WorkestraDocs
PlatformSettings

Data & Privacy

GDPR data export, data deletion requests, retention policies, and audit logs.

Data & Privacy

Workestra takes data privacy seriously. This guide covers how to export your data, request deletion, and review audit logs.

Data & Privacy settings require Admin or Owner permissions.

GDPR Data Export

Export all data associated with your workspace for compliance or backup purposes.

What Gets Exported

The export includes:

Data TypeFormatContents
ContactsCSV/JSONAll CRM contacts and companies
DealsCSV/JSONPipeline data, activities, notes
CandidatesCSV/JSONRecruiting data, applications
TasksCSV/JSONProjects data, time tracking
TicketsCSV/JSONSupport data, conversations
InvoicesPDF/CSVFinance data, line items
DocumentsMarkdownKnowledge Base documents
UsersCSVTeam member list (emails, roles)
Activity LogCSVFull audit trail

Requesting an Export

  1. Navigate to Settings > Data & Privacy
  2. Click Export Data
  3. Select export format:
    • Full Export — Everything in original formats
    • GDPR Package — Structured for data portability
  4. Click Request Export

Export Processing

Workspace SizeProcessing Time
Small (< 1GB)Minutes
Medium (1-10GB)Hours
Large (> 10GB)Up to 24 hours

You'll receive an email when the export is ready. The download link expires after 7 days.

Exports may contain sensitive data. Download securely and store appropriately.

Data Deletion Request

Request complete deletion of your workspace data.

Types of Deletion

TypeScopeUse Case
Workspace DeletionEntire workspaceClosing business, migrating
User DeletionSpecific user's dataGDPR right to be forgotten
Selective DeletionSpecific recordsData cleanup

Requesting Workspace Deletion

  1. Go to Settings > Data & Privacy
  2. Scroll to Danger Zone
  3. Click Delete Workspace
  4. Complete the verification steps:
    • Confirm workspace name
    • Enter Owner password
    • State reason for deletion
  5. Confirm

Deletion Timeline

PhaseTimelineStatus
Grace Period30 daysWorkspace marked for deletion, read-only
Soft Delete30-60 daysData hidden, recoverable by support
Hard Delete60+ daysPermanent, irreversible deletion

This cannot be undone. After the grace period, your data is permanently deleted and cannot be recovered.

Individual User Deletion

For GDPR "Right to be Forgotten" requests:

  1. Go to Settings > Team Members
  2. Find the user
  3. Click Remove
  4. Select Permanently Delete Data
  5. Confirm

The user's personal data is anonymized or deleted within 30 days.

Data Retention Policies

Active Workspaces

Data TypeRetention
RecordsUntil deleted by user
Activity Log2 years
Deleted Records30 days (recoverable)
EmailsUntil account disconnects
Files/AttachmentsUntil deleted by user

Deleted/Cancelled Workspaces

PhaseRetention
Active cancellation30 days full access
Read-only30 days
Soft delete30 days (support recoverable)
Hard deletePermanent

Backups

  • Daily backups retained for 30 days
  • Backups are encrypted and geographically distributed
  • Backup restoration requires support contact

Audit Log

Track all significant actions in your workspace.

Viewing the Audit Log

  1. Navigate to Settings > Data & Privacy
  2. Click View Audit Log
  3. Use filters to narrow results

Logged Events

The audit log captures 9 event types:

Event TypeDescriptionExample
user.loginUser authentication"john@example.com logged in from 192.168.1.1"
user.logoutSession termination"Session ended for john@example.com"
user.invitedTeam invitation sent"Admin invited jane@example.com as Member"
user.role_changedPermission modification"john@example.com role changed from Member to Admin"
record.createdNew record created"Contact 'Acme Corp' created by john@example.com"
record.updatedRecord modification"Deal 'Enterprise License' updated by jane@example.com"
record.deletedRecord deletion"Ticket #1234 deleted by admin"
settings.changedConfiguration change"AI provider changed from OpenAI to Moonshot"
export.requestedData export initiated"GDPR export requested by owner"

Audit Log Details

Each log entry includes:

  • Timestamp — When the action occurred (UTC)
  • Actor — Who performed the action
  • Action — What was done
  • Target — What was affected
  • IP Address — Where the action originated
  • User Agent — Browser/device information

Filter the audit log by:

  • Date range — Specific time period
  • User — Actions by specific team member
  • Event type — Category of action
  • Resource — Specific record or module

Exporting Audit Logs

For compliance reporting:

  1. Apply desired filters
  2. Click Export
  3. Choose format (CSV, JSON, PDF)
  4. Download

Audit logs are retained for 2 years. Contact support if you need older logs.

Privacy Controls

Manage cookie settings:

  1. Click the cookie icon in the footer
  2. Adjust preferences:
    • Essential — Required for the app to function (always on)
    • Analytics — Helps us improve the product
    • Marketing — Used for relevant communications
  3. Save preferences

Do Not Track

Workestra respects browser Do Not Track settings for analytics cookies.

Data Processing Agreement

Enterprise customers can request a Data Processing Agreement (DPA):

  1. Contact legal@workestra.app
  2. Provide your company details
  3. We'll send a signed DPA within 2 business days

GDPR Compliance

Workestra helps you comply with GDPR:

RequirementWorkestra Feature
Right to AccessGDPR Data Export
Right to RectificationEdit any record
Right to ErasureData Deletion Request
Right to Restrict ProcessingPause user account
Right to PortabilityStructured data export
Right to ObjectOpt-out of communications

Data Processing

  • Controller: Your organization (workspace Owner)
  • Processor: Workestra Inc.
  • Subprocessors: Listed in our DPA
  • Data Location: EU (Frankfurt) by default for EU workspaces

Security Certifications

Workestra maintains the following certifications:

  • SOC 2 Type II — Security and availability controls
  • GDPR Compliant — European data protection
  • CCPA Ready — California privacy rights

Reports available to Enterprise customers upon request.


Next Steps