Data Deletion & Public Authority Requests
Last updated: March 11, 2026
Overview
At Enydea (XBMS B.V.), we take your data rights seriously. This page explains how you can request deletion of your data, how we handle requests from public authorities, and what safeguards we have in place to protect your personal information.
Data Deletion
Request complete removal of your personal data at any time
Legality Review
All authority requests reviewed for legal validity before disclosure
Challenge Provisions
We challenge unlawful or overbroad data requests
Data Minimization
Only the minimum necessary data is ever disclosed
1. User Data Deletion
1.1 How to Request Data Deletion
You can request deletion of your personal data in one of the following ways:
- From the Enydea app: Go to Settings → Account → scroll to "Delete Account" and follow the prompts to permanently delete your account and all associated data.
- By email: Send a deletion request to [email protected] from the email address associated with your account. Include your full name and account email.
- By contacting our DPO: Write to our Data Protection Officer at [email protected] for any data protection related request.
1.2 What Gets Deleted
When you delete your account, we permanently remove:
- Your profile information (name, email, company details)
- All connected social media tokens and access credentials
- Generated content (images, videos, articles)
- CRM data (contacts, leads, opportunities)
- Email integration data and cached correspondence
- Analytics and usage data
- Marketing campaign data and mailing lists
Retention period: After account deletion, we retain your data for 90 days to allow account recovery. After this period, all data is permanently and irreversibly deleted. Exceptions apply only where retention is required by law (e.g., financial records for tax compliance).
1.3 Facebook & Instagram Data Deletion
If you connected your Facebook or Instagram account to Enydea and wish to revoke access:
- In Enydea: Go to Settings → Social Media and click "Disconnect" next to Facebook/Instagram.
- On Facebook: Go to Settings → Security → Apps and Websites → find "Enydea" → click "Remove".
- We will immediately delete all stored Facebook/Instagram tokens, Page data, post data, and analytics on disconnection.
To confirm deletion of your Facebook data, send a request to [email protected] with the subject line "Facebook Data Deletion Request" and we will provide a confirmation response within 48 hours.
2. Public Authority & Law Enforcement Data Requests
Enydea (XBMS B.V.) has established formal policies and processes regarding requests from public authorities — including law enforcement agencies, courts, and government regulators — for the personal data of our users.
2.1 Required Review of Legality
Every request from a public authority for user data is subject to a mandatory legal review before any data is disclosed. We verify:
- The requesting authority's competence and jurisdiction
- The cited legal basis (e.g., court order, subpoena, regulatory inquiry)
- Conformity with applicable data protection laws, including the GDPR (EU) 2016/679, CCPA (California), and other relevant jurisdictional regulations
- Proportionality and necessity of the request relative to the stated purpose
2.2 Provisions for Challenging Unlawful Requests
If a public authority request is determined to:
- Lack a valid legal basis
- Be overbroad in scope relative to the stated purpose
- Conflict with EU/EEA data protection law (e.g., where GDPR protections apply)
- Originate from an authority without proper jurisdiction
We will object to or challenge the request through all available legal channels. Where not legally prohibited, we will notify the affected user(s) to give them the opportunity to seek their own legal remedy.
2.3 Data Minimization Policy
When legally compelled to disclose data in response to a lawful request, we apply a strict data minimization principle:
- Only the specific data elements identified in the lawful request are disclosed — never bulk exports or unrelated records
- Technical staff narrow the data query scope before any extraction
- All disclosed data is reviewed to ensure no extraneous information is included
- We never voluntarily provide more data than is legally required
2.4 Documentation and Audit Trail
Every public authority request is documented in a secure internal register. For each request, we record:
- The requesting authority and their jurisdiction
- The legal basis cited in the request
- The date the request was received
- The scope of data requested
- The internal review decision and legal reasoning
- The data disclosed (if any) and the date of response
- Whether the affected user(s) were notified
These records are retained for regulatory audit purposes and to demonstrate compliance with our data protection obligations.
3. Your Rights
Under the GDPR and other applicable data protection laws, you have the right to:
- Access: Request a copy of all personal data we hold about you
- Rectification: Correct any inaccurate or incomplete personal data
- Erasure: Request the deletion of your personal data (the "right to be forgotten")
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to the processing of your personal data
- Lodge a complaint: File a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if you believe your rights have been violated
4. Contact
XBMS B.V. (Enydea)
Privacy & Data Deletion: [email protected]
Data Protection Officer: [email protected]
Oldenzaalsestraat 1202, 7524 RJ Enschede, Netherlands — KvK: 82379033