The retention period lets you automate anonymization of a service request submitter’s name, email address and phone number. The setting applies to the whole organization: it is not configured separately for each service request category or public form. It can also affect requests that are still in progress and cut off email communication with their submitters.

Setting the retention period

Make the change in the browser using an account with permission to edit service request settings. A local administrator has this permission.

  1. Open Manage tasks → Service requests → Service request settings and select the Settings tab.
  2. In the Basic info section, enter a whole number of at least 1 in the Submitter personal data retention (days) field. An empty field means automatic anonymization is disabled.
  3. Select Update service request setting at the bottom of the form.
  4. Reopen the settings and check that the intended number of days was saved.

Choose a period that keeps the submitter’s contact details available for as long as they are needed to handle the request. Setting a short period or shortening the retention period can cause older requests to be processed as early as the following night. Saving the setting does not anonymize data immediately.

When are requests processed, and which requests are included?

Processing is queued each night at midnight in the organization’s time zone. Completion may be delayed by the queue. Automatic processing applies to active Spotilla customer accounts with a retention period set.

The cutoff is calculated by subtracting the configured retention period from the start of the processing day. Only requests created before that cutoff that have not yet been anonymized are included. Age is based on the request’s creation time, not its completion time or last modification.

For example, with a one-day setting, processing on 5 October 2026 uses 4 October 2026 at 00:00 in the organization’s time zone as the cutoff. A request created on 3 October that meets the other conditions can be processed. A request created at exactly 00:00 on 4 October or later is not yet included in this run.

The request’s status does not restrict processing: Open, In progress, On hold, Completed, Cancelled and Forwarded requests may all be included. Each run for an organization processes up to 10,000 requests, so a large backlog may take several nights.

Exception for user accounts

A request is left unanonymized if the submitter’s stored email address matches the email address of any user account in the organization. The comparison ignores capitalization and spaces at the beginning or end of the address. It is not limited to active user accounts.

The exception is based on the address, not how the request was submitted. The standard creation form in the Android and iOS apps fills in the submitter’s name and email from the signed-in user’s details, so these requests are usually excluded from processing. A request submitted through a public form is also excluded if its address matches a user account.

What does anonymization change?

The submitter’s name and email are replaced with anonymization values, and the phone number is cleared. For a Finnish-language customer account, the name becomes GDPR Tyhjennetty and the email becomes gdpr.tyhjennetty@spotilla.com. The replacement values depend on the customer account’s language.

External email addresses in conversations associated with the processed request are also replaced, except where an address matches a user account in the organization. Stored copies of contact details in the request’s change history are cleared, and the submitter’s fallback name stored in the creation event is replaced. The anonymization time is recorded in the history. The request’s last modification time also changes.

The request is not deleted, closed or reassigned. This setting does not clear its title, description, additional fields, comments, conversation text or attachments. These may still contain personal data. The feature also does not perform a general cleanup of the history of requests that have already been deleted.

Effect on communication

No email is sent to the replacement addresses used for anonymization. Conversation notifications and notifications about status, responsibility and completion that rely on the original address stop for that address, even if the notification is enabled in the settings. Other remaining recipients can still receive notifications according to their settings.

Anonymization itself does not invalidate a previously sent conversation reply link. The link can still open the reply page if it is valid, the request exists and its status is not Completed, Cancelled or Forwarded. If needed, read about follow-up communication for public service requests.

Checking the result and disabling the feature

  1. After processing, open Manage tasks → Service requests → Service requests and refresh the table data, for example by reopening the page.
  2. Open the column visibility selector using the column icon at the end of the table’s column headers. Show the Personal data anonymized at column, which is hidden by default. The timestamp shown there indicates when the request was anonymized; an empty value means the request has not been marked as anonymized.
  3. Open the request’s details using its title link. On the Basic info tab, check the submitter’s replacement name and email and the empty phone number.

A confirmation that the setting was saved does not by itself indicate that processing is complete. If an expected request has not yet been anonymized, check its creation time, the retention period and the email exception for user accounts. Also allow for processing delays and a large number of requests.

Disable automatic anonymization by clearing the retention period field and saving with the same button. This prevents processing in future runs, but does not restore contact details or history data that have already been replaced. Extending the retention period does not restore data either. Disabling the public form alone does not stop anonymization.

Publishing the public form and configuring its options are covered separately in Public service request form settings.