> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://helpdesk.whydonate.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# How We Handle GDPR Data Deletion Requests

**Summary:** When someone asks us to delete their data, we delete or anonymize what we can, and keep only what we're legally required to (mainly Stripe/financial records) — responding within GDPR's one-month window.

**The right to erasure**: Under GDPR's "right to erasure" (Article 17), individuals can ask us to delete their personal data when we no longer need it, or they've withdrawn consent. This right isn't absolute — legal obligations, such as financial record-keeping requirements, can override it.

**Our process**: When we receive a deletion request, we:
* Verify the requester's identity
* Check what data exists across their account, campaign, and transaction records
* Delete or anonymize what we can
* Flag anything we're required to retain
* Confirm back to the user what was done

**What we can't delete**: Stripe transaction and financial data must be kept for compliance reasons. Our Data Processing Agreement also states that data is deleted or returned upon termination, unless retention is required by law.

**Response time**: We aim to respond to deletion requests within one month, in line with GDPR requirements.