privacyVersion 1SOC2GDPRCCPA
Data Subject Rights Policy
How Rex Black handles access, deletion, portability, and related rights.
Data Subject Rights Policy
1. Purpose
Defines how Rex Black receives, verifies, and responds to requests from data subjects (individuals whose personal data we process) to exercise their rights under GDPR, UK GDPR, CCPA/CPRA, and comparable laws.
2. Rights covered
| Right | GDPR | CCPA/CPRA | Rex Black action |
|---|---|---|---|
| Access / know | Art.15 | §1798.110 | Provide copy + categories of data, sources, recipients. |
| Correction | Art.16 | §1798.106 | Correct inaccuracies. |
| Deletion / erasure | Art.17 | §1798.105 | Delete, subject to legal holds and retention obligations. |
| Portability | Art.20 | §1798.130 | Export in a machine-readable format. |
| Restrict processing | Art.18 | , | Pause processing pending resolution. |
| Object | Art.21 | , | Stop processing absent overriding grounds. |
| Opt out of sale/share | , | §1798.120 | N/A (Rex Black does not sell or share personal data). |
| Limit use of sensitive PI | , | §1798.121 | Limit where requested. |
| Non-discrimination | , | §1798.125 | Do not retaliate for exercising rights. |
3. Intake channels
privacy@rexblack.com: primary intake, acknowledged within 2 business days.- A web form at
/privacy/request(tracked in the same queue). - Authorized agents may submit on behalf of a data subject with written authorization and identity verification.
4. Verification
- For clients (B2B): verified by matching the requester against the active org-user list and confirming via a sign-in challenge.
- For individuals: verified by matching known-good email and one additional attribute (most recent transaction, account identifier).
- Rex Black does not require more identity proof than necessary; we never require government ID for a standard request.
- Unverified requests are not fulfilled; the requester is asked for the minimum information to verify.
5. Timelines
| Jurisdiction | Initial acknowledgement | Final response |
|---|---|---|
| GDPR / UK GDPR | 2 business days | 30 days (extendable to 60 with notice) |
| CCPA / CPRA | 10 business days | 45 days (extendable to 90 with notice) |
| Other | 2 business days | 30 days default |
6. Processing steps
- Intake ticket created and classified.
- Verify requester.
- Determine Rex Black's role (controller vs. processor). If processor, forward to controller (the client) and assist as required by DPA.
- Discover data across Rex Black systems: DynamoDB by
orgId,userId,email; S3 by object tag; SaaS by account. - Prepare response; legal hold check; redact data about other data subjects.
- Deliver response through a secure channel.
- Record in the rights register (
registers/rights-requests.md) with date, scope, verification, and outcome.
7. Exceptions to deletion
Rex Black retains data required for:
- Legal obligation (tax / accounting / SOX / IRS: 7 years).
- Ongoing contract performance.
- Pending litigation or legal holds.
- Security investigations.
- Anonymized aggregate records.
Data subject is informed of any refusal with reasoning and how to appeal.
8. Appeals
Requesters may appeal a denial to privacy@rexblack.com. Appeals
are reviewed by the Privacy Officer with escalation to the CEO.
Responses are issued within 15 business days.
9. Children
Requests regarding data subjects under 13 (COPPA) or 16 (GDPR) are prioritized and, if the data exists, deletion is the default response.
10. Metrics
- Request volume by type and jurisdiction.
- Mean time to acknowledge and close.
- Appeals rate.
- Denials by reason.
11. Roles & responsibilities
| Role | Responsibility |
|---|---|
| Privacy Officer | Owns intake, routing, and response. |
| Engineering | Provides discovery and deletion tooling. |
| CEO | Final escalation authority on appeals. |
12. References
019-privacy-policy-internal.md010-data-retention-and-disposal-policy.md009-data-classification-and-handling-policy.md
13. Revision history
| Version | Date | Author | Approver | Change |
|---|---|---|---|---|
| 1.0 | 2026-04-17 | P.O. | CEO | Initial policy |
Approval
This policy has been reviewed and is hereby approved for the named version and effective date above.
| Approved by | Myles Bai |
| Title | Chief Executive Officer, Rex Black LLC |
| myles@rexblack.com | |
| Approval date | 2026-04-17 |
| Effective date | 2026-04-17 |
| Next review due | 2027-04-17 |
Digital signature of record: the CEO's electronic approval is captured
in the platform audit log (event kind admin.policy.approved) with
hash-chained integrity under the M-C1 control. The hash-chained audit
log entry for this document is the canonical signature of record; this
printed block exists for print/review convenience.