- MIRENA
- Compliance
- Data Rights Request Process
Compliance · Governance standard
Receive, verify, search, review, and answer a data-rights request through the correct controller.
The process covers intake, controller identification, identity verification, scope, search, third-party rights, legal holds, response, timing, refusal, complaint rights, provider routing, and records.
Semantec SEO Data Rights Request Handling Standard
The standard states what must happen, who owns the decision, what evidence is required, and what blocks release.
Intake and acknowledgement
Requests should be sent to privacy@semantecseo.com and logged with the receipt date, requester, contact route, stated right, relevant service, date range, and initial scope.
A request does not require legal terminology. The substance of the message controls.
Identify the controller and record
Determine whether Semantec SEO controls the requested website, account, entitlement, billing, support, privacy, security, or business record.
ChatGPT account, conversation, file, memory, training, and platform records may belong to OpenAI. Stripe, Authflow.ai, or another provider may control separate records.
Verify identity proportionately
Use existing account context, the originating email, transaction details, or other low-intrusion evidence where suitable. Ask for additional proof only when reasonably necessary.
Do not request a passport, driving licence, password, authentication code, or full card number by default. Use a secure route and delete excess verification material when no longer needed.
Clarify only where necessary
Where a large quantity of information is processed, ask the requester to clarify the information or activities sought only when reasonably necessary to locate the data.
Clarification must not be used to delay the request or narrow it unfairly.
Search and preserve
Search relevant account, entitlement, billing, support, privacy, security, communication, consent, website, and provider records controlled or received by Semantec SEO.
Preserve the request, search record, evidence, and legal hold while the matter is active. Do not collect new unrelated data merely to answer the request.
Assess the right and exceptions
| Right | Primary action | Review questions |
|---|---|---|
| Access | Confirm processing, provide data and required information | Rights of others, privilege, trade secrets, identity, format |
| Correction | Correct or complete eligible data | Evidence, disputed record, recipient notification |
| Deletion | Delete eligible data or explain retention | Legal obligation, claims, security, freedom of expression, other exceptions |
| Restriction | Limit eligible processing | Accuracy dispute, unlawful processing, objection, claim need |
| Portability | Provide eligible data in a structured machine-readable format | Consent or contract, automated processing, rights of others |
| Objection | Assess the lawful basis and compelling grounds | Direct marketing, public task, legitimate interests |
| Withdraw consent | Stop future consent-based processing | Earlier processing and separate lawful bases |
Protect the rights of others
An access or portability response should not adversely affect another person's privacy, trade secrets, intellectual property, confidentiality, or legal rights.
Redact or separate affected material where possible rather than refusing the entire request automatically.
Respond within the legal period
Act without undue delay and generally within one month of receipt. A permitted extension of up to two further months may apply where the request is complex or numerous, with notice and reasons within the first month.
Requests are generally free. A reasonable fee or refusal for a manifestly unfounded or excessive request requires a documented legal basis.
Explain refusal, limitation, and complaint rights
A full or partial refusal should identify the legal reason, the decision, and the right to complain to the Irish Data Protection Commission or another competent authority and to seek a judicial remedy where applicable.
Notify recipients and providers where required
Where applicable, communicate a correction, deletion, or restriction to recipients or processors and record their response.
Do not direct a provider to alter records it controls independently without a lawful and authorised route.
Close and retain the compliance record
Store the request, identity method, searches, decisions, redactions, response, dates, provider communications, complaint status, and retention trigger.
The record is retained only as long as needed to demonstrate compliance, handle disputes, and meet legal obligations.
Review and improvement
Repeat issues should update the Privacy Policy, provider register, retention schedule, support process, identity-verification method, or staff guidance that caused the friction.
Controlling guidance and first-party records.
The standard uses current source material but does not convert platform guidance into a ranking guarantee.
Irish DPC access and portability guidance
Official one-month, format, and clarification guidance.
Irish DPC right of access
Official rights-of-others and partial-disclosure guidance.
Semantec SEO GDPR Notice
Current first-party controller and request baseline.
Continue to the owner of the next control.
Claims, sources, AI review, approval, corrections, conflicts, and rights requests remain separate decisions.
Owned route
GDPR overview
Public rights, timing, verification, and complaint information.
Open route →
Owned route
Privacy Policy
Controller, purposes, recipients, retention, and rights.
Open route →
Owned route
Data retention
Retention criteria and deletion boundaries.
Open route →
Owned route
Provider register
External controller and processor routes.
Open route →
Owned route
Contact
Privacy request and support details.
Open route →
Owned route
Corrections Policy
Correction and propagation for public records.
Open route →