Overview #
The GDPR and Data Retention Module allows organizations to manage user consent, privacy policies, and data retention settings in compliance with GDPR and other privacy regulations. The system provides opt-in consent management, configurable Terms and Conditions, and data retention policies to ensure proper handling of user information.
Administrators can configure these settings through the Admin Portal under:
๐ Organization โ Compliance โ Terms and Conditions
๐ Organization โ Compliance โ Retention Settings
๐ Organization โ Compliance โ User Information
User Consent and Privacy Settings #
Users must opt-in to Terms and Conditions and acknowledge the Privacy Policy before gaining access to the network. These settings can be customized in the Admin Portal, allowing businesses to define their own terms of service, privacy information, and data handling policies.
๐น Configuring Terms and Conditions & Privacy Policy #
๐ Organization โ Compliance โ Terms and Conditions
- Organizations can choose between:
- A single combined text box for both Terms and Conditions & Privacy Policy.
- Two separate text sections, each with its own dedicated link on the Captive Portal.
- Administrators can write, modify, and update the privacy policies to comply with legal and corporate requirements.
- Changes are instantly reflected on the Captive Portal, ensuring that users always see the most recent version.
๐น User Experience on the Captive Portal #
When a user connects to the network, they must:
- Read the Terms and Conditions & Privacy Policy.
- Accept the terms before proceeding.
- Complete the login authentication process (e.g., email, SMS, SAML, etc.).
This ensures full transparency about how user data is collected and stored.
Data Retention Policies #
Organizations can configure data retention settings to automatically remove inactive records after a set period. This helps limit unnecessary data storage and ensures compliance with GDPR.
๐น Configuring Data Retention Settings #
๐ Organization โ Compliance โ Retention Settings
- Administrators can define a retention period (e.g., 3 months, 6 months, or custom).
- Data is deleted automatically based on inactivity rules, including:
- Self-Service Users (Email) โ Considered active if they have an associated login.
- Meeting Hosts โ Active if a pending guest request is linked.
- Radius Users โ Active if a session is associated with their credentials.
- SMS Users โ Active if their phone number is linked to a login.
- SAML Users โ Active if their account has an active login.
- Username/Password Users โ Active if an associated login exists.
- Conferences, whitelisted devices, and other data are included in the retention policies.
โ ๏ธ Warning: Changing retention settings permanently deletes system data that meets the deletion criteria.
User Data Management & Opt-Out Process #
Users have the right to request access to their stored data or opt-out entirely from the system.
๐น Searching & Exporting User Data #
๐ Organization โ Compliance โ User Information
- Search for user data by Email, MAC Address, or Phone Number.
- Generate reports of stored user data, including:
- Login history (Meeting Host, Self-Provisioning, SAML, Conferences).
- Associated whitelisted devices.
- Personal devices linked to the account.
๐น Performing a GDPR-Compliant Opt-Out #
๐ Organization โ Compliance โ User Information โ Opt-Out
- Opting out removes all associated user data, including:
- Active Meeting Host logins.
- Self-Provisioning and SAML logins.
- Associated conferences and events.
- Whitelisted and personal devices linked to the user.
- Users cannot be restored after opt-outโthis is a permanent action.
Security & Compliance Considerations #
โ Legal Compliance โ Fully supports GDPR, CCPA, and other privacy regulations.
โ Automated Data Deletion โ Ensures no excessive data retention.
โ User Transparency โ Users must opt-in and accept terms before using the network.
โ Customizable Privacy Policies โ Businesses can define their own privacy policies directly in the admin portal.
โ GDPR-Compliant Data Removal โ The opt-out process allows users to fully remove their stored data.
Benefits of GDPR-Compliant Data Retention #
โ Reduces liability by ensuring personal data is not stored beyond necessary periods.
โ Improves transparency with clear terms and conditions for users.
โ Simplifies data management by allowing admins to automate deletion policies.
โ Ensures legal compliance with GDPR and corporate data policies.