Skip to content
All articles
Security & governance

Privacy and compliance

A hub that brings together data retention, data subject rights, consent and auditing, with neutral wording that helps you comply with GDPR, LGPD, CCPA and other laws.

The Privacy & Compliance hub (Settings → Privacy & compliance) brings together in one place the data-protection tools: retention policy, data subject rights, consent and audit trail. The labels are deliberately neutral, because the same features help you comply with laws in many countries (GDPR in the European Union, LGPD in Brazil, CCPA in California, PIPEDA in Canada, among others). Final compliance also depends on your internal processes.

Retention policy

For each object (Contacts, Leads, Opportunities, etc.) you set how many days records are kept before automatically going to the trash. A daily sweep applies the rule. Keeping personal data only for as long as necessary is a principle common to privacy laws.

  1. Go to Settings → Privacy & compliance.
  2. In the "Retention policy" section, adjust the number of days per object.
  3. Use 0 to keep forever (no automatic deletion). The maximum is 3650 days (~10 years).
💡 The deletion is reversible (soft-delete): the records go to the trash and can be restored within the trash period.

Data subject rights

On a Contact or Lead record you handle access requests ("Export data subject data" button) and deletion requests ("Anonymize" button, admins only). See the article "Data subject rights: export and anonymize data" for the step by step.

Marketing communications are only sent to data subjects who gave consent; anyone who unsubscribed never receives them. Each email carries an unsubscribe link, and the data subject manages their own preferences through the Preference Center, without needing to log in.

Consent can be captured at sign-up time: when someone creates an account or fills in a public form, their agreement is stored with the record, serving as proof that the person agreed to be contacted.

Auditing

The Audit trail records who created, edited, deleted, exported and anonymized data. It is the basis for proving traceability in an inspection or a data subject request.

Privacy contact (data protection officer / DPO)

Optionally, provide a privacy contact email for your organization. Use it in your policies and communications as the channel for data subject requests.

In Settings → Privacy you configure a cookie banner for your landing pages, with geography rules: for example, opt-in (track only after accept) in Europe (GDPR bloc) and a simple notice elsewhere. Pick the visual template (bar, box or modal), the consent model and the texts per language. The first rule whose region matches the visitor country decides what to show.

This banner is for YOUR site, published on your landing pages, and is different from the SellioCRM cookie banner. Every visitor choice is stored as consent proof (LGPD/GDPR).

Open this article inside the system

Read it and want to see it working?

The account is free and the whole manual is available inside the system, with an assistant that answers from this very content.

Create free account
Privacy and compliance · Sellio