Skip to main content

  1. MIRENA
  2. Compliance
  3. Data Rights Request Process

Compliance · Governance standard

Receive, verify, search, review, and answer a data-rights request through the correct controller.

The process covers intake, controller identification, identity verification, scope, search, third-party rights, legal holds, response, timing, refusal, complaint rights, provider routing, and records.

Governance standard

Semantec SEO Data Rights Request Handling Standard

The standard states what must happen, who owns the decision, what evidence is required, and what blocks release.

01 · Receive

Intake and acknowledgement

Requests should be sent to privacy@semantecseo.com and logged with the receipt date, requester, contact route, stated right, relevant service, date range, and initial scope.

A request does not require legal terminology. The substance of the message controls.

02 · Route

Identify the controller and record

Determine whether Semantec SEO controls the requested website, account, entitlement, billing, support, privacy, security, or business record.

ChatGPT account, conversation, file, memory, training, and platform records may belong to OpenAI. Stripe, Authflow.ai, or another provider may control separate records.

03 · Verify

Verify identity proportionately

Use existing account context, the originating email, transaction details, or other low-intrusion evidence where suitable. Ask for additional proof only when reasonably necessary.

Do not request a passport, driving licence, password, authentication code, or full card number by default. Use a secure route and delete excess verification material when no longer needed.

04 · Scope

Clarify only where necessary

Where a large quantity of information is processed, ask the requester to clarify the information or activities sought only when reasonably necessary to locate the data.

Clarification must not be used to delay the request or narrow it unfairly.

05 · Locate

Search and preserve

Search relevant account, entitlement, billing, support, privacy, security, communication, consent, website, and provider records controlled or received by Semantec SEO.

Preserve the request, search record, evidence, and legal hold while the matter is active. Do not collect new unrelated data merely to answer the request.

06 · Decide

Assess the right and exceptions

Request decision
Right Primary action Review questions
Access Confirm processing, provide data and required information Rights of others, privilege, trade secrets, identity, format
Correction Correct or complete eligible data Evidence, disputed record, recipient notification
Deletion Delete eligible data or explain retention Legal obligation, claims, security, freedom of expression, other exceptions
Restriction Limit eligible processing Accuracy dispute, unlawful processing, objection, claim need
Portability Provide eligible data in a structured machine-readable format Consent or contract, automated processing, rights of others
Objection Assess the lawful basis and compelling grounds Direct marketing, public task, legitimate interests
Withdraw consent Stop future consent-based processing Earlier processing and separate lawful bases
07 · Balance

Protect the rights of others

An access or portability response should not adversely affect another person's privacy, trade secrets, intellectual property, confidentiality, or legal rights.

Redact or separate affected material where possible rather than refusing the entire request automatically.

08 · Respond

Respond within the legal period

Act without undue delay and generally within one month of receipt. A permitted extension of up to two further months may apply where the request is complex or numerous, with notice and reasons within the first month.

Requests are generally free. A reasonable fee or refusal for a manifestly unfounded or excessive request requires a documented legal basis.

09 · Explain

Explain refusal, limitation, and complaint rights

A full or partial refusal should identify the legal reason, the decision, and the right to complain to the Irish Data Protection Commission or another competent authority and to seek a judicial remedy where applicable.

10 · Propagate

Notify recipients and providers where required

Where applicable, communicate a correction, deletion, or restriction to recipients or processors and record their response.

Do not direct a provider to alter records it controls independently without a lawful and authorised route.

11 · Record

Close and retain the compliance record

Store the request, identity method, searches, decisions, redactions, response, dates, provider communications, complaint status, and retention trigger.

The record is retained only as long as needed to demonstrate compliance, handle disputes, and meet legal obligations.

12 · Improve

Review and improvement

Repeat issues should update the Privacy Policy, provider register, retention schedule, support process, identity-verification method, or staff guidance that caused the friction.

Sources

Controlling guidance and first-party records.

The standard uses current source material but does not convert platform guidance into a ranking guarantee.

Irish Data Protection Commission
Irish DPC access and portability guidance

Official one-month, format, and clarification guidance.

Open source →

Irish Data Protection Commission
Irish DPC right of access

Official rights-of-others and partial-disclosure guidance.

Open source →

Semantec SEO
Semantec SEO GDPR Notice

Current first-party controller and request baseline.

Open source →