Your Privacy Rights
Understanding and exercising your rights under GDPR
At Spread Suite, we respect your privacy and are committed to protecting your personal data. The General Data Protection Regulation (GDPR) gives you specific rights regarding your personal information. This page explains those rights and how you can exercise them.
Your Rights Under GDPR
Right to Access
You have the right to request a copy of all personal data we hold about you. This includes your profile information, booking history, payment records, and any other data associated with your account.
Right to Rectification
If any of your personal data is inaccurate or incomplete, you have the right to have it corrected. You can update most information directly in your account settings.
Right to Erasure
Also known as the "right to be forgotten," you can request deletion of your personal data. We will remove your data unless we have a legal obligation to retain it.
Right to Restriction
You can request that we limit how we process your data in certain circumstances, such as while we verify the accuracy of your data or assess a deletion request.
Right to Portability
You have the right to receive your personal data in a structured, commonly used format (JSON) that you can transfer to another service.
Right to Object
You can object to processing of your personal data for direct marketing purposes. You can also object to processing based on legitimate interests in certain circumstances.
Right to Withdraw Consent
Where we process your data based on consent, you have the right to withdraw that consent at any time. This won't affect the lawfulness of processing before withdrawal.
Right to Complain
If you believe we haven't handled your data properly, you have the right to lodge a complaint with your local data protection authority.
How to Exercise Your Rights
What to Expect
Verification
We may need to verify your identity to protect your data. This usually involves confirming your email address or, for sensitive requests, additional verification.
Processing
We will process your request and respond within 30 days. For complex requests, we may extend this by an additional 60 days with notice.
Response
You'll receive a response confirming the action taken. For data exports, you'll receive your data in JSON format. For deletions, you'll receive confirmation once complete.
π Important Notes
- Exercising your rights is free of charge in most cases
- We may retain certain data for legal compliance (e.g., financial records for tax purposes)
- Deletion requests for affiliate accounts require additional review due to business relationships
- Admin accounts cannot be deleted through self-service for security reasons
What Data Do We Hold?
Depending on how you use our service, we may hold the following categories of personal data:
Account Information
Name, email, phone number, timezone, profile photo
Booking Data
Appointment history, reading preferences, questions submitted
Payment Information
Transaction history, refunds (card details stored securely by Stripe)
Usage Data
Login history, session data, consent preferences
Communications
Support requests, feedback, reviews
For complete details on how we collect, use, and protect your data, please see our Privacy Policy.
Questions or Concerns?
If you have any questions about your privacy rights or how we handle your data, please don't hesitate to contact us:
Related: Privacy Policy Β· Cookie Policy Β· Terms of Service