Security and GDPR
In short: your company data is isolated from other companies', access to it requires signing in and depends on your role, and you stay in control of it at all times. Below we explain how that works and what you can do about it.
A fair question to ask
Before you start uploading product photos, content, documents or call recordings, one question comes up naturally: is this data safe and processed in line with GDPR? It's a good question — because some of it is personal data (for example in the logs of calls handled by the voice agent), and you're responsible for it as the data controller.
How we think about your data
A few simple rules describe the whole model:
- Company isolation. Each company's data lives in its own walled-off space. It never mixes with other companies' data and is never visible to them. There's more about this in Organisations and workspace.
- Access through sign-in and role. To see anything you have to be signed in, and what you see and can do depends on your role in the company.
- Event log. Important actions (such as settings changes, generation, or team changes) are recorded in a log — for accountability and a clear picture of who did what.
- We keep data only as long as needed. Personal data, for example in call logs, is kept for as long as it's needed to handle it, and then deleted.
- Sensitive content isn't sent outside. Notifications to external channels carry a link to the panel, not the content itself — the details stay in a safe place that requires signing in.
Info
Isolation and sign-in work together: even a signed-in person only sees the data of the company they belong to, and only within the scope of their role.
What this means for you
- You control your company data. You can export it and request its deletion — in line with the rights GDPR gives you.
- Team access is role-based. You decide who has access to what by assigning the right roles.
- Clear split of legal roles. Your company remains the data controller, and WebImpact acts as the data processor under a data processing agreement (DPA).
Uwaga
Before you add personal data about customers or staff to the panel, make sure you have a legal basis to process it — the tool helps you handle data, but your company is responsible for what data it enters.
What you can do about it
- Manage your team's roles so everyone has exactly the access they need — no less and no more.
- See what's happening by using the event log where it's available.
- For data export or deletion, or a DPA, write to your WebImpact manager — we'll help you through the process.
See also
- Organisations and workspace — how companies' data is walled off from one another.
- Roles and permissions — who sees what and can do what.