Template — pending legal review. This text is a DSGVO baseline for the Xboard pilot. Replace bracketed placeholders and have a qualified German data-protection counsel sign off before public launch.
Data deletion
1. Your right to deletion
Under Art. 17 GDPR ("right to be forgotten") you can ask us to delete the personal data we hold about you. This page explains how to make that request, what we delete, and how long it takes. It also covers deletion requests that reach us automatically through Meta (Facebook / Instagram).
2. How to request deletion manually
Email [Operator contact email] from the address associated with your data, or send a written request to the controller listed in our privacy policy. Please include:
- The email address, phone/WhatsApp number, or name your data is stored under.
- The studio (business) you interacted with, if known.
- A short statement that you are requesting erasure under Art. 17 GDPR.
We may need to verify your identity before acting, to protect your data from unauthorised deletion requests. Our Data Protection contact is [DPO contact].
3. Deletion requests through Meta
If you reached a studio through a Meta (Facebook or Instagram) Lead Ad, message, or login, you can also trigger deletion through Meta. When you remove the Xboard app or request data deletion from your Meta account settings, Meta sends us a signed deletion request. We:
- Verify the request's signature using our Meta app secret.
- Record the request and issue a confirmation code.
- Delete or de-identify the data linked to that Meta user, including any connected Meta access tokens and Meta-sourced records.
Meta returns a status URL of the form https://app.xboard-ai.com/data-deletion?confirmation=<code>. Opening that link shows the current status of your request directly on this page. Keep your confirmation code: you can also quote it in an email to [Operator contact email] to check the status of your request.
4. What we delete
- Contact data (name, email, WhatsApp number, location).
- Project briefs and free-text descriptions you submitted.
- Communication content (emails / WhatsApp / Instagram messages).
- Tracking and ad-measurement events tied to you.
- Connected Meta access tokens and Meta-sourced lead records.
5. What we must retain
Some data cannot be deleted immediately because the law requires us to keep it:
- Booking, deposit, and invoice records — retained as required under §147 AO (10 years for tax records in Germany). These are kept in a restricted, minimised form and deleted when the legal period ends.
- A minimal record of your deletion request itself (date, confirmation code, outcome) — kept so we can prove the request was handled, as required by Art. 5(2) GDPR (accountability).
6. Timeline
We complete deletion requests without undue delay and within 30 days as required by Art. 12(3) GDPR. If a request is complex we may extend this by up to two further months and will tell you why.
7. Complaints
If you believe we have not handled your request correctly, you may lodge a complaint with the supervisory authority. For the German pilot: the Berliner Beauftragte für Datenschutz und Informationsfreiheit.