GDPR & Data Privacy
Manage GDPR compliance features including audit logging, data export, visitor data erasure, privacy masking, and DPA signing.
Overview
Yaplet includes built-in tools to help you meet GDPR requirements and manage personal data responsibly. From Settings → Organization settings, you can track who did what, export data, erase visitor records, and formalize your data processing relationship with a signed DPA.
Data Retention
Conversations
Yaplet automatically cleans up old conversation data based on your subscription:
| Subscription | Retention Period |
|---|---|
| Paid plans | 3 years of inactivity |
| Free plans | 120 days of inactivity |
Conversations and their associated media files are permanently removed daily once they have been inactive — no new messages or agent activity — for the full retention period. Each cleanup is logged in the Audit Log.
Visitors and website traffic
Two further cleanups remove records the table above says nothing about:
- A conversation that never received a message is deleted once its visitor has been inactive for 60 days. These are the placeholder records the chat widget opens for every new visitor — never something a person wrote.
- A visitor with no conversations left is deleted after 125 days of inactivity.
- Kept forever, regardless of how idle they are: visitors who identified themselves (an email address, phone number or your own customer ID passed in through
identify()), visitors carrying a security review status or a risk signal, visitors who own a session replay, and banned visitors. This is the answer to "will my customer records disappear?" — they will not. - Website analytics (the page views and sessions behind the Reports → Web analytics tab) are kept for 125 days.
Privacy Masking
Privacy masking is a switch on Brand → Brand settings → Advanced. It hides email addresses, phone numbers and card numbers in what visitors write, before that text is sent on to the AI provider. Today it applies to chat, phone calls, the AI's visitor memory and AI-generated ticket titles.
One switch, two different behaviours — you need both halves:
- On chat, it redacts what Yaplet sends to the AI provider. The AI never sees the original text.
- On voice, it redacts what Yaplet stores. A phone call is answered in real time, so the caller's speech has already reached the AI provider by the time it can be masked. What masking protects there is your own transcript, not the transmission.
Three more limits worth knowing before you switch it on:
- The visitor's page URLs are not masked, and those routinely carry email addresses and order numbers in the query string.
- Uploaded images are not masked.
- Conversations recorded before you switched the toggle on stay exactly as they were — masking is not applied retroactively.
Features
Audit Log
Track important actions across your organization — user changes, subscription events, data exports, visitor erasures, and more.
Data Export
Download your visitors, conversations, and messages as CSV files for GDPR portability or internal backups.