When a data subject requests deletion under GDPR's right to be forgotten (or CCPA's right to delete), turgo's deletion workflow removes their data across all systems and confirms completion.
When deletion applies
Anyone whose data you process can request deletion. Under GDPR, this is the right to erasure; under CCPA, it's the right to delete. There are limited exceptions (ongoing legal claims, compliance with law) but for most B2B contacts, deletion requests are honored without dispute.
How to process a request
Data → Subject Requests → New → Deletion → enter the email or identifier of the person. The workflow runs: identify all records linked to this person (including derived activity and signal data), soft-delete pending review, produce a deletion report for your records, then hard-delete after review.
What gets deleted
The person's record, all activity associated with them, all agent decisions about them, derived signals attributed to them, and any communications in the Unibox. The deletion propagates to integrated systems too — CRM, marketing automation, the warehouse export — via the standard sync, marked as deletion not update.
What doesn't get deleted (and why)
Some data may be retained under legitimate grounds:
- Audit logs — required for compliance.
- Financial records — required by tax authorities.
- Records under legal hold — required by litigation.
Each exception must be documented; the deletion report shows what was retained and why.
Timelines
GDPR requires response within 30 days; CCPA within 45. turgo's deletion workflow completes within hours of submission for most requests. Documentation and confirmation to the subject is your responsibility — turgo provides the technical completion.