FAQs
Answers to common GDPR questions about Bento data handling, backups, deletion rights, retention windows, subprocessors, and customer privacy controls.
Should I get consent from a customer to collect their personal data?Can I modify a customer's personal data?Can I delete personal data?Is personal data permanently deleted when I remove it?How long is personal data retained in Bento if I don't delete it?Does my data get included in backups, and if so, for how long?Can I delete customer's personal data from Bento backups?If my data centre is located in the EU, does Bento transfer my personal data outside the EU at any point?Does Bento ensure that my data is accessed only by employees with reasonable justification for doing so?Does Bento use sub-processors that process my data?If a data breach occurs with the Bento platform that affects my data, how and when will I be notified?How can I comply with a Subject Access Request and portability as required by GDPR?How do I comply with a Subject Access Request to "be forgotten?"How does Bento comply with its GDPR obligations to return or destroy all EU personal data?How does Bento comply with its GDPR obligations to encrypt personal data?How can I ensure my customers that Bento security meets applicable law and the GDPR (Article 32)?