GDPR · Article 17 · Right to erasure
Data Deletion Instructions
You can delete your SmashOne account and the personal data associated with it at any time. This page explains both deletion routes, what gets erased, how long it takes, and the narrow records we must keep under EU and Polish law. It is public and requires no sign-in.
Option 1 — Delete from your account
- Sign in to your SmashOne workspace at app.smashone.ai.
- Open Settings → Account.
- Choose Delete account and confirm. Active subscriptions are cancelled as part of deletion.
Deleting your account disconnects every social platform you linked (including Facebook and Instagram), revokes and deletes the stored access tokens, and starts the erasure described below.
Option 2 — Request erasure by email
Email info@smashone.ai with the subject "Data Deletion Request" from the address on your account. If you no longer control that address, tell us and we will verify your identity another way (we never ask for your password).
We act on verified erasure requests without undue delay and at the latest within one month, as GDPR Article 12(3) requires. For complex cases that period may be extended by up to two further months — we will tell you within the first month if that happens.
What gets deleted
- Your account profile (name, email, phone, sign-in credentials, two-factor secrets).
- Business workspaces, drafts, scheduled and published content stored in SmashOne, and uploaded media.
- Conversations and contact records processed through connected messaging channels.
- Social platform connections and all stored access tokens.
- AI assistant configuration and knowledge-base content you provided.
- Product analytics identifiers associated with your account.
What we must keep, and for how long
- Invoicing, accounting, and tax records — retained for the statutory period under Polish accounting and tax law (generally 5 years from the end of the relevant tax year), per GDPR Article 17(3)(b).
- Fraud-prevention and security logs — kept for a limited period, then purged.
- The record of your erasure request itself — kept as evidence of compliance.
- Data needed for legal claims — per GDPR Article 17(3)(e).
Encrypted backups age out on a fixed rotation; data erased from live systems disappears from backups as that rotation completes.
Data received from connected platforms
If you connected Facebook or Instagram to SmashOne, we store the page/profile identifiers, access tokens, and the messages and comments the platform delivers to us so the service can operate. Account deletion (or disconnecting a platform) erases those tokens and platform-derived data.
You can also remove SmashOne's access on the platform side at any time — for example via Facebook: Settings & privacy → Settings → Apps and websites → SmashOne → Remove. Removing the app revokes our access; to also erase the data already stored with us, use Option 1 or Option 2.
Your rights and complaints
Erasure is one of your GDPR rights — access, rectification, restriction, portability, and objection are described in our Privacy Policy. Exercising them is free of charge and never affects the service you receive while your account is active.
If you believe we handled your request incorrectly, you may lodge a complaint with the Polish supervisory authority (Prezes UODO, uodo.gov.pl) or the supervisory authority of your Member State.