Skip to main content

How can respondents request to access, edit, or delete their personal data processed by Retently

Written by Alex Bitca

Retently is a Processor, not the Controller. For the contact data you import into Retently, we only process what you send us, and we can surface or act on the data we hold. You remain responsible for any data about the person that you process outside Retently.

Survey respondents can ask to see, correct or delete the personal data you hold about them in Retently, and opt out of future surveys, directly from your surveys. Every request lands on the Privacy requests page in your account, where you can handle it yourself or let Retently handle it for you. This article covers what respondents see, how to work the requests, and how automatic handling works.

How a respondent submits a request

Every email survey includes an Unsubscribe link in its footer.

​

​

Clicking it opens the Unsubscribe page, where respondents can opt out of future surveys.

​

Below the unsubscribe options is a second link: Request your data access, edit or removal.

​

​

This link opens the Manage your personal data page, with three options:

  • Show me the data you have about me (access request). The respondent sees a confirmation and stays subscribed to surveys. The confirmation includes an Unsubscribe link in case they also want to opt out.

  • Correct my personal data (correction request). The respondent gets a short form showing the values you hold for seven fields: First name, Last name, Job title, Company, Phone, City and Country. They edit what is wrong and send the correction. Their email address is shown for context but cannot be changed. They stay subscribed to surveys.

  • Delete my personal data (deletion request). The respondent confirms in a dialog, which tells them they will also stop receiving your surveys. They are unsubscribed immediately.

​

A Back to unsubscribe options link returns them to the Unsubscribe page. It can be reworded or translated, but not removed.

​

A few things worth knowing:

  • The correction form shows only those seven fields. It does not reveal your tags, custom properties, internal notes, responses, scores or anything else stored on the contact.

  • Only real changes are sent. If a respondent opens the correction form and submits it without editing anything, no request is created. Clearing a field counts as a change (for example, "I don't want a job title on record").

  • Opting out and data rights are separate. A respondent who has already unsubscribed can still open the data request page and submit a request.

  • A deletion request cannot be undone from the dashboard as an opt-out. Because the respondent unsubscribed themselves, you cannot resubscribe them from the dashboard.

​

Who gets notified

When a request arrives, an email goes to every team member marked as Data Protection Officer. If no one is marked, it goes to the Account Owner, so no request is missed. The email states what the respondent asked for, and for correction requests it lists the exact changes they submitted.

​

The DPO flag can be assigned to several team members, both Admins and Users. Analysts cannot be DPOs because their access is view-only. Learn how to assign the Data Protection Officer role

​

The Privacy requests page

Go to Settings and open Privacy requests. The page has three tabs: Requests, History and Settings.

Admins and Users can view and act on requests. Analysts cannot access this page.

​

The Requests tab

Lists every request that still needs an answer. The counter next to the tab name shows how many are open, and turns red when any are overdue. You can search by contact email and filter by type, status, or Overdue only.

  • Contact: The respondent's email address. A note icon appears when your team has added a note.

  • Type: Access, Edit, Deletion or Unspecified.

  • Source: Where the request came from (for example, Email survey), with the region and country it was submitted from.

  • Status: Open, Removal scheduled, In progress or Needs attention. If automatic handling applies, the row also shows when Retently will act.

  • Deadline: Time left to respond. Shows Overdue in red once it passes, and Extended if you extended it.

  • Received: When the request arrived.

Unspecified requests come from older in-app survey widgets that ask for "access, edit or removal" without letting the person choose. Retently does not guess what they meant. Reach out to the person to confirm, then use the matching action.

​

The deadline

Each request gets a 30-day deadline from the moment it arrives. GDPR Article 12(3) requires you to respond without undue delay and at the latest within one month.

​

For complex or numerous requests, choose Extend deadline from the row's menu. This moves the deadline two months beyond the original date, and asks you to record why. The regulation only allows the extension if you tell the person, with the reason, within the first month.

​

Handling a request

Each row has its main action as a button, and more options in the ⋯ menu.

​

Access requests: Export data. Retently gathers the personal data it holds about the contact (contact details and attributes, the surveys sent to them, and their answers and scores) into a JSON file and emails it to you. You can also find it on the Import/Export history page. Internal notes are not included. Send the file to the person, then choose Mark as completed from the row's menu. The request stays open until you do.

​​

Correction requests: Review correction. Opens a before-and-after view of each field the respondent changed. Choose Apply correction to save those values to the contact. Only the fields they edited change. Their email address, tags, custom properties and responses are left untouched, and you can still edit the contact yourself afterwards.

​

Deletion requests: Remove contact. The removal does not happen right away: the request moves to Removal scheduled and a Cancel removal button stays available for 24 hours, in case you or the respondent change your mind. When the 24 hours pass, Retently adds the email address to your suppression list and removes the contact from your account. Suppression means the address cannot be surveyed again or brought back by a CSV import or an integration sync.

​

Unspecified requests offer both Export data and Remove contact, so you can act once you know what the person wants.

​

Also in the ⋯ menu:

  • Notes: private notes for your team, visible only to people with access to this page.

  • Extend deadline: see above.

  • Reject request: closes the request without acting on the data. Choose an outcome: No matching contact, Duplicate request, Outside the request scope, Contact could not be verified or Withdrawn by the contact. If you decline a request (for example, under an Article 17(3) exception), you still need to tell the person within one month, explain why, and mention their right to complain to a supervisory authority.

  • Mark as completed: records that you fulfilled the request yourself, and moves it to History.

​

To act on several requests at once, select them with the checkboxes. Bulk Export data and Remove contact work when all selected requests are the same type and still open.

​

If an export, removal or correction fails, the request shows Needs attention, your DPOs get an alert email, and a Retry button appears on the row.

​

The History tab

Every concluded request, with when it was received, the outcome and when it was resolved. Outcomes include Data exported, Completed by you, Contact updated, Contact removed, Withdrawn and the rejection reasons. History is kept as your record of how each request was handled.

​

For removed contacts, History shows a masked address (for example, c***@company.com), so you can still see and search which company a removal came from without keeping a readable list of the people removed.

​

Letting Retently handle requests automatically

By default, you or your team handle every request. On the Settings tab, you can instead let Retently answer them for you. There are three separate switches:

  • Send data exports automatically: Retently emails the person a download link to their data, at the address the survey was sent to.

  • Remove contacts automatically: Retently removes and suppresses the contact, exactly as the manual action does.

  • Apply corrections automatically: Retently saves the changes the person submitted, exactly as the manual action does.

​

Turning a switch on opens a short authorization that you confirm with a checkbox. Each switch is authorized on its own, so enabling exports does not enable removals or corrections. You can turn any of them off at any time.

​

How automatic handling works:

  1. Retently waits 7 days before acting. Until then, the request sits in your Requests tab marked with the date Retently will handle it, so you can take it over at any point.

  2. Removals keep their 24-hour window. After the 7 days, a removal is scheduled like a manual one, and Cancel removal is still available for 24 hours.

  3. Only verified requests qualify. Requests submitted from the link in the person's own survey email are verified. Requests added manually or through the API are never handled automatically.

  4. Unspecified requests always stay with you.

  5. It applies to requests that arrive after you turn it on. Requests already in the queue stay with you.

​

If you sync contacts from another system (a CRM or other integration), that system stays the source of truth, and a later sync can overwrite a correction applied in Retently. Apply the correction there, too.

​

Only Admins and the Account Owner can change these switches. Other team members see their current state. You remain the data controller throughout, and Retently acts only on your instruction.

​

Reply-to address

Also on the Settings tab. This is the address set as Reply-To on the emails Retently sends to your contacts about their data, and it is shown in the message. If you leave it empty, replies go wherever replies to your survey emails go, which may not be a mailbox your privacy team watches.

​

Customize or remove the data request pages

All respondent-facing text can be reworded or translated in your survey template. Open the campaign's template, go to the Unsubscribe section in the template editor, and find the Data requests subsection. It contains four pages: Data request page, Access confirmation, Correction confirmation and Deletion confirmation. Click any text to edit it, then save the template. The pages use the template's branding automatically.

The data request link sits on the Unsubscribe page, so it depends on the unsubscribe link being present in the survey. The link can also be removed from the Unsubscribe page entirely. In either case, you remain responsible for giving respondents another way to exercise these rights, such as a contact address in your privacy policy.

​

​

Related reading

​

This article explains how Retently's features map onto common GDPR obligations. It is not legal advice. For how the regulation applies to your business, consult your own counsel or Data Protection Officer.

Did this answer your question?