> ## Documentation Index
> Fetch the complete documentation index at: https://docs.conversion.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Subject Requests

> How Conversion supports access, deletion, rectification, portability, and opt-out requests, and how to submit a request to Conversion.

This page explains how data subject requests (DSARs) are handled in Conversion, what you can action yourself, and how to ask Conversion to fulfill a request on your behalf.

## Roles

For the personal data held in your workspace, you are the **data controller** and Conversion acts as a **data processor** on your behalf. You are responsible for receiving and responding to data subject requests, and Conversion assists you in fulfilling them.

Where an individual contacts Conversion directly to exercise their rights over personal data held in your workspace, Conversion will refer the request to you as the relevant controller.

## Supported requests

Conversion supports every core data subject right. Each can be actioned directly in your workspace, through the API, or by submitting a request to Conversion.

| Right | In your workspace | API | Learn more |
| :- | :- | :- | :- |
| **Access** | View the [contact record](/product-docs/records/contacts/contact-record) and its [activity](/product-docs/records/contacts/activity) history. | [Get Contact](/api-reference/get-contact) | — |
| **Deletion** | Delete the contact from its record, or in bulk with a [Delete Contact](/product-docs/workflows/nodes/delete-contact) workflow node. | [Full Delete Contact](/api-reference/full-delete-contact) | [Data deletion](/product-docs/gdpr/data-deletion) |
| **Rectification** | [Edit the contact's fields](/product-docs/records/contacts/contact-record#editing-a-contact) inline on the record. | [Upsert Contact](/api-reference/upsert-contact) | — |
| **Portability** | Export the contact from the contacts table as a CSV file. | [Export Contacts](/api-reference/export-contacts), [Export Email Events](/api-reference/export-email-events), [Export Custom Events](/api-reference/export-custom-events) | [Imports and exports](/product-docs/workspace-settings/imports-and-exports/overview) |
| **Opt-out of sharing or sale** | Set a do-not-share/sell field on the contact and exclude it from ad audiences. | [Upsert Contact](/api-reference/upsert-contact) | [Do not share/sell](/product-docs/ccpa/do-not-share-sell) |

Exports are delivered as CSV, a structured, commonly used, machine-readable format suitable for portability requests.

## Submitting a request to Conversion

To ask Conversion to fulfill a request on your behalf, email [privacy@conversion.ai](mailto:privacy@conversion.ai). Include:

* The **type of request**: access, deletion, rectification, portability, or opt-out.
* The **email address** of each data subject the request applies to.
* For rectification, the **corrected values** for each field.
* Your **workspace name** and any other detail needed to scope the request.

Conversion confirms the scope of the request with you before acting on it.

Administrators can also submit deletion requests from **Settings > Data retention** in the workspace. See [Data retention](/product-docs/workspace-settings/data-retention/overview).

## Response times

| Stage | Timeframe |
| :- | :- |
| **Acknowledgement** | Within 2 business days of receipt. |
| **Fulfillment** | Within 14 calendar days of a verified request. |
| **Complex or high-volume requests** | Within 30 calendar days. Conversion will notify you if a request requires the extended timeframe. |

These timeframes are designed to leave you sufficient time to meet your own obligations to data subjects, such as the one-month response period under Article 12 of the GDPR and the 45-day period under the CCPA.

## Connected systems

Requests fulfilled in Conversion apply only to the data held in Conversion. Where the same personal data is held in a connected CRM such as Salesforce, review your [sync preferences](/product-docs/sync/salesforce/sync-preferences) so that deletions reach every system, and action the request in the connected system as needed.

<Warning>
  This page is intended as general implementation guidance and is not legal advice. We recommend working with a qualified data protection professional to validate your compliance status.
</Warning>
