Administration

Data privacy and retention (GDPR)

Bricksta turns the GDPR obligations “store only as long as necessary” and “right to erasure” into a per-template rule — it runs automatically so clean-up does not depend on manual work.

On this page

What this setting does

Per template you decide how long closed cases are kept — and what happens to them automatically afterwards. In the template editor, open “Settings” in the header and set the period, the action and optional per-field periods together under “Retention” on the “Defaults” tab.

The header of the template editor with the “Template settings” button, which opens the defaults including retention
Open “Settings” in the header to reach the defaults; retention is set there on the “Defaults” tab.
The “Data privacy & retention” panel with retention period (days after close), the action “Anonymize PII” and the overview of personal fields
The data-privacy panel bundles everything: period, action (anonymize or delete) and the per-field periods of the PII fields.

What happens after the period is irreversible — there is no undo. Check the period and the markings before you publish a template.

The period counts from close

“Days after close” is a period from the moment a case is closed (status completed or cancelled) — not from when it was created. If a case is reopened, the period starts over.

  • Empty = keep indefinitely: nothing ever happens.
  • 0 = on the next nightly run right after the case is closed.
  • e.g. 30 = 30 days after the case is closed.

Two actions: anonymize or delete

Anonymize PII
The values of all fields marked as personal are irreversibly cleared, the case title and all comments become “[anonymized]”, and personal file attachments are removed. The case itself is kept — reporting and the process statistics keep working.
Delete case
The whole case is removed with all of its content (tasks, values, attachments). No record is left behind for statistics.

Which fields are “personal”?

When anonymizing, only what you have marked as PII is cleared. To do so, open an output field in the template editor and enable the “PII (sensitive)” switch. The data-privacy panel lists all fields marked this way as an overview. Fields without this marking are left untouched.

Mark every field with names, addresses, contact details, ID or contract numbers as PII. Only then does anonymization reach it — the accuracy of this marking decides whether anonymization has any effect at all.

A separate period for individual fields

Some entries must disappear earlier than the rest. In the data-privacy panel (or directly on the field under “Field retention”) you set a field's own, usually shorter, period. That field is then cleared after its own period — even if the case as a whole is kept longer. Empty means the field follows the template period.

Visible on the case

If a template has a period, every case shows it in its header as a “Retention” chip (e.g. “30 days → anonymize”). This chip is purely informational — the period is set on the template, not on the individual case. Once a case has been anonymized, a note in the header explains that state instead.

When does this run automatically?

A nightly run applies all due periods automatically — you do not trigger anything, there is no “apply now” button. If you change a template's period, it applies from the next run to all affected closed cases.

A person's erasure request

If a person requests erasure of their data, an organization administrator can anonymize them: Organization → Members, pick the member, “Erase personal data”. Bricksta replaces the name with “Deleted member” and deactivates the membership (no longer assignable or mentionable); it also pseudonymizes the personal references in the audit trail and improvement opportunities to a tombstone. If the person no longer belongs to any other organization, their cross-organization identity (profile name) is anonymized too. Aggregates and counts survive and the audit entry is not hard-deleted (traceability is preserved) — but the person is no longer identifiable. Afterwards the member only shows “Personal data erased on …”; the action is permanent and cannot be repeated. You type the name to confirm beforehand.

Anonymized or deleted data cannot be restored. Treat retention as part of template design, not an afterthought.