Getting started
- Sign in with your administrator or workspace-member account.
- Open Settings to review the organization name, privacy contact, target-date configuration, and retention policy.
- Open Portal to configure the requester-facing company name, introduction, request types, contact details, and privacy-policy link.
- Open the public portal from the sidebar and submit a test request using synthetic information.
Do not use real personal information until your workspace has completed its production-readiness review and has been activated for live processing.
Using the request queue
The Requests page lists the privacy requests available to your workspace. Use it to review request type, requester, status, assignee, target date, and recent activity.
- Use filters to focus on the requests that need attention.
- Open a row to view the complete request workspace.
- Use the CSV export only when you are authorized to export workspace records.
Working on a request
Each request workspace combines the requester's submission with the organization's workflow record.
- Confirm that the request belongs to the correct organization workspace.
- Assign an owner and choose an internal handling priority.
- Review the requester's description and organization account reference.
- Complete workflow tasks and record searches performed in connected or external systems.
- Record status changes only after the corresponding organization action has occurred.
- Use the activity history to review recorded actors, timestamps, messages, and decisions.
Recording verification
Email confirmation records access to the submitted email address. It does not establish legal identity or decide whether another method is needed.
Administrators can record methods such as review through an existing customer account, manual organization review, or an approved external process. Record what actually happened and avoid placing identity documents, passwords, or unnecessary sensitive information in notes.
Configuring target dates
In Settings > Target dates, administrators choose the organization's calendar-day target, rule name, version, source, and review date.
- Requester location does not automatically select a rule.
- Each new request records the organization configuration used at creation.
- An individual target date can be changed only with a recorded organization reason.
- A passed target is a workflow signal, not a legal determination.
Messages and templates
Requester messages and internal notes are separate. Requesters can see messages intended for them, while internal notes remain in the administrative workflow.
- Keep messages factual, concise, and organization-authored.
- Do not include passwords, payment-card information, identity documents, or unnecessary personal information.
- Treat saved templates as editable starting drafts. Review each message for the circumstances before sending it.
- OtterPortal does not certify that a template or message satisfies a legal requirement.
Managing the requester portal
The Portal page renders the same request experience used by requesters. Draft changes appear in an isolated preview and do not submit a request.
- Choose the request types your organization is prepared to receive.
- Use a role-based contact mailbox that is safe to publish.
- Add the organization's public privacy-policy URL when available.
- Save changes before expecting them to appear on the public portal.
- Custom-domain DNS and certificates are managed by the hosting operator.
Protecting your account
Enable authenticator-app MFA from Account security. OtterPortal supports standard TOTP applications.
- Enter your current password and select Set up.
- Scan the QR code with your authenticator app.
- Enter the generated six-digit code.
- Copy or download the one-time recovery codes and store them privately.
- Use trusted-device access only on a private device you control.
Regenerating recovery codes invalidates all previous recovery codes and trusted devices. Disabling MFA also signs out other sessions.
Retention and account deletion
Administrators configure active-database retention periods in Settings > Data retention. The authenticated retention worker removes eligible active records according to that configuration.
Active-database deletion does not prove immediate removal from backups, infrastructure logs, provider systems, caches, or downstream services. Those systems require separate lifecycle controls.
Account deletion requires the current password, an MFA or recovery code when MFA is enabled, and the explicit confirmation shown on the security page.
Current product boundaries
OtterPortal does not currently provide identity-document uploads, response-file hosting or delivery, team invitations, API keys, outbound webhooks, automated legal-rule selection, or automatic external-system searches.
Unavailable controls are disabled or clearly labeled. For more detail, review Trust and product scope, Privacy, and Terms.
Need additional help? Use the support contact listed on the Privacy page.