages record and action what you tell them — they do not decide anything on your behalf. See also the Compliance module.

Export your own data

Settings → Your data exports your workspace records to CSV whenever you are signed in. No active plan is required, even after you cancel.

  1. Find the dataset you want — Contacts, Companies, Projects, or Invoices.
  2. Select Download CSV next to it.
  3. Open the file in Excel, Google Sheets, or any spreadsheet tool.

Exports are generated on demand. Very large datasets are capped at the first 50,000 rows, and the page tells you when that has happened. For a formal, logged data-portability export, use the Request one here link, which takes you to the data subject tooling below.

Set your compliance options

Settings → Compliance is where you configure data retention, consent, cookie settings, and data subject rights for your workspace. The page is grouped into four sections:

  • Data Retention — set a Retention period (days) and turn on Auto-delete expired data.
  • Consent & Cookies — turn on Consent required, Double opt-in, and the Cookie consent banner, set the Cookie banner text, and record your Privacy policy URL and Privacy policy version.
  • Data Subject Rights — turn on Data portability, Right to erasure, and Automated DSAR processing, which processes access requests without manual review.
  • DPO Contact — record a DPO name, DPO email, DPO phone, and Breach notification email.

Changes take effect when you save.

Work through data subject requests

Settings → Compliance → Data subjects finds a customer, partner, or lead so you can action a request on their behalf. Search by email, company name, or contact person, then open the match.

The detail page shows their Core data, their Consents, and their Prior DSARs with an SLA indicator on each. From there you can:

  1. Select Fulfill export to download their data.
  2. Select Fulfill anonymize to permanently anonymize their personal data — this cannot be undone, so the page asks you to confirm.
  3. Select Reject and give a reason, which is recorded in the audit log.
  4. Use Initiate new DSAR to log a fresh request with its Request type, Verification method, Requester email, and notes.

Settings → Data subject requests is the audit log of export and erasure activity across the workspace. Filter by request type and status, page through the results, select View on any row for its full detail, and use Export CSV to take the log with you.

Record consents, notices, and processing activities

Settings → Consent records is the audit trail of who granted what, when, and whether it has been withdrawn. Each row shows the data subject, purpose, legal basis, status, granted and withdrawn timestamps, method, and version. Filter by purpose or tick Active consents only, and use Export CSV for the filtered set.

Settings → Privacy notices manages the privacy notice versions your users acknowledge. Select New notice, then enter a Version, Title, Language, Content as plain text or Markdown, an Effective Date, and an optional Expiry Date. Mark a notice Active to put it in use, or Archive an old one — existing acknowledgements are preserved. Notices supplied as Platform Default cannot be edited or archived.

Settings → Processing activities holds your Records of Processing Activities (ROPA). Select New activity and fill in the activity name, description, data categories, data subjects, purposes, legal basis, recipients, retention period in days, and security measures. Comma-separate multiple entries in the list fields. Uncheck Active to archive an entry; tick Include archived to see archived ones again.

Review retention and audit logs

Settings → Retention policies lists the platform-wide retention rules that apply to your workspace, with each rule's entity type, purpose, retention length, legal basis, and whether auto-delete is on. These rules are maintained by the platform team and cannot be edited per workspace today; the page links to Contact us to discuss a custom configuration.

Settings → Erasure and export logs is the chronological Erasure & Export Audit Log. The Deletions tab lists each deletion with its timestamp, data subject, table, record count, method, and verification hash. The Exports tab lists each export with its timestamp, data subject, format, record count, and checksum. Hashes and checksums can be copied to the clipboard.

SaaSy is not a legal advisor. Confirm your obligations with a qualified professional.