Exercise your privacy rights

Draft — to be reviewed by counsel

This is a working draft prepared for review by qualified counsel. It is not legal advice and is not yet binding. Items in [SQUARE BRACKETS] are placeholders to be completed by REAT Global; notes marked “Counsel:” are decisions for review. See the placeholder register.

Version 1.0-draftLast updated [LAST UPDATED DATE]Effective [EFFECTIVE DATE]Draft prepared 30 September 2026

On this page

You can ask REAT Global what personal data we hold about you, ask us to correct, export or delete it, object to how we use it, or withdraw a consent. This page explains how, how we verify requests, how long we take, and how to appeal. It supplements the Privacy notice.

1. The fastest way: self-service in Tractrix Cloud

If you have a Tractrix Cloud account, sign in and open Settings → Privacy. There you can, immediately and without contacting us:

  • download your data — a zip file of JSON and GeoJSON containing your account, memberships, consent history, API-token details (never the secrets), sign-in sessions, security-log events about you, your privacy requests, and the full content of any organisation you own;
  • correct your name, and change your e-mail address (confirmed by a link to the new address);
  • give or withdraw consents, such as marketing e-mail and cloud processing from the CAD add-ins;
  • delete your account — confirmed with your password; your account is deactivated at once and permanently purged after 30 days, and you can cancel with the link we e-mail you until then;
  • submit any other request to our privacy team, with the statutory deadline tracked automatically.

Organisation owners can also export all of an organisation's content and delete the organisation. If you are the only owner of an organisation, transfer ownership or delete the organisation before deleting your account.

2. Request types by region

Your rights depend on where you live. We honour the requests below everywhere we reasonably can, even where the law does not require it.

Table 1 Main request types and where they apply.
RequestWhat it doesMain laws
Access / right to knowConfirm whether we process your data and get a copy, with information on purposes, recipients, retention and sourcesGDPR/UK GDPR Art. 15; nFADP Art. 25; CCPA; US state laws; PIPEDA; LGPD Art. 18; POPIA s. 23; and most other laws
PortabilityReceive data you gave us in a structured, machine-readable format, or have it sent to another providerGDPR/UK GDPR Art. 20; nFADP Art. 28; CCPA; US state laws; Québec; LGPD; NDPA; Kenya DPA
CorrectionFix inaccurate or incomplete dataNearly all laws
Deletion / erasureDelete your data, subject to legal exceptions (for example tax records)Nearly all laws
RestrictionLimit processing while a dispute is resolvedGDPR/UK GDPR Art. 18; NDPA; Kenya; UAE
ObjectionObject to processing based on legitimate interests, and to direct marketing at any timeGDPR/UK GDPR Art. 21; POPIA s. 11(3); LGPD; Kenya; and others
Withdraw consentStop processing that relies on consent (for example marketing)All laws that use consent
Opt out of sale, sharing, targeted advertising or profilingWe do none of these, but you may still send an opt-out; Global Privacy Control is honoured automatically (see Your privacy choices)CCPA; US state laws; Nevada
Limit use of sensitive personal informationWe use sensitive information only as permitted without this right, but you may still askCCPA
List of third partiesNames of the specific third parties to which we disclosed your dataOregon, Delaware, Maryland, Minnesota
AppealAsk us to reconsider a refusalUS state laws (see section 6)
NominateNominate someone to exercise your rights if you die or become incapacitatedIndia DPDP Act

Requests about customer content (projects, drawings and results that an organisation stores in Tractrix Cloud) should go to that organisation, which controls it. If you send such a request to us, we will pass it on and tell you that we have done so.

3. How we verify your request

  • Signed in: requests made from Settings → Privacy are already verified by your sign-in; deletion also asks for your password.
  • By e-mail or the form below: we reply to the e-mail address on the account and ask you to confirm. For access to specific pieces of information or for deletion, we may ask for one or two further details that only the account holder is likely to know (for example the name of an organisation you belong to and roughly when you signed up). We never ask for your password.
  • No account: if you do not have an account (for example you wrote to us, or an organisation invited you), we verify with information matching our records, such as the e-mail address you used.
  • We use the information you give only for verification and to handle the request. If we cannot verify you, we will explain why and what else we need.

4. Authorised agents

Someone else may make a request for you (for example under the CCPA or the Colorado, Connecticut, Oregon, Texas, Montana, Delaware, New Jersey, Minnesota or Maryland laws) if they provide your signed permission or a valid power of attorney. Unless a power of attorney is provided, we may ask you to verify your identity directly with us and to confirm that you gave the agent permission. Parents and guardians may act for a minor, and legal representatives for a person who lacks capacity, with appropriate evidence. Opt-out requests sent through a universal opt-out mechanism, such as Global Privacy Control, need no further authorisation.

5. How long we take

We confirm receipt promptly and answer within the period required by your local law, counted from receipt of the request (the clock may pause while we wait for information needed to verify you, where the law allows).

Table 2 Response times.
RegionResponseExtension
EEA (GDPR)1 month+2 months for complex or numerous requests, with notice within the first month
United Kingdom (UK GDPR)1 month+2 months, as above; complaints acknowledged within 30 days
Switzerland (nFADP)30 daysMay be extended with reasons given within 30 days
California (CCPA)Acknowledge within 10 business days; respond within 45 calendar days. Opt-out requests: as soon as feasible and within 15 business days+45 days, with notice
Other US states45 days+45 days, with notice; appeals decided within 45 days (60 in Virginia and Kentucky)
Canada (PIPEDA, Québec)30 days+30 days where permitted, with notice
Brazil (LGPD)Simplified confirmation immediately; full statement within 15 days—
South Africa (POPIA)Within a reasonable time; we commit to 30 days (PAIA requests: 30 days)PAIA: +30 days, with notice
South Korea (PIPA)10 daysWith notice of the reason and a new date
New Zealand20 working daysWhere permitted, with notice
Australia, Singapore30 daysSingapore: we tell you if we need longer
India (DPDP Act)Within the period set by the DPDP Rules (for grievances, currently up to 90 days); we aim for 30 days—
All other countries30 days, unless local law sets a shorter periodWhere local law permits

Requests are free. Where the law allows, we may charge a reasonable fee or refuse requests that are manifestly unfounded, excessive or repetitive, and will explain why. We keep records of requests for three years.

6. Appeals and complaints

If we decline all or part of your request, we will explain why. US residents may appeal by replying to our decision or by writing to [PRIVACY CONTACT EMAIL] with the subject “Privacy appeal” within 60 days of our decision. A different member of staff reviews the appeal and we tell you the outcome and our reasons within 45 days (60 days in Virginia and Kentucky). If the appeal is denied, you may contact your state Attorney General; we will give you the contact details.

Everywhere, you may complain to us first, and you may complain to a data protection authority at any time. The authorities for each region are listed in the regional supplements.

7. Request form

This form does not send anything by itself: it prepares an e-mail to [PRIVACY CONTACT EMAIL] in your e-mail program, which you then send. Nothing you type is stored on this website. Alternatively, write to us directly or by post at [REGISTERED ADDRESS].

What would you like us to do?

8. What happens next

  1. We acknowledge your request and, if needed, ask you to verify your identity.
  2. We search the systems that hold personal data (the Tractrix Cloud database, backups within their retention cycle, support and e-mail records, and our providers' systems).
  3. We send you our response securely, with the data in a commonly used electronic format for access and portability requests.
  4. For deletion, we delete the data from live systems and tell our sub-processors to do the same; backups expire within their normal cycle. We tell you if we must keep anything and why (for example invoices required by tax law).