Last updated: 27 July 2026
This notice explains what personal data the data subject request portal (gdpr-request.com) collects, why it is used, how long it is kept, and your rights. It applies only to use of this portal.
Who is responsible
The organisation operating this portal is the data controller for information you submit here. For privacy questions or to exercise your rights outside this form, contact the Data Protection Officer / privacy team using the contact details published on the organisation’s main website, or via the contact email shown in verification and fulfilment messages where provided.
What we collect
- Name (first and last name you enter)
- Email address
- Request type (for example Delete Data or Request Copy)
- Technical details needed to run the service (for example IP address for rate limiting, and security checks such as reCAPTCHA)
- Verification and download tokens (stored hashed where applicable)
- Admin notes and audit events related to handling your request
Submitting this form proves control of the email inbox used for verification. It does not by itself prove legal identity beyond that email address.
Why we use your data
- To receive, verify, and process your data subject request
- To send verification, status, and (where applicable) secure download emails
- To prevent abuse (rate limiting and bot protection)
- To keep an audit trail of admin actions on your request
- To meet legal obligations under UK GDPR / GDPR
How long we keep it
- Unverified requests: removed after the verification window expires (typically within about 9 days of creation).
- Completed request records: retained for about 12 months after completion, then personal fields are anonymised (tracking/status history may remain).
- Copy packages: available for a limited time (typically 14 days after upload), then deleted. Download links expire sooner (typically 72 hours).
- Email delivery records: retained for a limited operational period (typically 90 days after a terminal delivery state).
Who can access your data
Authorised administrators of the organisation process requests through a protected admin area. Service providers that host email, storage, and the portal infrastructure (for example Microsoft Azure and related services) process data only as needed to run the service.
Your rights
Depending on applicable law, you may have rights to access, rectify, erase, restrict, or object to processing, and to lodge a complaint with a supervisory authority (in the UK, the Information Commissioner’s Office). You can use this portal to submit Delete Data or Request Copy requests related to the organisation’s processing.
Security
Access to the admin area requires authentication. Verification and download links use short-lived secrets. The public site is served over HTTPS. No method of transmission or storage is perfectly secure; report suspected misuse promptly to the organisation.
Changes
We may update this notice when the portal or retention practices change. The “Last updated” date at the top will be revised when material changes are made.