Skip to main content

How can respondents request to access, edit or delete their personal data processed by Retently, or opt out of surveys

Written by Alex Bitca

Retently is a Processor, not the Controller. For the contact data you import into Retently, we only process what you send us and can only surface the data we hold. If you collect or process the same person’s data anywhere outside Retently, you are solely responsible for including it in your response to them.

Survey respondents can ask to see, correct or delete the personal data you process about them, and can opt out of future surveys, directly from your email surveys. This article explains what they see, what Retently does automatically, and what you need to do to close each request.

How a respondent submits a request

Every email survey carries an Unsubscribe link in its footer.

Clicking it opens the Unsubscribe page, where they can opt out of future surveys and, optionally, tell you why.

Underneath the unsubscribe options there is a second link, Request your data access, edit or removal.

That link opens the Data request page, a separate page titled Manage your personal data with two choices:

  • Show me the data you have about me, an access request.

  • Delete my personal data, an erasure request, shown behind a confirmation dialog.

  • Back to unsubscribe options, which returns them to the Unsubscribe page. This link can be reworded or translated but never removed.

Once they pick an option, the page replaces itself with a confirmation message and an email notification goes out to your team.

A respondent who has already unsubscribed can still open the Data request page and submit a request. Opting out and exercising data rights are separate things.

What Retently does automatically

The two options behave differently, and the difference matters.

Show me the data you have about me

  • A GDPR data access request via Retently email is sent to your Data Protection Officers.

  • The respondent’s subscription is left untouched. They stay subscribed to your surveys.

  • The confirmation page they see carries an Unsubscribe link, so they can opt out in one click if they also want that. You can remove that link from the template editor.

  • Nothing is exported, sent or deleted automatically. Answering the request is your job.

Delete my personal data

  • The respondent is unsubscribed from your surveys immediately, before anyone on your team is notified.

  • A GDPR data deletion request via Retently email is sent to your Data Protection Officers, and it states that the respondent has also been unsubscribed.

  • Because the respondent unsubscribed themselves, you cannot resubscribe them from the dashboard. Re-adding them requires their fresh written consent and the steps in How to resubscribe contacts.

  • No data is deleted automatically. Retently notifies you; you decide what to remove and remove it. See Handle a deletion request below.

Each request type is tracked separately, so a respondent who first asks for access and later asks for deletion generates two notifications.

Who gets notified

Notifications go to every user in your account flagged as Data Protection Officer. If no DPO is assigned, the notification falls back to the Account Owner, so a request is never lost.

Admins and regular Users who are not flagged as DPO do not receive these emails.

You can assign the DPO flag to as many team members as you need, including Admins and Users. Analysts cannot be DPOs, since the role is view only.

Handle an access request

Under GDPR Article 15, the person is entitled to a copy of their personal data plus context about how you use it. In practice, reply to them at the address the survey was sent to and cover:

  1. What you hold. In Retently this is typically first and last name, email address, company, any custom properties and tags you imported, their survey responses and comments, and the record of surveys sent to them.

  2. Why you process it. For example, to measure customer satisfaction and follow up on feedback.

  3. Who else sees it. Any integrations or systems you sync Retently data into.

  4. How long you keep it, or the criteria you use to decide.

  5. Their other rights, including rectification, erasure and the right to lodge a complaint with a supervisory authority.

To pull the data itself, use the export tools.

Their contact record: go to the Contacts page, search their name or email address, then click Export as CSV and choose Export filtered records.

Their responses: go to the Feedback page, search the same name or email address, click Export as CSV and choose Legacy export (single file). That option respects the filter you applied, so you get only their responses. Export per campaign ignores the search and returns a whole campaign.

Their survey history: the Outbox page lists every survey sent to them, with delivery status. Search for their email address, then use Export as CSV and Export filtered records.

Answer within one month. GDPR Article 12(3) requires you to respond without undue delay and at the latest within one month of the request. You may extend that by two further months for complex or numerous requests, but only if you tell the person about the extension, and why, inside the first month.

Handle an edit request

If they ask you to correct their data, open their profile by clicking their name anywhere in the app and choose Edit from the Actions menu.

You will get a form with their current data, which you can change as requested.

Handle a deletion request

Retently unsubscribes the respondent for you, but it does not delete anything. A contact, their responses and their outbox records are three separate objects, and deleting the contact does not delete the other two. To honour an erasure request in full, remove all three, then close the loop with the person.

Step 1: Delete the contact

On the Contacts page, find them by name or email address and choose Delete from the Actions menu. This permanently removes their personal data from your Retently account.

Step 2: Delete their responses

On the Feedback page, search for their email address, select their responses, then choose Delete from the Actions menu in the top right.

Step 3: Delete their outbox records

On the Outbox page, do the same: search for their email address, select the records, and choose Delete survey.

Step 4: Add their email to the Suppression List

Go to Settings and open the Suppression list page, then add their email address on the Emails tab. Without this, nothing stops the same address from being re-imported and surveyed again later.

Suppression does not reintroduce personal data. Retently stores suppressed addresses as one way cryptographic hashes, not readable text, so nobody, including Retently, can read the original address back out. Incoming addresses are still compared against those hashes and blocked automatically.

Step 5: Confirm back to the person

Tell them the deletion is done, within the same one month window as an access request. Two reasons this matters:

  • Under Article 12(3) you must inform the data subject of the action taken on their request. Silence is not a valid response, even when you complied in full.

  • Under Article 19 you must also pass the erasure on to anyone you shared their data with, unless that is impossible or takes disproportionate effort. If you sync Retently data into a CRM, a data warehouse or a support tool, delete it there too.

If you decide not to act on a request, for example because one of the Article 17(3) exceptions applies, you still have to tell them within one month, explain why, and point them to their right to complain to a supervisory authority.

Customize or remove the data request pages

Every text a respondent sees, on the Data request page and on both confirmation pages, can be reworded or translated from the email template editor, under the Unsubscribe section. The pages inherit your template’s branding automatically.

You can also remove the data request link from your unsubscribe page entirely, from the same place. If you do, you remain responsible for giving respondents another way to exercise these rights, for example a contact address in your privacy policy.

Related reading

This article explains how Retently’s features map onto common GDPR obligations. It is not legal advice. For how the regulation applies to your business, talk to your own counsel or Data Protection Officer.

Did this answer your question?