1. Your rights
TL;DR — Access, rectification, erasure, portability, restriction, objection, and — where relevant — withdrawal of consent.
Under the EU GDPR, UK GDPR, Swiss revFADP, CCPA/CPRA, and most other modern privacy laws, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data;
- Erase data (subject to the retention exceptions in Privacy Policy §5);
- Restrict processing while we resolve a dispute;
- Object to processing based on legitimate interests;
- Port your data in a machine-readable format (JSON export);
- Withdraw consent for anything processed on consent (newsletter, product analytics).
2. How to submit a request
TL;DR — Use the form on /contact with request type "GDPR / Data rights", or email [email protected] directly.
The fastest path is the contact form — it routes the request to our privacy inbox and automatically tags it with type=gdpr, which surfaces in the admin inquiries view with a 1-business-day SLA.
Or email [email protected] directly. Tell us:
- which right you're exercising (access / rectification / erasure / etc.);
- the email + store domain associated with your Surfient account;
- any specifics (e.g. "please only delete telemetry, keep billing records for tax").
3. What happens next
TL;DR — 1 business day to acknowledge, 30 calendar days to complete.
We acknowledge every request within 1 business day. For straightforward requests (access, data export, deletion) we complete within the 30-calendar-day GDPR window. For complex requests we may extend by up to 60 days, but we'll tell you within the first 30 days that we're extending and why.
If we refuse a request (rare — usually only where a legal retention obligation applies), we'll explain why in writing and point you at your right to appeal to a supervisory authority.
4. California residents (CCPA/CPRA)
TL;DR — Same rights, one extra: you can tell us not to sell or share your personal information. (We don't sell, but you can still tell us.)
If you're a California resident, CCPA/CPRA gives you the rights in §1 above plus:
- Right to know what categories of personal information we collect, use, and share (all listed in Privacy Policy §2 and §4);
- Right to opt out of sale or sharing — we don't sell personal data, but you can still formally opt out via [email protected];
- Right to non-discrimination — we won't penalise you for exercising any CCPA right.
Ready to exercise your rights?
Use the contact form with the "GDPR / Data rights" option, or email [email protected].