Your Data Rights
Effective July 2026 · Version 3.0
You have rights over the personal data we hold about you. This page explains each right, what it covers, and how to exercise it. We are committed to responding promptly and without unnecessary barriers.
1. Right of access
You have the right to request confirmation of whether we hold personal data about you, and if so, a copy of that data along with information about how we use it, who we share it with, and how long we keep it.
We will provide this as a structured summary in a commonly used format (typically PDF or plain text) at no charge for the first request in any 12-month period.
2. Right to correction (rectification)
If any personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct it promptly. We will update the data within our systems and inform any third parties to whom we have disclosed the data where doing so is practicable.
3. Right to deletion (erasure)
You may request that we delete personal data we hold about you in the following circumstances:
- The data is no longer necessary for the purpose for which it was collected.
- You withdraw consent and there is no other legal basis for processing.
- You object to processing and we have no overriding legitimate grounds.
- The data has been unlawfully processed.
- Deletion is required to comply with a legal obligation.
See Section 13 for data we are legally required to retain and cannot delete on request.
4. Right to restriction of processing
You may request that we pause the processing of your personal data (while still storing it) in these situations:
- You contest the accuracy of the data, while we verify it.
- Processing is unlawful but you prefer restriction to deletion.
- We no longer need the data for our purposes, but you need it for a legal claim.
- You have objected to processing, pending verification of whether our legitimate grounds override yours.
During a restriction, we will only process the data with your consent or for the establishment, exercise, or defence of legal claims.
5. Right to data portability
Where processing is based on your consent or on a contract, and carried out by automated means, you may request your personal data in a structured, commonly used, machine-readable format (such as CSV or JSON). You may also request that we transmit it directly to another controller where technically feasible.
This right applies to data you provided to us directly (such as your account information, contact details, and communications) and does not extend to data we derived or inferred from your activity.
6. Right to object
You may object at any time to processing of your personal data where that processing is based on legitimate interests or for direct marketing purposes.
- Legitimate interests: We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is for the establishment, exercise, or defence of legal claims.
- Direct marketing: If you object to processing for direct marketing (including profiling for marketing purposes), we will stop immediately without exception.
7. Right against automated decision-making
ACKINGLOBAL does not make decisions about you based solely on automated processing that produce legal or similarly significant effects. We do not engage in automated profiling that affects your access to our services or the terms on which they are offered.
If this changes in the future, we will update this page and our Privacy Policy accordingly and give you the right to request human review of any automated decision.
8. Right to withdraw consent
Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal is as easy as giving consent:
- Analytics and marketing cookies: Use the cookie preferences banner on this website to withdraw consent. Changes take effect immediately.
- Email marketing: Use the unsubscribe link in any email or contact us directly.
- Any other consent-based processing: Email us at hello@ackinglobal.com.
Withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal.
9. CCPA / CPRA rights (California residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) gives you these specific rights:
- Right to know: Request disclosure of the categories and specific pieces of personal information collected about you in the past 12 months.
- Right to delete: Request deletion of personal information we collected from you (subject to exceptions).
- Right to correct: Request correction of inaccurate personal information.
- Right to opt out of sale or sharing: We do not sell personal information. We do not share personal information for cross-context behavioural advertising without consent.
- Right to limit use of sensitive personal information: We do not use or disclose sensitive personal information beyond what is necessary to provide our services.
- Right to non-discrimination: Exercising your CCPA/CPRA rights will not result in denial of services, different pricing, or different quality of service.
To submit a CCPA/CPRA request, use the process in Section 10 and include "California Privacy Request" in your subject line. We will acknowledge within 10 business days and respond within 45 days.
Authorised agents may submit requests on your behalf with written proof of authorisation.
10. How to submit a request
Email hello@ackinglobal.com with:
- Subject line: [Right type] Request - e.g., "Data Access Request" or "Data Deletion Request"
- Your full name
- The email address associated with your account or enquiry
- A description of your request and the specific data it concerns
- Any additional information required for identity verification (see Section 12)
All requests are handled confidentially by a designated team member. We will not charge a fee for reasonable requests.
11. Response timelines
| Jurisdiction | Acknowledgement | Full response | Extension allowed |
|---|---|---|---|
| EU / EEA (GDPR) | Without undue delay | 30 days | Up to 60 additional days for complex requests (you will be notified) |
| UK (UK GDPR) | Without undue delay | 30 days | Up to 60 additional days for complex requests |
| California (CCPA/CPRA) | 10 business days | 45 days | Up to 45 additional days (you will be notified) |
| Canada (PIPEDA) | As soon as practicable | 30 days | Extension possible with notice |
| All other regions | Within 5 business days | 30 days | Up to 30 additional days for complex requests |
12. Identity verification
To protect your privacy, we verify your identity before processing most requests. We use a risk-based approach:
- For low-sensitivity requests (such as confirming what categories of data we hold), we verify by confirming details that match our records (email address, project name).
- For higher-sensitivity requests (full data copy, deletion of account data), we may ask you to confirm additional details or provide a government-issued ID.
- We will never ask for your password.
We will not process a request if we cannot reasonably verify your identity, to prevent unauthorised access to others' data.
13. Data we cannot delete
Some data must be retained regardless of a deletion request to comply with legal obligations:
- Financial and transaction records (invoices, payment confirmations, contracts) - retained for 7 years to comply with tax and accounting laws in applicable jurisdictions.
- Data subject to an active legal dispute or regulatory inquiry - retained until the matter is resolved.
- Data needed to comply with a court order or law enforcement request - retained for the duration specified.
- Security and fraud prevention logs - retained for up to 90 days for security monitoring.
Where deletion is not possible due to a legal retention obligation, we will inform you of what data must be retained, for how long, and why. All other data within your request will still be deleted.
14. Complaints and supervisory authorities
If you are not satisfied with how we handle your data rights request, you have the right to lodge a complaint with the relevant supervisory authority:
- EU/EEA: Your national data protection authority - find yours at edpb.europa.eu.
- UK: Information Commissioner's Office (ICO) - ico.org.uk/make-a-complaint
- Canada: Office of the Privacy Commissioner of Canada - priv.gc.ca
- Australia: Office of the Australian Information Commissioner (OAIC) - oaic.gov.au
- California: California Privacy Protection Agency (CPPA) - cppa.ca.gov
We ask that you contact us first so we can try to resolve your concern before you escalate to a supervisory authority.
Contact: hello@ackinglobal.com