GDPR – Processing data subject rights requests

1. Purpose

The General Data Protection Regulation (GDPR) aims to safeguard individuals’ fundamental rights and freedoms, particularly their right to privacy and control over their personal data. It is based on the principles of transparency, fairness, and accountability, requiring organizations to process data lawfully, fairly, and securely.

Beyond legal compliance, the GDPR embodies an ethical approach designed to establish a relationship of trust between data controllers and data subjects. It requires the implementation of organizational and technical measures to uphold individuals’ rights, mitigate risks, and demonstrate compliance at all times (the accountability principle).

The purpose of this procedure is to define within GravitHy the rules, responsibilities, and steps required to receive, assess, process, and respond to requests from data subjects exercising their rights under the General Data Protection Regulation.

2. Scope

This procedure applies to all personal data processing activities carried out by GravitHy in its capacity as either a data controller or a data processor as part of its commercial, administrative, and technical operations.

It applies to all data subjects involved in such processing activities, including:

This procedure covers all requests to exercise rights granted under the GDPR (Articles 12 to 23), regardless of the channel through which the request is received (email, postal mail, online form), and applies to all systems and media used for data processing (IT databases, paper files, business applications).

3. References

4. Definitions

Personal Data

Any information relating to an identified or identifiable natural person. A natural person may be identified:

A person may be identified:

Processing

Any operation or set of operations performed on personal data, regardless of the means used, including collection, recording, organization, storage, adaptation, modification, extraction, consultation, use, disclosure by transmission or dissemination, or any other form of making data available, as well as matching or combining data.

Data Controller

The natural or legal person, public authority, agency, or other body that alone or jointly with others determines the purposes and means of processing personal data. For the purposes of this procedure, the Data Controller is GravitHy.

Data Processor

The natural or legal person, public authority, agency, or other body that processes personal data on behalf of the Data Controller. In the course of its activities, GravitHy may act as a processor or appoint processors.

5. Right to Information

This right guarantees that any individual whose personal data is processed is informed in advance, in a transparent and understandable manner, of the key aspects of the relevant processing activity (Article 13 GDPR).

6. Right of Access

Provided for under Article 15 GDPR, this right allows a data subject to obtain confirmation as to whether their personal data is being processed, to access such data, verify its accuracy, and obtain copies at any time without restriction.

7. Right to Rectification

Provided for under Article 16 GDPR, this right allows any data subject to obtain from the Data Controller the correction of inaccurate personal data or the completion of incomplete data.

8. Right to Erasure (Right to be Forgotten)

Provided for under Article 17 GDPR, this right allows a data subject to request that the Data Controller delete their personal data without undue delay, subject to certain conditions.

The right to erasure does not apply where processing is necessary for:

9. Right to Restriction of Processing

Provided for under Article 18 GDPR, this right allows a data subject to request that their personal data no longer be processed but only stored, particularly when:

10. Right to Data Portability

Provided for under Article 20 GDPR, this right enables a data subject to receive their personal data in a structured, commonly used, and machine-readable format and to transmit it to another Data Controller without hindrance when:

11. Right to Object

Provided for under Article 21 GDPR, this right allows a data subject to object at any time, on grounds relating to their particular situation, to the processing of their personal data when such processing is based on:

12. Right Not to Be Subject to Automated Individual Decision-Making

Provided for under Article 22 GDPR, this right allows an individual to request that a decision based on their personal data not be made solely through automated processing or algorithmic analysis, but also be subject to review or verification by a natural person.

13. Procedure

Requests to exercise GDPR rights must be sent to:

Email:
rgpd@gravithy.eu

Or by post:
GravitHy
Attention: GDPR Contact Person
5 Rue du Louvre
75001 Paris
France

If a request is initially made orally, it must subsequently be confirmed in writing by the requester to facilitate, among other things, proper identification.

13.1 Receipt of the Request by GravitHy

Each request received shall be recorded by the Personal Data Contact Person in a centralized register containing:

13.2 Acknowledgement of Receipt

The GDPR Contact Person shall acknowledge receipt of the request as soon as possible (within a maximum of 72 hours).

The acknowledgement must specify the maximum response period (one calendar month). If the request is unclear or incomplete, additional information may be requested.

13.3 Verification of the Requester’s Identity

The identity of the individual exercising their rights must be verified to ensure that the request does not relate to a third party.

Where there is reasonable doubt concerning the identity of the requester, proof of identity may be requested. However, this should remain an exceptional measure.

13.4 Qualification and Admissibility of the Request

The GDPR Contact Person shall determine the nature of the request (access, erasure, rectification, etc.).

The Contact Person shall then assess its admissibility, ensuring in particular that:

13.5 Processing of the Request

13.5.1 The Data Concerned Is Processed by GravitHy

After acknowledging receipt, qualifying the request, and assessing its admissibility, the Personal Data Contact Person shall forward the request to the relevant department(s).

The relevant department(s) must provide a response to the Contact Person within a maximum period of ten (10) days from receipt of the request, including the requested information or confirmation that the requested action has been completed (erasure, rectification, etc.).

The relevant departments shall prepare, in collaboration with the GDPR Contact Person, a response file containing all personal data effectively held in an intelligible format and explaining:

13.5.2 The Data Concerned Is Processed by a Processor

GravitHy remains the sole point of contact for the requester.

The GDPR Contact Person shall notify the processor without delay and provide formal instructions specifying:

Upon receipt of the information from the processor, the GDPR Contact Person shall verify:

The GDPR Contact Person shall also obtain evidence that the requested action has been carried out (e.g., confirmation of deletion or modification).

In all cases, the Data Controller must refuse a request for erasure where the request is not legally justified (for example, where the data remains necessary for the performance of a contract).

13.6 Response to the Request

A response must be provided in writing within a maximum of one month. This period may be extended by an additional month in the case of multiple and complex requests.

Where the data is processed by a processor, the response must always be issued by GravitHy in its capacity as Data Controller.

14. Record Retention

Requests and responses shall be retained for three (3) years as evidence in the event of an inspection by the French Data Protection Authority (CNIL).

15. Updates

This policy is the property of GravitHy.

It may be amended at any time to reflect legislative, regulatory, case law, or technical developments, as well as changes in our practices relating to the processing of personal data.