GDPR Compliance

How Ayorax helps you meet GDPR obligations — consent, data rights, and DPA.

5 min readSecurity & Compliance

Ayorax is designed with GDPR compliance in mind. This article explains your responsibilities as a data controller and the tools Ayorax provides to fulfil them.

Data Processing Agreement (DPA)

Ayorax acts as a Data Processor on your behalf. A standard DPA is available for all customers. Download it from Settings → Organization → Legal → Data Processing Agreement, or email legal@ayorax.com for a custom version.

Consent management

You are responsible for obtaining lawful consent before adding individuals to Ayorax. Tag contacts with a "consent" tag and record the consent source in the Notes field or a custom field.

Right to erasure (Right to be forgotten)

1

Find the lead in CRM → Leads.

2

Open the Lead Detail page.

3

Click "..." → Delete Lead.

4

Select "Permanently erase all data" — this removes all records including activity history and conversation logs.

5

The deletion is logged in the Audit Log.

Data export (Right of access)

To export all data for a specific individual, open their Lead Detail page → Export → Full Data Export. This generates a JSON file of all stored data within 72 hours.

Data retention

  • Lead data: retained while active, deleted within 30 days of account closure
  • Audit logs: 12 months (immutable)
  • Email campaign logs: 24 months
  • AI conversation logs: 6 months

Ayorax is not a law firm. This article is informational — always consult your own legal counsel for GDPR compliance advice.

Was this article helpful?