GDPR — your rights, in detail
The GDPR (Regulation (EU) 2016/679), the UK GDPR and Canada's PIPEDA give you eight concrete rights over your personal data. This page is the operational playbook — what each right means, how to exercise it at FotifyPay, and what we are allowed to refuse.
0. The doctrine in one paragraph
GDPR is built on accountability. We don't just say "we protect your data" — we have to show the lawful basis (Art. 6), the documentation (Art. 30), the controls (Art. 32) and the impact assessments (Art. 35) for every kind of processing. This page is the customer-facing slice of that work.
1. The rights, in order
1.1 Right to information (Art. 13 & 14)
You get told, at collection time, who we are, what we collect, why and on what legal basis. That notice lives in our Privacy Policy.
1.2 Right of access (Art. 15)
You can ask for a copy of your personal data and a description of how we use it. We respond within 30 calendar days (extendable by 60 days for complex requests, with notice). First copy is free; we may charge a reasonable administrative fee for repetitive or excessive requests (Art. 12(5)).
Submit: dashboard → "Download my data" or privacy@fotifypay.com.
1.3 Right to rectification (Art. 16)
Wrong name spelling, outdated address — fix it in the dashboard or write to privacy@fotifypay.com. We propagate the correction to every processor (Art. 19) within a week.
1.4 Right to erasure ("right to be forgotten" — Art. 17)
You can ask us to delete your personal data. We delete unless we are legally required to keep it — chiefly the five-year AML retention obligation in Art. 21 AMLR, reg. 40 UK MLR 2017 and s. 12.1 PCMLTFA Regulations. When we refuse, we tell you exactly which provision compels us, and we delete everything not covered by that provision.
1.5 Right to restriction (Art. 18)
You can ask us to stop using your data (but keep it stored) while a dispute is being sorted — e.g. while you contest the accuracy of an entry.
1.6 Right to data portability (Art. 20)
You can download the personal data you gave us in a structured, commonly used, machine-readable format (JSON + CSV). We can transmit it directly to another controller where technically feasible.
1.7 Right to object (Art. 21)
You can object to processing based on legitimate interests (Art. 6(1)(f)) — for example, our fraud-prevention analytics. We then stop unless we can show compelling legitimate grounds that override your interests, or we need to defend a legal claim.
1.8 Rights related to automated decision-making (Art. 22)
We use rule-based risk scoring during KYC. We do not rely on solely-automated decisions that produce legal or similarly significant effects without a human in the loop. Where a transaction is paused by risk, a compliance officer reviews before any final decision — and you can request that review explicitly.
2. How long we take
| Right | Target | Statutory ceiling |
|---|---|---|
| Access (Art. 15) | 7 calendar days | 30 days, extendable +60 |
| Rectification (Art. 16) | 3 business days | 30 days |
| Erasure (Art. 17) | 14 calendar days | 30 days |
| Restriction (Art. 18) | Immediate | 30 days |
| Portability (Art. 20) | 7 calendar days | 30 days |
| Objection (Art. 21) | Immediate | 30 days |
3. How to exercise a right
- Self-serve in the dashboard where available (download, edit, delete, export).
- Otherwise email privacy@fotifypay.com from your registered address. Include "GDPR" in the subject and the right you want to exercise.
- We may ask for one additional identifier (e.g. order ID) if we cannot identify you confidently — never more than necessary (Art. 12(2)).
4. Data Protection Officer
Our DPO is reachable at dpo@fotifypay.com. The DPO operates independently of the business, in line with Art. 38 GDPR.
5. International transfers — your safeguards
Where data leaves the EEA, it travels under the European Commission Standard Contractual Clauses (Decision (EU) 2021/914), with Transfer Impact Assessments documented for each route. For UK transfers we use the ICO International Data Transfer Addendum. You can request a copy of the SCCs we have in place with any specific processor.
6. Personal data breach handling (Art. 33 & 34)
If a breach is likely to risk your rights or freedoms, we notify the lead supervisory authority within 72 hours. Where the risk is high, we notify you directly without undue delay. DORA (Reg. (EU) 2022/2554) timelines for ICT-related incident reporting run in parallel.
7. Right to complain
- EU: your country's Data Protection Authority — list at edpb.europa.eu.
- UK: Information Commissioner's Office.
- Canada: Office of the Privacy Commissioner of Canada.