GDPR Compliance
Data export, deletion requests, and privacy rights.
GDPR Compliance
Workestra helps you comply with the General Data Protection Regulation (GDPR) for EU data subjects.
Your Role Under GDPR
Data Controller
You (the workspace Owner) are the Data Controller:
- Determine purposes of processing
- Decide how data is used
- Responsible for compliance
- Point of contact for data subjects
Data Processor
Workestra Inc. is the Data Processor:
- Processes data per your instructions
- Implements security measures
- Assists with compliance
- Subprocessor management
Data Subject Rights
Right to Access
Data subjects can request their data:
How to fulfill:
- Go to Settings > Data & Privacy
- Click Export Data
- Generate complete export
- Provide to data subject
Timeline: 30 days
Right to Rectification
Data subjects can request corrections:
How to fulfill:
- Navigate to their record
- Edit incorrect information
- Save changes
- Confirm correction
Timeline: Immediate
Right to Erasure ("Right to be Forgotten")
Data subjects can request deletion:
How to fulfill:
- Go to Settings > Data & Privacy
- Click Delete Data
- Select user/data to delete
- Confirm permanent deletion
Timeline: 30 days
Deletion is permanent and cannot be undone. Verify request authenticity before proceeding.
Right to Data Portability
Data subjects can receive data in structured format:
How to fulfill:
- Export data as JSON
- Provide machine-readable format
- Include all personal data
Timeline: 30 days
Right to Restrict Processing
Data subjects can limit how data is used:
How to fulfill:
- Pause marketing communications
- Exclude from analytics
- Restrict access
- Maintain minimal data only
Right to Object
Data subjects can object to processing:
How to fulfill:
- Honor opt-out requests
- Stop processing for that purpose
- Document objection
Data Export
What's Included
Complete export contains:
| Data Type | Format |
|---|---|
| Profile | JSON |
| Contacts | CSV |
| Activities | CSV |
| Documents | Original format |
| Emails | MBOX |
| Comments | JSON |
| Audit log | CSV |
Generating Export
- Admin: Go to Settings > Data & Privacy
- Click Export Data
- Select user
- Choose format (GDPR Package recommended)
- Generate
- Download when ready
- Securely transfer to data subject
Data Retention
Default Retention Periods
| Data Type | Retention |
|---|---|
| Active records | Until deleted |
| Deleted records | 30 days (recoverable) |
| Audit logs | 2 years |
| Email history | Until account deletion |
Configuring Retention
Customize in Settings > Data & Privacy:
- Set retention periods
- Configure auto-deletion
- Define data categories
- Save policies
Data Processing Agreement (DPA)
Requesting a DPA
Enterprise customers can request a DPA:
- Email legal@workestra.app
- Include:
- Company name
- Workspace ID
- Billing address
- DPA sent within 2 business days
- Sign and return
Standard Contractual Clauses
For EU-US data transfers:
- SCCs included in DPA
- Module 2 (Controller-Processor)
- Additional safeguards documented
Lawful Basis for Processing
Common Legal Bases
| Purpose | Legal Basis |
|---|---|
| Service delivery | Contract performance |
| Marketing (existing) | Legitimate interest |
| Marketing (new) | Consent |
| Analytics | Legitimate interest |
| Legal compliance | Legal obligation |
Documenting Consent
Track consent for:
- Marketing emails
- Cookie usage
- Data processing
- Third-party sharing
Data Breach Notification
If a Breach Occurs
Workestra will:
- Notify you within 24 hours
- Provide breach details
- Recommend actions
- Assist with notifications
Your Responsibilities
As Controller, you must:
- Assess data subject risk
- Notify supervisory authority (if high risk)
- Notify affected individuals (if high risk)
- Document the breach
Timeline: 72 hours to authority
International Transfers
Data Location
Default data storage:
- EU workspaces: Frankfurt, Germany
- US workspaces: US East (N. Virginia)
Transfer Mechanisms
EU data may be processed in US with:
- Standard Contractual Clauses
- Adequate safeguards
- Data Processing Agreement
Privacy by Design
Workestra Features
Built-in privacy features:
- Data minimization
- Purpose limitation
- Storage limitation
- Security by design
Your Configuration
Configure for privacy:
- Minimal data collection
- Clear retention policies
- Regular access reviews
- Staff training
Contact
Data Protection Questions
- Email: privacy@workestra.app
- Response time: 2 business days
- DPO: Available for Enterprise
Supervisory Authority
If needed, contact:
- EU: Your local data protection authority
- UK: Information Commissioner's Office
- Other: Relevant local authority
Next Steps
- Data & Privacy Settings — Configure privacy options
- Audit Log — Track data access
- Security Overview — General security info