How Empatyzer handles data retention and deletion
TL;DR:
- Deleting an account removes the user from views and aggregate statistics.
- Personal data and conversations are removed on request or at contract end per the retention policy; backups are cleaned within set windows.
- Only anonymized, non-identifiable aggregates and metrics remain.
How does Empatyzer handle data retention and deletion?
Empatyzer gives the user the option to delete the account, and the retention rules organize further data deletion and anonymization of information remaining only at the aggregate level.
In practice, deleting an account in Empatyzer removes the person from lists, company reports and team-level aggregated statistics; that is the primary effect on visibility. Accounts can also be suspended automatically when an employee leaves, and administrators receive a prompt to suspend the account. At the user’s request or at contract termination, personal data are removed from the system in line with the retention policy; if a company or user requests full erasure, support initiates the process which deletes the profile and related data. Conversation content and user materials are not shared with HR or managers; they are stored privately and treated as confidential. For reporting and analytics the system retains only anonymized, non-identifiable aggregates and metrics that cannot be traced back to an individual. Backups and archives follow defined retention windows; complete deletion also includes removal from backups within a set timeframe, subject to legal and operational requirements. In legal or audit situations data may be placed on legal hold, which temporarily suspends standard deletion until the obligation ends. Empatyzer hosts data in an EU AWS data center, uses encryption and customer data isolation, holds a DPA and DPIA, and does not use company data to train models. Provider-side administrative access is audited and logged, and all actions are recorded for control and security. When a user requests deletion the provider begins the procedure and confirms completion; after it finishes the profile no longer exists in the system and only anonymized aggregate statistics remain.
Deleting an account removes visibility and reports; only non-identifiable aggregates remain in the system per the retention policy.
Sources and research
- European Parliament & Council of the European Union. (2016). Regulation (EU) 2016/679 (General Data Protection Regulation). Official Journal of the European Union, L 119, 1–88. Source
- European Data Protection Board. (2020). Guidelines 4/2019 on Article 25 Data Protection by Design and by Default (Version 2.0). Source
- National Institute of Standards and Technology. (2020). Security and Privacy Controls for Information Systems and Organizations (NIST SP 800-53 Rev. 5). https://doi.org/10.6028/NIST.SP.800-53r5 DOI: 10.6028/NIST.SP.800-53r5
Author: Empatyzer
Published:
Updated: