DATA REQUESTS

Exercise privacy rights or request a customer-data export or deletion.

RYTHM provides an electronic request channel for access, correction, deletion, restriction, objection, and portability requests. We normally respond without undue delay and within the timeframe required by applicable data-protection law.

HOW TO REQUEST

Send the minimum information needed to identify the request.

  • Email privacy@rythm-os.com from the email address associated with your RYTHM account where possible.
  • State the organization/workspace name and the right you want to exercise: access, correction, deletion, restriction, objection, or portability.
  • For customer-controller requests, identify whether you are the organization owner/authorized contact or the individual data subject.
  • Do not send passwords, one-time links, API keys, payment-card data, government IDs, or unrelated confidential material in the initial request.

IDENTITY & AUTHORITY

RYTHM verifies scope before releasing or deleting data.

  • We may ask for reasonable additional information to confirm identity or authority where necessary.
  • Organization data will not be exported or deleted solely because an unverified third party asks for it.
  • If RYTHM processes the data only on behalf of a customer organization, we may redirect or coordinate the request with that controller where legally appropriate.
  • Verification information is limited to what is reasonably necessary for the request.

ACCESS & EXPORT

Validated requests can receive a structured copy of relevant personal data.

  • Access responses identify whether relevant personal data is being processed and provide a copy where required.
  • Where portability applies, RYTHM will use a commonly used machine-readable format where technically reasonable.
  • Exports are scoped to the verified requester and organization authority and are reviewed to avoid disclosing another person's protected data.
  • Security secrets, internal anti-abuse signals, privileged credentials, and data that would adversely affect the rights of others are not disclosed merely because an export is requested.

DELETION

Deletion requests are assessed against legal and operational retention duties.

  • Eligible account or workspace data is removed from active systems after scope and authority are confirmed.
  • Some records may be retained where law requires it or where necessary for security, fraud prevention, accounting, dispute handling, or legal claims.
  • Residual encrypted backup copies may remain until their normal backup lifecycle expires; they are not used for ordinary production processing.
  • Where only part of a record must be retained, RYTHM will seek to minimize or isolate the retained data where reasonably possible.

TIMING

Requests are tracked from receipt through closure.

  • GDPR requests are handled without undue delay and, in principle, within one month of receipt once the request can be properly identified.
  • Where the GDPR permits an extension for complex or numerous requests, the requester will be informed within the required initial period.
  • If a request is refused or limited, RYTHM will provide the legally required explanation and available complaint/remedy information.
  • Requests are generally handled without charge, subject to the limited exceptions allowed by applicable law for manifestly unfounded or excessive requests.

CONTROLLER CONTACT

RYTHM privacy contact.

SUBMIT A REQUEST

Use the dedicated privacy channel.

For security incidents, use security@rythm-os.com instead of the data-rights channel so incident triage can begin immediately.