Last updated: August 25, 2026
Depending on where you live, the information involved, and the role OfflistMe has in a particular processing activity, an applicable privacy law may give you rights over personal data we hold about you. This page is a practical request guide, not a determination that a specific law applies to every person or request.
The EU GDPR, UK GDPR, and California Consumer Privacy Act (CCPA) do not create one universal set of rights or exemptions. We will review the request, verify identity or authority when reasonably necessary, and explain any applicable limitation or refusal.
Ask whether we process personal data about you and, where the applicable law provides that right, request a copy and related information such as purposes, categories, sources, recipients, or retention criteria.
Submit Right of Access (SAR) →Request deletion of personal data. Erasure is subject to the applicable law, identity verification, and exceptions such as legal obligations, security, or other permitted purposes.
Submit Right to Erasure →Request correction of inaccurate personal data where the applicable law gives you that right and we hold the information in question.
Submit Right to Rectification →Where the GDPR portability conditions apply, request qualifying personal data you provided in a structured, commonly used, machine-readable format.
Submit Right to Data Portability →Ask for processing to be restricted in the situations described by the applicable law, for example while accuracy, lawfulness, or an objection is being assessed.
Submit Right to Restrict Processing →Object to processing where the applicable law provides that right, including certain processing based on legitimate interests or direct marketing.
Submit Right to Object →Where a processing activity relies on your consent, ask to withdraw that consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Submit Right to Withdraw Consent →Primary references: EUR-Lex GDPR text, ICO individual-rights guidance, and CPPA CCPA FAQs, plus the current CCPA text and regulations.
You can exercise any of the above rights by emailing us at support@offlist.me with the subject line “Data Rights Request — [type of request]”.
Please include the following in your email:
Do not include passwords, payment credentials, or unnecessary identity documents in your first email. We may request proportionate information to verify your identity or authority before disclosing or changing personal data.
| Regulation | Response Deadline |
|---|---|
| EU GDPR / UK GDPR (if applicable) | Within one calendar month; a further two months may be available for complex or numerous requests with notice |
| CCPA specified requests (if applicable) | Current CPPA Regulation §7021 covers requests to delete, correct, know, access ADMT, or appeal ADMT: confirm receipt within 10 business days and respond within 45 calendar days; one further 45-day extension may be available with notice |
| Our standard target | We aim to acknowledge requests as soon as practicable and respond within the applicable deadline; this is operational language, not a legal conclusion or guarantee |
The CCPA timing row is not a universal deadline for every privacy choice or request type; opt-out and other CCPA processes can have different rules.
If you are not satisfied with our response, or believe we are processing your data unlawfully, you have the right to lodge a complaint with your relevant data protection authority:
Requests are normally free of charge. Depending on the applicable law, a manifestly unfounded, excessive, or repetitive request may be subject to a reasonable fee or refusal, with an explanation where required.
This page provides general information about potential rights and request channels. It does not determine whether OfflistMe is subject to a particular law in a particular circumstance and is not legal advice. Laws, guidance, exemptions, and our processing context can change; the primary references above should be checked for current detail.