> ## Documentation Index
> Fetch the complete documentation index at: https://help-empuls.xoxoday.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Your data and privacy

> Learn what Empuls stores about you, how to export your data, and how to request deletion under GDPR, CCPA, and similar privacy frameworks.

Empuls stores work-related data about you — profile fields synced from your HR system, recognitions you've given and received, redemption history, survey responses, social posts. You have rights over that data: you can export a copy, request specific items be deleted, or invoke your **Right to be Forgotten** to have your entire account removed.

## What Empuls stores about you

| Data category             | What's in it                                                 | Source                          |
| ------------------------- | ------------------------------------------------------------ | ------------------------------- |
| **Profile fields**        | Name, email, department, designation, manager, photo         | Your HR system or manual entry  |
| **Recognitions given**    | Awards and citations you've sent to colleagues               | Your activity                   |
| **Recognitions received** | Awards and citations colleagues sent to you                  | Colleagues' activity            |
| **Reward points balance** | Current and historical points                                | Recognition events, redemptions |
| **Redemption history**    | Orders placed, items received                                | Your activity                   |
| **Survey responses**      | Anonymous and identified survey responses                    | Your activity                   |
| **Social posts**          | Feed posts, comments, reactions, polls                       | Your activity                   |
| **Login records**         | Sign-in timestamps, IP addresses (last 90 days), device info | Your activity                   |

Your organization's [privacy policy](/admin/security/privacy-policy) describes the legal basis for processing each category.

## Export your data

You can request a complete export of everything Empuls holds about you:

<Steps>
  <Step title="Open data-privacy controls">
    From your profile menu, click **Privacy → My Data**, or open the URL directly.
  </Step>

  <Step title="Open data-privacy controls">
    From your profile menu, click **Privacy → My Data**, or open the URL directly.
  </Step>

  <Step title="Open data-privacy controls">
    From your profile menu, click **Privacy → My Data**, or open the URL directly.
  </Step>

  <Step title="Open data-privacy controls">
    From your profile menu, click **Privacy → My Data**, or open the URL directly.
  </Step>

  <Step title="Open data-privacy controls">
    From your profile menu, click **Privacy → My Data**, or open the URL directly.
  </Step>

  <Step title="Open data-privacy controls">
    From your profile menu, click **Privacy → My Data**, or open the URL directly.
  </Step>

  <Step title="Click Export my data">
    Empuls schedules an export job. You'll get an email when the export is ready, typically within 24 hours.
  </Step>

  <Step title="Click Export my data">
    Empuls schedules an export job. You'll get an email when the export is ready, typically within 24 hours.
  </Step>

  <Step title="Download the export">
    The export is a ZIP containing JSON files (one per data category) and any media you've uploaded. The download link expires after 7 days for security.
  </Step>

  <Step title="Download the export">
    The export is a ZIP containing JSON files (one per data category) and any media you've uploaded. The download link expires after 7 days for security.
  </Step>
</Steps>

The exported data is machine-readable and suitable for GDPR portability requests.

## Right to be Forgotten

If you're leaving the organization or want your data removed, you can request deletion of your entire Empuls account:

<Steps>
  <Step title="Open the Right to be Forgotten page">
    <Frame>
      <img src="https://mintcdn.com/empuls/iHWcXX4tOrECrE_5/images/image-4.png?fit=max&auto=format&n=iHWcXX4tOrECrE_5&q=85&s=fd0aa0ce6a0b8fac6a42dbb577419597" alt="Right to be Forgotten page in Empuls privacy settings" width="619" height="379" data-path="images/image-4.png" />
    </Frame>
  </Step>

  <Step title="Read the impact summary">
    Empuls shows exactly what will be deleted, what will be anonymized (recognitions you gave to others — those stay on the recipient's record but show as "Anonymous"), and what is retained for legal or audit reasons (typically transaction records for the regulatory retention period).

    <Frame>
      <img src="https://mintcdn.com/empuls/iHWcXX4tOrECrE_5/images/right2.png?fit=max&auto=format&n=iHWcXX4tOrECrE_5&q=85&s=822e9d00f09416a6f416e9b0e2b31db7" alt="Impact summary detailing what is deleted or anonymized" width="224" height="173" data-path="images/right2.png" />
    </Frame>
  </Step>

  <Step title="Read the impact summary">
    Empuls shows exactly what will be deleted, what will be anonymized (recognitions you gave to others — those stay on the recipient's record but show as "Anonymous"), and what is retained for legal or audit reasons (typically transaction records for the regulatory retention period).

    <Frame>
      <img src="https://mintcdn.com/empuls/iHWcXX4tOrECrE_5/images/right2.png?fit=max&auto=format&n=iHWcXX4tOrECrE_5&q=85&s=822e9d00f09416a6f416e9b0e2b31db7" alt="Impact summary detailing what is deleted or anonymized" width="224" height="173" data-path="images/right2.png" />
    </Frame>
  </Step>

  <Step title="Confirm by re-entering your password">
    Empuls requires you to re-authenticate before processing this request.

    <Frame>
      <img src="https://mintcdn.com/empuls/kZKA4_hUeWO-aNOX/images/Screenshot-2026-05-28-153731.png?fit=max&auto=format&n=kZKA4_hUeWO-aNOX&q=85&s=96ac398eb21b31fd6f807543af266dcf" alt="Password re-authentication prompt before account deletion" width="770" height="474" data-path="images/Screenshot-2026-05-28-153731.png" />
    </Frame>
  </Step>

  <Step title="Wait for processing">
    Deletion runs as a background job. You'll receive a confirmation email when complete — typically within 30 days, depending on your tenant's data-residency rules.
  </Step>
</Steps>

## What gets deleted vs anonymized

| What you do      | What happens to recognitions you sent                           | What happens to recognitions you received     |
| ---------------- | --------------------------------------------------------------- | --------------------------------------------- |
| Account deletion | Sender name replaced with "Anonymous" on the recipient's record | All your received recognitions deleted        |
| Account deletion | Citation text is retained (it's part of the recipient's record) | Including any reward points balance (forfeit) |

Survey responses you submitted anonymously stay anonymous. Identified survey responses are deleted with your account.

## Regional considerations

* **GDPR (EU/UK)** — Right to access, portability, rectification, and erasure all supported.
* **CCPA (California)** — Right to know, delete, and opt out supported.
* **PIPL (China)**, **PDPA (Singapore)**, **LGPD (Brazil)** — Equivalent rights supported.

Your organization may impose retention requirements (e.g., a labor-law obligation to keep employment records for a specified period) that override your deletion request for those specific records. The impact summary calls these out before you confirm.

## Limits and gotchas

* Deletion is irreversible. Once the job completes, you cannot recover your account or data.
* Some data lives on systems Empuls integrates with (your HR system, identity provider). Deletion in Empuls does not propagate there — request deletion from those owners separately.
* If you're a Super Admin, you cannot delete your own account while it's the only Super Admin on the tenant. Reassign Super Admin to a colleague first.

## Related

<CardGroup cols={2}>
  <Card title="Privacy policy" href="/admin/security/privacy-policy">
    Legal terms governing data processing.
  </Card>

  <Card title="Information security" href="/admin/security/information-security">
    Technical safeguards Empuls applies.
  </Card>

  <Card title="Profile" href="/employees/getting-started/employee-profile">
    Where you can edit your profile data directly.
  </Card>
</CardGroup>
