Data Deletion Instructions
- Version
- 1.0
- Effective
What changed. First published version. Explains what you can delete yourself, how to ask us to delete the rest, and what we cannot delete.
This page explains how to have personal information held in Clickbase deleted, what you can delete yourself, and what we are not able to delete. It is the page referenced by Meta, Google, LinkedIn and Microsoft as our data deletion instructions URL.
Nothing on this page is a separate promise from our Privacy Policy. It is the deletion part of that policy, stated on its own page and in the order you would actually need it. Where the two say the same thing, the Privacy Policy governs.
1. First, work out who holds your data#
This is the step that decides where your request goes, and sending it to the wrong place is the most common reason a request stalls.
Every Clickbase account is held by an advertising agency. We provide the software; the agency decides what is in it.
- You work at an agency that uses Clickbase. Your name, email address and profile image are in Clickbase because you have a login. We can act on your request directly. Use section 3.
- You are a client of an agency, or a customer of one of that agency's clients. Your information is in Clickbase because the agency put it there. That agency, not us, decides what happens to it. We hold it as their operator. Send your request to the agency. If you send it to us, we will pass it on, tell you we have done so, and support them in answering it. We will not act on it directly, because it is not ours to act on.
2. What you can delete yourself, right now#
Inside the application you can delete campaigns, budget lines, tasks, sub-tasks and task attachments. Deleting an attachment removes both the record and the stored file.
Some records are deleted automatically on a schedule, with no request needed:
- Gateway action log, recording calls made to advertising platforms: deleted after 90 days.
- Host and system metrics: deleted after 30 days.
- The agent's intermediate reasoning events: deleted after 48 hours.
- Orphaned agent memory summaries: deleted after a configured period once the source session is gone.
3. How to request deletion of anything else#
There is currently no automated deletion of user account records or of client records. We are plain about this rather than implying a self-service button that does not exist. Removing a user from an organisation updates their membership but retains the record holding their name, email address and profile image. Closing an organisation marks it archived and retains its records. We do this for the audit trail, which has to stay intact for changes that moved money. It is not a reason to keep personal information indefinitely.
So deletion is done manually, by us, when you ask.
Email us at [email protected] with:
- the email address you use to sign in to Clickbase, or the name of the organisation your data sits under if you do not have a login;
- what you want deleted, or simply that you want everything deleted.
We may ask you to verify your identity before we act. That is there to stop someone else deleting your data.
We will respond within 30 days for a request under POPIA, and within one month for a request under the GDPR. If we need longer we will tell you, and why.
When it is done, we will confirm what was deleted and what we had to retain, and why.
We are building automated deletion. This page will be updated when it exists, rather than in anticipation of it.
4. What we cannot delete, and what to do about it#
Data already sent to an advertising platform. Conversions, audience memberships and campaign configuration pushed to Meta, Google, LinkedIn or Microsoft are held by that platform under its own retention rules. Deleting your Clickbase data does not remove them, and we cannot remove them for you. You have to deal with the platform directly:
- Meta: https://accountscenter.facebook.com/info_and_permissions
- Google: https://myaccount.google.com/data-and-privacy
- LinkedIn: https://www.linkedin.com/mypreferences/d/data-privacy
- Microsoft: https://account.microsoft.com/privacy
Backups. Data may persist in routine backups for a short period after it is deleted from the live system. Backups are taken daily and kept on a rolling seven day window, so anything deleted from the live system stops existing in backups within seven days. It is not returned to service in the meantime, and point-in-time recovery is not enabled.
Records we are required by law to keep, for the period the law requires.
5. If you are not satisfied#
Contact us first. We would rather fix something than have you escalate it.
If you are still not satisfied, you may complain to a regulator.
South Africa, the Information Regulator: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 Complaints: [email protected] Website: https://inforegulator.org.za
EU or UK: your local supervisory authority. In the UK, that is the Information Commissioner's Office at https://ico.org.uk.