GDPR Compliance
How Ayorax helps you meet GDPR obligations — consent, data rights, and DPA.
Ayorax is designed with GDPR compliance in mind. This article explains your responsibilities as a data controller and the tools Ayorax provides to fulfil them.
Data Processing Agreement (DPA)
Ayorax acts as a Data Processor on your behalf. A standard DPA is available for all customers. Download it from Settings → Organization → Legal → Data Processing Agreement, or email legal@ayorax.com for a custom version.
Consent management
You are responsible for obtaining lawful consent before adding individuals to Ayorax. Tag contacts with a "consent" tag and record the consent source in the Notes field or a custom field.
Right to erasure (Right to be forgotten)
Find the lead in CRM → Leads.
Open the Lead Detail page.
Click "..." → Delete Lead.
Select "Permanently erase all data" — this removes all records including activity history and conversation logs.
The deletion is logged in the Audit Log.
Data export (Right of access)
To export all data for a specific individual, open their Lead Detail page → Export → Full Data Export. This generates a JSON file of all stored data within 72 hours.
Data retention
- Lead data: retained while active, deleted within 30 days of account closure
- Audit logs: 12 months (immutable)
- Email campaign logs: 24 months
- AI conversation logs: 6 months
Ayorax is not a law firm. This article is informational — always consult your own legal counsel for GDPR compliance advice.