# Privacy and data subject rights

{/* AUTO-SYNCED SOURCE: this page lives in apps/app/src/modules/db-leads/docs/ and is mirrored into the docs app by `bun sync:module-docs`. Edit it in the module, not in apps/docs. */}

<Lead>
DB-Leads assesses people: it estimates whether someone intends to sell and backs that up with sentences from your CRM. People who are assessed have rights, and this tool answers them with functions you operate yourself rather than with a form sent to support.
</Lead>

## Disclosure per contact (Art. 15)

When a person asks what you have stored about them, you create the answer from the contact menu.

<Steps>
  <Step title="Open the contact menu">
    In the drawer via the three-dot menu, in the list and on the board via a right click on the contact. The entry is called **Create disclosure (Art. 15)**.
  </Step>
  <Step title="Confirm the prompt">
    The prompt says what goes into the file and where it lands. Nothing is created before you confirm.
  </Step>
  <Step title="Open the PDF or leave it filed">
    The disclosure is stored in Files under Tools, DB-Leads, Disclosures. The notification offers **Open**; the file stays there until you delete it.
  </Step>
</Steps>

### What the disclosure contains

<DefinitionList>
  <DefItem term="Contact details">Name, email, phone numbers, address, customer number, contact types and origin as taken over from the CRM, with the time of the last transfer.</DefItem>
  <DefItem term="AI assessment">Summary, key facts, persona, sale readiness, processing stage and score, each with the evidence the statement comes from and the date of that evidence. A recorded objection appears in the same place.</DefItem>
  <DefItem term="Findings">Every finding of the database scan with date, score, band, status and the reason if you dismissed it. Dismissed and snoozed findings are included: the score is a statement about the person regardless of what you did with it.</DefItem>
  <DefItem term="Property hints">Address, relation (ownership, tenancy, inheritance), evidence, date, confidence and whether the hint came from the AI or was entered by hand.</DefItem>
  <DefItem term="Contact policy">Per channel, whether an advertising objection is recorded.</DefItem>
  <DefItem term="Flags and history">Scan exclusion, follow-up, archiving, disqualification and consent, plus the history in numbers: how many entries, how many from the CRM and how many of your own notes, and the period covered.</DefItem>
  <DefItem term="Retention">The note stating after how many months without contact the assessment is deleted, with the value from your settings.</DefItem>
</DefinitionList>

<Callout tone="note" title="What is left out, and why">
The call plan and the opening line from the briefing are missing: those are your working notes for the next conversation, not data about the person. The name of the AI model is missing as well. The history appears in numbers, not verbatim: the entries themselves come from onOffice and are disclosed there.
</Callout>

Anyone who can see the contact can create the disclosure. There is no separate right for it: whoever may read may hand out what can be read. Every disclosure is recorded in the workspace log with date, creator and file.

## Delete and lock the AI assessment (Art. 21)

If a person objects to being assessed, you remove them via **Delete and lock AI assessment** in the contact menu. This deletes the assessment, summary, persona, signals, sale readiness, the findings and the AI property hints. The contact itself, its history and your own entries remain.

The lock applies to every future scan and to every click on "Qualify": a right that a click could override would be no right at all. You can allow the assessment again later; the deleted assessment does not come back.

<Tip title="Not the same as “Exclude from scan”">
Excluding from the scan is your decision and reversible with one click. The objection is the request of the data subject and uses its own flag, so that an accidental "Scan again" cannot revoke a right.
</Tip>

This entry requires the delete right for DB-Leads because data disappears for good.

## Retention period for assessments

Under Settings, DB-Leads you find the **retention period** for assessments: default 24 months, adjustable from 6 to 60. The period runs from the later of the last contact and the creation of the assessment. A daily run deletes what is due: the assessment including the score, the findings and the AI property hints. Contact details, history and your notes remain.

A contact with a set phase is protected: whoever is in your pipeline is being worked on, and ongoing work is not a forgotten record.

## Contacts deleted in the CRM

If you delete a contact in onOffice, it disappears from DB-Leads after the next sync, including briefing, findings, history and property hints. How this works in detail and which safety limits apply is described on the [onOffice import](/tools/db-leads/onoffice-import) page under "Deleted contacts follow".

## Rights at a glance

<DefinitionList>
  <DefItem term="Create disclosure">Read (whoever sees the contact).</DefItem>
  <DefItem term="Delete and lock assessment">Delete.</DefItem>
  <DefItem term="Change retention period">Configure (tool settings).</DefItem>
</DefinitionList>

Which role carries which right is listed on the [Permissions](/tools/db-leads/berechtigungen) page.
