Exercise your privacy rights
This is a working draft prepared for review by qualified counsel. It is not legal advice and is not yet binding. Items in [SQUARE BRACKETS] are placeholders to be completed by REAT Global; notes marked “Counsel:” are decisions for review. See the placeholder register.
On this page
You can ask REAT Global what personal data we hold about you, ask us to correct, export or delete it, object to how we use it, or withdraw a consent. This page explains how, how we verify requests, how long we take, and how to appeal. It supplements the Privacy notice.
1. The fastest way: self-service in Tractrix Cloud
If you have a Tractrix Cloud account, sign in and open Settings → Privacy. There you can, immediately and without contacting us:
- download your data — a zip file of JSON and GeoJSON containing your account, memberships, consent history, API-token details (never the secrets), sign-in sessions, security-log events about you, your privacy requests, and the full content of any organisation you own;
- correct your name, and change your e-mail address (confirmed by a link to the new address);
- give or withdraw consents, such as marketing e-mail and cloud processing from the CAD add-ins;
- delete your account — confirmed with your password; your account is deactivated at once and permanently purged after 30 days, and you can cancel with the link we e-mail you until then;
- submit any other request to our privacy team, with the statutory deadline tracked automatically.
Organisation owners can also export all of an organisation's content and delete the organisation. If you are the only owner of an organisation, transfer ownership or delete the organisation before deleting your account.
2. Request types by region
Your rights depend on where you live. We honour the requests below everywhere we reasonably can, even where the law does not require it.
| Request | What it does | Main laws |
|---|---|---|
| Access / right to know | Confirm whether we process your data and get a copy, with information on purposes, recipients, retention and sources | GDPR/UK GDPR Art. 15; nFADP Art. 25; CCPA; US state laws; PIPEDA; LGPD Art. 18; POPIA s. 23; and most other laws |
| Portability | Receive data you gave us in a structured, machine-readable format, or have it sent to another provider | GDPR/UK GDPR Art. 20; nFADP Art. 28; CCPA; US state laws; Québec; LGPD; NDPA; Kenya DPA |
| Correction | Fix inaccurate or incomplete data | Nearly all laws |
| Deletion / erasure | Delete your data, subject to legal exceptions (for example tax records) | Nearly all laws |
| Restriction | Limit processing while a dispute is resolved | GDPR/UK GDPR Art. 18; NDPA; Kenya; UAE |
| Objection | Object to processing based on legitimate interests, and to direct marketing at any time | GDPR/UK GDPR Art. 21; POPIA s. 11(3); LGPD; Kenya; and others |
| Withdraw consent | Stop processing that relies on consent (for example marketing) | All laws that use consent |
| Opt out of sale, sharing, targeted advertising or profiling | We do none of these, but you may still send an opt-out; Global Privacy Control is honoured automatically (see Your privacy choices) | CCPA; US state laws; Nevada |
| Limit use of sensitive personal information | We use sensitive information only as permitted without this right, but you may still ask | CCPA |
| List of third parties | Names of the specific third parties to which we disclosed your data | Oregon, Delaware, Maryland, Minnesota |
| Appeal | Ask us to reconsider a refusal | US state laws (see section 6) |
| Nominate | Nominate someone to exercise your rights if you die or become incapacitated | India DPDP Act |
Requests about customer content (projects, drawings and results that an organisation stores in Tractrix Cloud) should go to that organisation, which controls it. If you send such a request to us, we will pass it on and tell you that we have done so.
3. How we verify your request
- Signed in: requests made from Settings → Privacy are already verified by your sign-in; deletion also asks for your password.
- By e-mail or the form below: we reply to the e-mail address on the account and ask you to confirm. For access to specific pieces of information or for deletion, we may ask for one or two further details that only the account holder is likely to know (for example the name of an organisation you belong to and roughly when you signed up). We never ask for your password.
- No account: if you do not have an account (for example you wrote to us, or an organisation invited you), we verify with information matching our records, such as the e-mail address you used.
- We use the information you give only for verification and to handle the request. If we cannot verify you, we will explain why and what else we need.
4. Authorised agents
Someone else may make a request for you (for example under the CCPA or the Colorado, Connecticut, Oregon, Texas, Montana, Delaware, New Jersey, Minnesota or Maryland laws) if they provide your signed permission or a valid power of attorney. Unless a power of attorney is provided, we may ask you to verify your identity directly with us and to confirm that you gave the agent permission. Parents and guardians may act for a minor, and legal representatives for a person who lacks capacity, with appropriate evidence. Opt-out requests sent through a universal opt-out mechanism, such as Global Privacy Control, need no further authorisation.
5. How long we take
We confirm receipt promptly and answer within the period required by your local law, counted from receipt of the request (the clock may pause while we wait for information needed to verify you, where the law allows).
| Region | Response | Extension |
|---|---|---|
| EEA (GDPR) | 1 month | +2 months for complex or numerous requests, with notice within the first month |
| United Kingdom (UK GDPR) | 1 month | +2 months, as above; complaints acknowledged within 30 days |
| Switzerland (nFADP) | 30 days | May be extended with reasons given within 30 days |
| California (CCPA) | Acknowledge within 10 business days; respond within 45 calendar days. Opt-out requests: as soon as feasible and within 15 business days | +45 days, with notice |
| Other US states | 45 days | +45 days, with notice; appeals decided within 45 days (60 in Virginia and Kentucky) |
| Canada (PIPEDA, Québec) | 30 days | +30 days where permitted, with notice |
| Brazil (LGPD) | Simplified confirmation immediately; full statement within 15 days | — |
| South Africa (POPIA) | Within a reasonable time; we commit to 30 days (PAIA requests: 30 days) | PAIA: +30 days, with notice |
| South Korea (PIPA) | 10 days | With notice of the reason and a new date |
| New Zealand | 20 working days | Where permitted, with notice |
| Australia, Singapore | 30 days | Singapore: we tell you if we need longer |
| India (DPDP Act) | Within the period set by the DPDP Rules (for grievances, currently up to 90 days); we aim for 30 days | — |
| All other countries | 30 days, unless local law sets a shorter period | Where local law permits |
Requests are free. Where the law allows, we may charge a reasonable fee or refuse requests that are manifestly unfounded, excessive or repetitive, and will explain why. We keep records of requests for three years.
6. Appeals and complaints
If we decline all or part of your request, we will explain why. US residents may appeal by replying to our decision or by writing to [PRIVACY CONTACT EMAIL] with the subject “Privacy appeal” within 60 days of our decision. A different member of staff reviews the appeal and we tell you the outcome and our reasons within 45 days (60 days in Virginia and Kentucky). If the appeal is denied, you may contact your state Attorney General; we will give you the contact details.
Everywhere, you may complain to us first, and you may complain to a data protection authority at any time. The authorities for each region are listed in the regional supplements.
7. Request form
This form does not send anything by itself: it prepares an e-mail to [PRIVACY CONTACT EMAIL] in your e-mail program, which you then send. Nothing you type is stored on this website. Alternatively, write to us directly or by post at [REGISTERED ADDRESS].
8. What happens next
- We acknowledge your request and, if needed, ask you to verify your identity.
- We search the systems that hold personal data (the Tractrix Cloud database, backups within their retention cycle, support and e-mail records, and our providers' systems).
- We send you our response securely, with the data in a commonly used electronic format for access and portability requests.
- For deletion, we delete the data from live systems and tell our sub-processors to do the same; backups expire within their normal cycle. We tell you if we must keep anything and why (for example invoices required by tax law).