Help center
Browse topics

Privacy, GDPR and data retention

Accept the Data Processing Agreement, set how long client data is kept, handle data requests and check client consent.

How-toChecked against the app on 24 September 2026

Under GDPR you are the controller of your clients' data and Nola processes it for you. Settings → Privacy brings together what that means in practice: the agreement between you and Nola, how long data is kept, requests from clients and the consent they have given.

Accept the Data Processing Agreement

The Data Processing Agreement (DPA) sets out how Nola handles your clients' data.

  1. Open Settings → Privacy.
  2. Click Data Processing Agreement to read it.
  3. Click Accept DPA.

The card then shows the date you accepted, with a link to View the DPA. Accepting is recorded in the audit log.

Set your retention policy

A nightly job cleans up old data based on the numbers you set here.

SettingDefaultWhat it does
Anonymise inactive clients after (months)36Clients whose record has not changed for this long are anonymised: name replaced, email, phone, notes and birthday removed.
Keep booking history (months)84How long you intend to keep booking history.
Purge notification logs after (days)180Delivery logs of emails and SMS older than this are deleted.
  1. Enter the numbers you want. Set a field to 0 to turn that cleanup off.
  2. Click Save policy.

Financial records such as invoices and transactions follow Estonia's 7-year accounting minimum. Anonymising a client keeps those records and only removes the personal details.

Handle data requests

The Data request queue lists pending requests recorded for your business. Each one shows its type (Data export or Deletion) and the date it was requested.

  • Click Mark done once you have handled it.
  • Click Reject if the request cannot be met, for example because you cannot verify who sent it.

Most clients ask you directly, by email or at the desk. Handle those requests like this:

  • For a copy of their data: open the client on Clients to see their details and history. Reports → Overview has Export clients under CSV export.
  • To be forgotten: remove the client on Clients, then open Settings → Trash and click Delete forever. Their past bookings stay for your records. See Trash and restore.

Consent overview lists every client with the consents they have given:

  • Marketing: agreed to receive marketing messages.
  • Rankings: agreed to appear in rankings and leagues.
  • Camera: agreed to camera use.

A dash means no consent is recorded. The Clients list shows the same consents in its own column. Campaigns skip clients who have declined marketing and clients who have been anonymised.

Still stuck?

Ask the AI Copilot inside Nola, or send a request to the Nola team. A person answers within one working day.