GDPR and data requests

How to ask about your personal data and exercise applicable privacy rights.

Your personal data

The Privacy Policy on the main website describes PrimalDesk’s current data practices. This guide explains how to make a request; it is not a separate privacy policy or a certification of compliance.

Rights under the GDPR

Where the GDPR applies, rights may include access, correction, erasure, restriction, portability and objection. Their availability depends on the circumstances and the legal basis for processing. You may withdraw consent for processing based on consent, without affecting the lawfulness of earlier processing. You may also complain to a competent data protection authority.

Send a request

Email privacy@primaldesk.com with the account email or early-access signup address and the action you are requesting. State whether your request concerns an account, a host or the early-access list. Do not send passwords, access tokens or identity documents in the initial message. Additional information may be needed to verify identity and protect another person’s data.

If available in your account, the privacy controls provide data export and account deletion. For an early-access signup, you can request removal by email without creating an account.

Timing and limitations

Under the GDPR, requests generally require a response within one month. An extension of up to two further months may be permitted for complex or numerous requests, with notification and reasons within the first month. Some information may need to be retained where an applicable legal exception allows or requires it; erasure is not an unconditional right.

See the European Commission’s guidance on individual requests for the general rules.