1. Overview
You can request deletion of personal information that CloseUp controls, and CloseUp customers can request deletion of Customer Data processed in their workspace. Some requests can be completed from the product; others require a verified request to privacy@closeup.co.il.
Deletion is subject to legal, security, contractual and backup-retention requirements described below. Deleting data from CloseUp does not automatically delete the same information from a third-party service unless the integration and applicable API support that action and the customer has instructed CloseUp to perform it.
2. Who should submit the request?
| You are… | Recommended route |
|---|---|
| A CloseUp workspace owner or authorized administrator | Use available workspace privacy/deletion controls, or email privacy@closeup.co.il from an authorized administrator address. |
| A CloseUp user who wants to delete their own user profile | Ask the workspace administrator to remove the user, or send a verified request to CloseUp if the information is controlled directly by CloseUp. |
| A lead, contact, prospect, employee or other person stored in a customer’s CRM | Contact the business that collected your information. That business normally controls the data. You may also contact CloseUp; we may route the request to the customer or assist the customer in fulfilling it. |
| A person who connected or used CloseUp through Meta/Facebook/WhatsApp | Use the Meta deletion process described in Section 5 or contact us directly. |
3. Deleting a CloseUp account or workspace
If your CloseUp plan exposes self-service deletion controls, an authorized administrator may use the applicable Settings → Company/Workspace → Data & Privacy area to request deletion. If the control is unavailable, email privacy@closeup.co.il with the subject “CloseUp Workspace Deletion Request.”
Please provide:
- workspace/company name;
- administrator email address;
- the type of deletion requested (user only, selected CRM records, integration data, or full workspace);
- whether you require a data export before deletion;
- any relevant connected provider or account identifier.
For a full workspace deletion, CloseUp may require confirmation from an authorized owner because the request can permanently remove data for multiple users.
4. Deleting CRM information about an individual
When a business stores a lead or contact in CloseUp, that business is normally the controller of the information and CloseUp processes it on the business’s behalf. For the fastest response, send your request to the business that contacted you or collected your information.
If you submit the request to CloseUp instead, provide enough information for us to identify the relevant customer, such as the business name, the phone number or email address involved, and approximate dates of interaction. We will not disclose one customer’s data to another person without appropriate verification.
An authorized customer may delete or anonymize lead/contact records using available CRM controls or request backend deletion where necessary. The implementation should ensure that related notes, tasks, interaction links, transcripts, recordings, AI-derived records and search/index data are handled consistently with the selected deletion scope.
5. Meta, Facebook and WhatsApp data deletion
If you connected a Meta/Facebook/WhatsApp account to CloseUp or used a CloseUp integration that receives data through Meta, you can request deletion in either of these ways:
- Through Meta: open your Meta/Facebook settings, review Business Integrations or the applicable connected-app area, remove the CloseUp integration, and choose the available option to request deletion of data associated with the app.
- Directly through CloseUp: email privacy@closeup.co.il with the subject “Meta Data Deletion Request,” and include the connected business/workspace and enough information to identify the integration.
When Meta sends a valid deletion request to CloseUp’s configured deletion callback, CloseUp should validate the request, identify the associated account or external identifier, initiate deletion of the data CloseUp is required to delete, and return a confirmation code and status URL as required by Meta’s developer process.
Removing the integration also prevents future synchronization once the applicable authorization/token is revoked or disconnected. Data that originated from Meta but was lawfully copied into customer-managed CRM records may be subject to the customer’s own retention obligations and deletion instructions.
6. What a deletion request can cover
Depending on the scope and CloseUp’s role, deletion may include:
- CloseUp user profile and authentication references;
- CRM lead/contact records and customer-defined fields;
- notes, tasks, assignments, tags, statuses and activity history;
- emails, WhatsApp messages and telephony interaction records imported into CloseUp;
- call recordings or references to recordings, where CloseUp controls the stored copy;
- transcripts, summaries, sentiment, extracted entities, scores and other AI-derived data associated with the deleted record;
- connected-account tokens and integration identifiers;
- search-index, cache and derived operational copies that should no longer remain active;
- support or website profile information controlled by CloseUp, subject to retention exceptions.
If the request is for a full workspace, deletion should be scoped to that tenant and must not affect another customer’s data.
7. Information we may retain
CloseUp may retain limited information when necessary and legally permitted, including:
- billing, invoice, tax and accounting records;
- security, fraud-prevention and abuse records;
- records needed to establish, exercise or defend legal claims;
- information subject to a legal hold or lawful authority request;
- minimal suppression records needed to honor a do-not-contact or opt-out request;
- de-identified or aggregated information that can no longer reasonably identify an individual;
- temporarily retained copies in protected backups until the applicable backup expires or is overwritten.
Where deletion from backups is not technically immediate, restored backup data should be protected from ordinary use and re-subjected to the applicable deletion process before being returned to production use.
8. Identity and authority verification
To protect users and customers from unauthorized deletion, CloseUp may verify the requester’s identity, the relevant identifiers, and—when a workspace or company-wide deletion is requested—the requester’s authority to act for the customer.
We will request only information reasonably necessary for verification and will not require unnecessary sensitive information. An authorized agent may submit a request where applicable law allows it, subject to proof of authority.
9. Timing, confirmation and status
We aim to acknowledge verified requests promptly and complete them without undue delay. The exact deadline depends on the applicable law and the complexity of the request. Where GDPR applies, requests are generally handled within the GDPR statutory period; where California law applies, applicable California response periods are used.
For Meta callback requests, CloseUp’s endpoint should return the confirmation information required by Meta so the requester can check deletion status. For direct requests, CloseUp will confirm completion by email or provide an explanation if some information must be retained.
10. Deletion and connected third-party services
Disconnecting an integration from CloseUp stops future access when the authorization is revoked, but it may not delete data held independently by the third-party provider. For example, deleting an email imported into CloseUp does not necessarily delete the original message from the customer’s mailbox. Customers and users should use the third party’s own privacy controls for data controlled by that provider.
Google Calendar and Google Workspace Data
Users who connect Google Calendar to CloseUp CRM may disconnect the integration at any time from the Connections section of their CloseUp CRM settings.
Disconnecting the integration stops CloseUp CRM from accessing the connected Google Calendar through that authorization. CloseUp CRM deletes the stored OAuth credentials associated with that connection from its systems and attempts to revoke the authorization with Google.
Google Workspace API data accessed through the Google Calendar integration is used solely to provide meeting-scheduling functionality, including creating, updating, rescheduling and cancelling calendar events, adding attendees, creating Google Meet links, and checking free/busy availability.
Google Workspace API data is not sent to CloseUp CRM's AI/ML providers and is not used for AI inference, model training, fine-tuning, model improvement, embeddings, or other unrelated secondary purposes.
The use of information received from Google Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements.
Users may also revoke CloseUp CRM's authorization directly through their Google Account security settings.
11. Meta developer callback implementation
This public page may be used as CloseUp’s data deletion instructions URL in Meta developer settings. Separately, the CloseUp backend should expose a secure HTTPS data-deletion callback endpoint configured in the Meta app.
The callback implementation should:
- accept the request method and payload required by Meta;
- validate and parse Meta’s signed request using the correct app secret;
- map the Meta user/business identifier to CloseUp records without relying on unverified client-supplied identifiers;
- create an idempotent deletion job and auditable internal request record;
- revoke or remove integration credentials where appropriate;
- delete or anonymize applicable data across primary tables, derived AI data, caches/search indexes and controlled object storage;
- return the confirmation code and status URL format required by Meta;
- avoid exposing personal information in the public status URL;
- log operational status without logging secrets, access tokens or unnecessary personal data.
The exact API path is intentionally not hard-coded on this public page so CloseUp can change internal routing without breaking the published legal instructions. The Meta app configuration must point to the actual production callback endpoint.
12. Contact
Data deletion and privacy requests
Email: privacy@closeup.co.il
Subject suggestion: “Data Deletion Request”
Website: closeup-crm.com/en/contact