GDPR Compliance
What it does
POTAL is fully GDPR-compliant with data processing agreements, right-to-erasure support, data portability, and EU data residency options. No personal data is required for API usage — only product and trade data is processed.
How to use it
Review DPA
Download the Data Processing Agreement from potal.app/legal/dpa for your records.
Request data export
Submit a data portability request to receive all your stored data in machine-readable format.
Request deletion
Exercise right-to-erasure by contacting support — all data including backups is deleted within 30 days.
Configure retention
Enterprise customers can set custom data retention periods to meet their GDPR policies.
Related Features
California Consumer Privacy Act compliance and disclosures
Transparent privacy policy covering all data processing
Configurable data retention policies per plan tier
AES-256 encryption at rest and TLS 1.3 in transit
Cookie consent banner compliant with EU ePrivacy Directive