Privacy & erasure (GDPR)
This page is for the Firm Admin (role merchant_admin). It describes the GDPR erasure (“right to be forgotten”) on the Privacy page (/privacy).
Who can trigger erasure
Section titled “Who can trigger erasure”Erasure is restricted to privileged roles:
merchant_admin(Firm Admin),compliance_officer(internal KS compliance),super_admin(internal KS administration).
A reviewer (staff) cannot trigger erasure.
What is erased
Section titled “What is erased”Erasure targets the data of an end customer (shopper), identified by their email address. It removes that end customer’s personal data from the client’s imported records.
How to trigger erasure
Section titled “How to trigger erasure”- Open the Privacy page (
/privacy). - Choose Erase customer email.
- Enter the affected end customer’s email address.
- Confirm. The erasure runs and is recorded in the audit trail.
Logging
Section titled “Logging”Every erasure is recorded in the audit trail — with the triggering person and timestamp. This keeps it traceable, for an audit, who triggered which erasure and when.
Next step
Section titled “Next step”Background on immutability and the log: GoBD & period close and Audit trail.