Data Subject Rights.
One workflow to exercise your rights as a data principal, data subject, or consumer, under India's DPDPA, the EU and UK GDPR, or the CCPA / CPRA in California.
What this page does
This is a single workflow for any right you wish to exercise over the personal data SMMARUN holds about you. It covers three regimes:
- India's Digital Personal Data Protection Act, 2023 (the DPDPA) and the rules made under it.
- The EU General Data Protection Regulation and the UK GDPR (together, GDPR / UK GDPR).
- The California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, CCPA / CPRA).
You do not need to know which regime applies to you. Tell us where you are and what you want to do, and we will route the request correctly. If more than one regime applies, we will apply the standard most favourable to you.
Your rights, by regime
Under the DPDPA (India)
If you are a data principal under the DPDPA, you have the right to:
- Access a summary of the personal data we hold about you and the processing activities applied to it (DPDPA Section 11).
- Correction, completion, and erasure of personal data (DPDPA Section 12).
- Grievance redressal through our Grievance Officer (DPDPA Section 13).
- Withdraw consent at any time, with prospective effect.
- Nominate another person to exercise your rights in the event of death or incapacity.
Under the GDPR / UK GDPR (EU and UK)
If you are a data subject under the GDPR or UK GDPR, you have the right to:
- Access a copy of your personal data and information about how it is processed (Article 15).
- Rectification of inaccurate or incomplete data (Article 16).
- Erasure in the circumstances set out in Article 17.
- Restriction of processing in the circumstances set out in Article 18.
- Data portability for data you have provided to us, where Article 20 applies.
- Object to processing carried out on the basis of legitimate interests or for direct marketing (Article 21).
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you (Article 22). SMMARUN does not carry out such decision-making.
Under the CCPA / CPRA (California)
If you are a consumer under the CCPA / CPRA, you have the right to:
- Know what personal information we have collected, the categories of sources, the business or commercial purposes, and the categories of third parties with whom we share it.
- Delete personal information we have collected about you, subject to the exceptions in California Civil Code §1798.105(d).
- Correct inaccurate personal information.
- Opt out of sale or sharing of personal information. SMMARUN does not sell or share personal information in the CCPA / CPRA sense; we honour the right as a matter of course.
- Limit the use and disclosure of sensitive personal information to purposes specified in the regulations.
- Non-discrimination for exercising any of the above (Civil Code §1798.125).
How to submit a request
Write to hello@smmarun.ai using one of the following subject lines, so the request is routed correctly:
- DPDPA request
- GDPR request
- UK GDPR request
- CCPA request
In the body, please include:
- Your full name.
- The email address you have used to interact with SMMARUN (forms, Library requests, correspondence).
- The regime under which you are exercising the right.
- The specific right or rights you wish to exercise.
- Any details that will help us locate the right records (for example, the date of an enquiry or the title of a paper requested).
You are not required to disclose more than is necessary to identify you and the records concerned. If we ask for more, we will explain why.
Identity verification
Before we act on a request, we need to be reasonably satisfied that the request comes from you. We may ask one or two follow-up questions to confirm your identity, such as the date or subject of a recent enquiry, or the company name associated with your work email.
We do not over-collect. We will not ask for government identity documents, financial information, or biometric data to verify a request of this kind. If we cannot verify your identity within reason, we will tell you in writing, explain why, and where possible suggest an alternative path.
Response timelines
- DPDPA: timelines are set by the rules notified under the Act. The detailed rules are pending at the time of writing. As a working ceiling we aim to respond within 30 calendar days, and sooner where we can.
- GDPR / UK GDPR: within 30 calendar days of receipt, extendable by a further 60 days where the request is complex or where several requests are made, per Article 12(3). If we extend, we will tell you within the first 30 days and explain the reason.
- CCPA / CPRA: within 45 calendar days of receipt, extendable by a further 45 days where reasonably necessary, per Civil Code §1798.130(a)(2). If we extend, we will tell you within the first 45 days.
We will acknowledge receipt of every request promptly, regardless of regime.
If we cannot fulfil a request
In a small number of circumstances we may not be able to fulfil a request in full, or at all. These include:
- Where we are required to retain the data under a legal or regulatory obligation (for example, tax, audit, or statutory record-keeping).
- Where fulfilling the request would adversely affect the rights and freedoms of another person.
- Where the request is manifestly unfounded or excessive, including repeated requests of the same kind.
- Where an exemption in the applicable regime expressly permits us to decline.
If we decline a request in whole or in part, we will tell you which circumstance applies, why it applies, and how to appeal.
Appeal route
If you are not satisfied with how we have handled your request, you may escalate as follows.
- Internal escalation: contact our Grievance Officer, Preeti Mohan, at preeti.mohan@smmarun.ai. We will acknowledge within 24 hours and aim to resolve within 15 calendar days.
- DPDPA (India): the Data Protection Board of India, established under the Act.
- GDPR (EU): the supervisory authority in your country of habitual residence, place of work, or place of the alleged infringement, with EDPB cooperation for cross-border matters.
- UK GDPR: the Information Commissioner's Office (ICO).
- CCPA / CPRA: the California Privacy Protection Agency, or the California Attorney General.
No charge, no retaliation
You can exercise these rights free of charge. We do not require payment, a subscription, or any other consideration in return.
We will not retaliate against you for exercising a right. In particular, under CCPA / CPRA §1798.125 we will not deny you goods or services, charge different prices, provide a different quality of service, or suggest that any of these consequences may follow from your request.