---
title: "GDPR Compliance"
canonical: "https://red-ant-documentation.refined.site/space/RET/380010545/GDPR%20Compliance"
format: markdown
---
## Overview

The RetailOS platform is compliant with EU General Data protection Regulation (GDPR) which came into force on 5/25/2018.

### Anonymisation

Customer data is anonymised via two independent mechanisms as outlined below; 

- **“Forget Me”** – There is an option on each customer profile to “Forget” the customer. Selecting this anonymises the customers personal information such as title, first name, last name, telephone number, email address, home / delivery address, gender, dob, all inbound / outbound messages, and notes
- **Automated, periodic customer anonymisation** – After 3 years of customer inactivity the customers personal information is automatically anonymised. A customer is considered inactive if in the last 3 years there have been no changes to their customer record, no new orders or messages.

> ℹ️ Only Super Admins and Admins have the authority to anonymise a customer record. The ‘Forget Me’ feature does not display for any other role type.

### **Obscuring contact details** 

In addition to anonymisation, the platform also supports configuration to obscure customer contact information (e.g., phone number or email address) across the user interface, based on the retailer’s data privacy preferences. When enabled, the platform will mask all but the last few characters (e.g., ***1234) of these fields. This can be applied selectively depending on the retailer’s use case, although we recommend aligning visibility rules consistently with your internal data protection policy to ensure compliance.