GDPR & Data Rights
How to ask LABSZPHC about your personal information and request action on it.
WHEN THESE RIGHTS APPLY
Your rights depend on the law applicable to the processing of your personal information. The GDPR rights outlined below apply where the EU GDPR governs that processing; other jurisdictions may provide additional or different protections. We will handle requests according to the applicable requirements.
[REVIEW: Confirm territorial scope and whether an EU/UK representative or data protection officer is required. Add actual details where applicable; do not invent an appointment.]
RIGHTS YOU MAY EXERCISE
- Information and access: learn how your data is used and request access to personal information held about you.
- Correction: ask for inaccurate information to be corrected or incomplete information completed.
- Erasure: request deletion where the relevant conditions are met.
- Restriction: request limits on processing in qualifying circumstances.
- Portability: obtain qualifying data you provided in a reusable electronic format where processing is automated and based on consent or contract.
- Objection: object to qualifying processing based on your circumstances. You may object to processing for direct marketing.
- Consent withdrawal: where processing relies on consent, withdraw it for the future without affecting the lawfulness of earlier processing.
- Automated decisions: seek applicable safeguards concerning solely automated decisions with legal or similarly significant effects.
These rights have conditions and exceptions. The European Commission’s information for individuals provides further guidance.
HOW TO MAKE A REQUEST
Contact the privacy email above. “Data Rights Request” is a helpful subject line, but no special wording is required. Tell us what you would like us to do and provide enough context to locate the relevant records.
- Your reply address and, if relevant, the email used for an earlier enquiry.
- The relevant website feature, approximate date or message reference.
- The information or issue concerned, as far as you can describe it.
You do not need to create an account or use a special form. We will also recognise requests received through other appropriate contact channels. Do not send passwords, payment-card details or identity documents with an initial request.
IDENTITY AND REPRESENTATIVES
If reasonably necessary, we may ask for proportionate information to verify identity or a representative’s authority before releasing or changing personal data. We will explain what is needed and avoid collecting unnecessary information. A product code alone may not establish entitlement to another person’s records.
RESPONSES, FEES AND LIMITATIONS
Where the EU GDPR applies, we will respond without undue delay and normally within one month. If a lawful extension is needed, we will explain the reason and notify you within the initial month. Requests are normally free; any permitted fee or refusal must have a lawful basis and be explained.
If we cannot fulfil a request fully, we will explain the relevant reasons and available complaint or review routes, subject to applicable law. See the European Data Protection Board’s rights guidance.
VERIFICATION RECORDS AND BROWSER DATA
For a request relating to a verification check, describe the approximate time and relevant context. Do not post a complete unused authentication code publicly. If additional information is needed, we will explain how to provide it privately.
Clearing cookies or local storage does not automatically remove backend verification logs, enquiry emails or backups. Likewise, hiding query history on the public result page does not mean that no history is retained internally.
A data-rights request concerns personal information about you; it does not automatically require removal of the product-code inventory itself. We must also consider other people’s rights and any lawful retention requirements. We will explain relevant limits rather than promise immediate deletion of every copy.
[OPERATOR CHECK: Establish how requests will be handled across authentication logs, replacement/import backup tables, mailboxes, hosting logs and backups. Confirm retention and restoration procedures before publication.]
COMPLAINTS
You can contact us with a concern about our handling of your data. Where applicable, you may also complain to the competent data protection authority without first completing an internal complaint process. This page does not restrict your available legal remedies.
[ADD THE RELEVANT AUTHORITY’S VERIFIED CONTACT INFORMATION AFTER CONFIRMING THE OPERATOR’S LOCATION AND APPLICABLE LAW.]
RELATED NOTICES
Our Privacy Policy explains the purposes, legal bases, recipients and retention of personal information. Our Cookie Policy addresses browser storage and related choices. This page supplements those notices rather than replacing them.
[LINK TO THE FINALISED PRIVACY POLICY AND COOKIE POLICY. Confirm that the privacy mailbox is monitored and the published process can actually be followed.]