Skip to main content
This page explains how data subject requests (DSARs) are handled in Conversion, what you can action yourself, and how to ask Conversion to fulfill a request on your behalf.

Roles

For the personal data held in your workspace, you are the data controller and Conversion acts as a data processor on your behalf. You are responsible for receiving and responding to data subject requests, and Conversion assists you in fulfilling them. Where an individual contacts Conversion directly to exercise their rights over personal data held in your workspace, Conversion will refer the request to you as the relevant controller.

Supported requests

Conversion supports every core data subject right. Each can be actioned directly in your workspace, through the API, or by submitting a request to Conversion. Exports are delivered as CSV, a structured, commonly used, machine-readable format suitable for portability requests.

Submitting a request to Conversion

To ask Conversion to fulfill a request on your behalf, email privacy@conversion.ai. Include:
  • The type of request: access, deletion, rectification, portability, or opt-out.
  • The email address of each data subject the request applies to.
  • For rectification, the corrected values for each field.
  • Your workspace name and any other detail needed to scope the request.
Conversion confirms the scope of the request with you before acting on it. Administrators can also submit deletion requests from Settings > Data retention in the workspace. See Data retention.

Response times

These timeframes are designed to leave you sufficient time to meet your own obligations to data subjects, such as the one-month response period under Article 12 of the GDPR and the 45-day period under the CCPA.

Connected systems

Requests fulfilled in Conversion apply only to the data held in Conversion. Where the same personal data is held in a connected CRM such as Salesforce, review your sync preferences so that deletions reach every system, and action the request in the connected system as needed.
This page is intended as general implementation guidance and is not legal advice. We recommend working with a qualified data protection professional to validate your compliance status.