Skip to main content

EU Data Protection/GDPR

Where personal data appears in Mobaro and how to find, export, correct or remove it when your staff make GDPR requests.

Written by Logan Bowlby

Overview

Under the GDPR, your organization is the data controller for the personal data in your Mobaro account, and Mobaro is your data processor. Your organization decides what personal data goes into Mobaro, mostly about your own staff, and uses the tools in this article when someone asks about their data.

This article shows where personal data appears in Mobaro and which features you can use to find, export, correct and remove it. For Mobaro's Data Processing Agreement, hosting and sub-processors, see How Mobaro complies with GDPR.

At a glance

Who can do this

Super Users, or a Role with Users › Modify (edit profiles) or Users › Delete (disable and delete). Exporting Results needs access to those Results.

Where

Users and Results in the Backend

Works on

Backend (web) and Public API

Availability

All organizations

💡 Why this matters: When a member of staff asks what Mobaro holds about them, or asks to be removed, you need to know where to look and what each action really changes. Deleting a User, for example, doesn't remove their name from the Checklists they completed.


Where personal data appears

Area

Personal data it can hold

User profiles

Name, Email, External ID, Phone number, Language, Profile Image and Address

Results

Who completed each Result and answered each question, and when; comments and photos; the device's position with answers, when the device shares it

Assignments and Notes

Who created, was assigned and resolved them; comments and photos

Timesheets

Each User's time entries

Certifications and Competencies

Each User's training and qualification records

RideOps

Which Operators and Attendants worked each ride, and the dispatches and entries they logged

Free-text answers, comments and photos can also contain personal data about other people, such as guests. Mobaro stores them as entered, so set clear rules for your teams about what to record.


Find and export someone's data


Correct someone's data

To correct a profile, go to Users, select the User and click Edit. A User who belongs to several Mobaro organizations can only be edited by someone who can administrate Users in all of them.

If a Result was recorded under the wrong person, a Super User can use Change result user; the change is logged in the Result's activity feed. See Changing the User Who Completed a Result.


Stop access or remove a User

Disable a User to stop their access straight away while keeping their setup. Delete a User to remove them from your organization: they're cleared from Assignments, Schedules, Roles, User Groups and other mappings, and their Certifications are deleted. Their Mobaro account is deleted only when they belong to no other organization. You can't disable or delete a Super User yourself; ask Mobaro Support. See How to deactivate a User.

🛑 Critical: Deleting a User doesn't erase their name from work already done. Completed Results, the history of Assignments and other records keep showing who did them, and deletion can't be undone from the Backend. If a request needs personal data removed from those records, contact Mobaro Support or your Customer Success Manager before you act.

There's no retention setting in the Backend, and Mobaro doesn't remove Results or other records automatically after a set period. Invalidate on a Result doesn't erase it either: it moves to Invalidated Results. For how data is handled when your subscription ends, see your agreement with Mobaro or ask your Customer Success Manager.


Best practices

  • Only collect personal data your operation needs; avoid free-text questions that invite details about guests or staff health.

  • Disable rather than delete seasonal staff who will return; delete Users who have left for good.

  • Keep a simple log of the requests you receive and what you did in Mobaro for each.


Frequently asked questions

If I delete a user, do the checklists they completed disappear?

No. Completed Results and the history of their work stay in Mobaro and keep showing their name. Deleting removes them from Assignments, Schedules, groups and Roles, and deletes their Certifications. See How to deactivate a User.

Where is my data stored?

Mobaro's production systems are in Europe, on Microsoft Azure. See How Mobaro complies with GDPR and Sub Processors and Sub Contractors.

Can we set up a report where the person who submitted it is anonymous?

No. Mobaro always records who completed a Result. A Report Template can hide most names in the report itself, but not Timesheet entries; see Creating and using Report Templates.

Can I bring back a user I deleted?

Not yourself. Mobaro Support can recover a deleted account into your organization, but not its previous Roles or User Group memberships.

Did this answer your question?