GDPR TOOLKIT · COREIncluded with every Ticaga licence

Privacy requests. Sorted.

Give customers a clear path to export or delete their data, give admins an approval trail, and keep optional scripts behind consent. No separate SaaS portal, no per-seat privacy add-on, no spreadsheet of requests to chase.

RIGHT TO ACCESS

Customer exports. JSON or PDF.

Authenticated users can request a data export from the privacy area. Ticaga packages profile data, tickets, responses, IP addresses, and consent records into JSON or PDF.

48h download windowauth protected
RIGHT TO ERASURE

Deletion requests. Not guesswork.

Customers can request deletion, admins can approve or reject it, and scheduled processing anonymises personal data while preserving the operational ticket record where needed.

approval queuescheduled job
CONSENT RECORDS

Every consent, timestamped.

Consent records store the consent type, text, IP address, user agent, consent time, and revocation time so you can see what changed and when.

privacy · terms · cookiesrevocable
// CUSTOMER DATA WORKFLOW

Built into the help desk. Not bolted on later.

Most teams handle privacy requests in email threads, spreadsheets, and admin notes. Ticaga keeps the request, approval, export, deletion schedule, and notifications in the same system as the customer record.

  • +Customer self-service export and deletion routes under /privacy
  • +Admin deletion queue with approval, rejection, notes, and scheduled deletion date
  • +Anonymises profile fields, public ticket identity, IP addresses, and active consents
  • +Can notify configured third parties by webhook, API-style request, or email when deletion completes
privacy/export request received
→ collect profile, tickets, responses
→ include consent records and IP addresses
✓ PDF or JSON ready for authenticated download

privacy/delete request submitted
→ admin review pending
→ scheduled after retention window
✓ anonymisation job runs daily
Cookie Consent Settings

Banner: enabled
Region: EEA + UK only
Position: top or bottom
Blocks: live chat · tracking
Expiry: 1–3650 days
// COOKIE CONSENT

Consent that can actually control scripts.

The cookie banner is not just decoration. Admins can target EEA/UK visitors, customise the text and colours, choose top or bottom placement, set expiry, and block live chat or tracking until consent allows it.

  • +Region-aware banner with fallback behaviour if GeoIP is unavailable
  • +Helpers such as gdpr_allows('livechat') and gdpr_allows('tracking')
  • +Live Chat integration can show an in-widget consent screen before a visitor starts chatting
AreaWhat the extension doesWhy it beats ad-hoc compliance
Data accessAuthenticated JSON or PDF export with expiring download tokenNo manual copy/paste from tickets, profiles, and consent rows
Data deletionRequest queue, admin approval, scheduled anonymisation, login disablementNo deleting the wrong customer because someone forwarded an email
RetentionConfigurable retention years and backup anonymisation schedulingLegal hold and operational history can be handled deliberately
ConsentConsent type, text, IP, user agent, timestamp, and revocation trackingProof lives beside the customer, not in a separate consent vendor
Cookies/scriptsEEA/UK banner, custom styling, expiry, live chat and tracking gatingConsent changes behaviour, not just a banner message
Third partiesConfigured webhook, API-style, or email deletion notificationsArticle 19 follow-up is tracked instead of remembered manually

¹ This is compliance tooling, not legal advice. Your organisation still chooses retention rules, lawful basis, subprocessors, and customer-facing policy wording.

// INCLUDED

Privacy tooling should not be a paid panic button.

GDPR Compliance Tools ship with the core Ticaga licence, alongside ticketing, knowledge base, and SLA management.