Legal notice
GDPR Process
Export, deletion, restriction, credential revocation, and retention operating rules. Effective July 25, 2026.
Back to legal documentsRequest intake
- Classify the request as organization export/deletion, user export/deletion, contact/data-subject request, credential revocation, imported-leftovers cleanup, or processing restriction.
- Verify requester authority before acting: organization admin/owner for organization data, verified user for own account data, or customer-approved instruction for contact/data-subject cases.
- Record a request owner, due date, scope, decision notes, and completion evidence before any destructive step.
Export
- Exports should include organization, user, role, integration metadata, route settings, imported records, external identities, sync runs, write-back evidence, and cleanup decisions.
- Exports must not include plaintext passwords, API keys, app-specific passwords, OAuth access tokens, refresh tokens, cookies, CSRF tokens, or other organizations' data.
- Customer-authorized source systems remain outside Sentria's export unless Sentria has stored the selected records.
- Admin export packages include request metadata, safe integration metadata, counts, matching subject records, and recent sync/write-back evidence where relevant.
Deletion and retention
- Deleting an integration disables sync and removes local credentials, but imported local records stay until the user/admin chooses imported-leftovers cleanup.
- Organization deletion should disable routes, revoke/delete credentials, export first if requested, delete organization-scoped data, and let backups expire under the documented backup window.
- Security, sync, write-back, support, billing, and legal evidence is retained only as long as the retention schedule, legal obligation, dispute handling, or security investigation requires.
- Archived CRM records remain recoverable until the customer permanently deletes them. Permanent deletion requires a separate explicit confirmation and may require linked records to be resolved first.
- A user may delete their own account where available. Shared-workspace owners must leave another owner, and a sole workspace with a Stripe subscription remains available until renewal is cancelled and its current access period ends. Billing, security, support, and other legally required evidence can be retained for the published period.
- If Sentria acts as processor, it assists the customer with verified data-subject requests and follows customer instructions where legally and technically possible.