Data Subject Requests

Last updated: August 8, 2026

This page describes the process Assenture follows when an individual asks to access, correct, delete, port or restrict the personal data we hold about them. It applies to requests under the UK and EU GDPR, the CCPA/CPRA, Singapore's PDPA and comparable laws, and to consumers whose financial account data reached us through our bank data aggregation partner. Read it with our Privacy Policy and Data Retention and Disposal Policy.

1. Rights we honour

  • Access. A copy of the personal data we hold about you and the purposes of processing.
  • Correction. Rectification of inaccurate or incomplete data.
  • Deletion. Erasure, subject only to data we must retain by law.
  • Portability. A machine-readable export (JSON or CSV) of data you provided.
  • Restriction and objection. Pausing or objecting to a particular processing activity.
  • Withdrawal of consent. Including disconnecting a linked financial account at any time.
  • No discrimination. Exercising a right never degrades your service or pricing.

2. Controller or processor

Where your data was entered into Assenture by your employer or another organisation, that organisation is the controller and we act on their instructions. We will acknowledge your request, forward it to the controller within 5 business days, tell you we have done so, and assist them in fulfilling it. Where Assenture is the controller (our own account, billing and website data), we handle the request directly.

3. How to submit a request

  • Email privacy@assenture.app with the subject line "Data Subject Request".
  • Signed-in users can also self-serve: export or delete workspace data from Settings, and disconnect a linked bank account from the banking screen at any time.
  • An authorised agent may act for you with written authorisation; we will still verify your identity.

Please include the right you are exercising, the email address or account associated with the data, and any detail that helps us locate it.

4. Identity verification

We verify the requester before disclosing or deleting anything, proportionate to the sensitivity of the request. Ordinarily we confirm control of the account email and, for signed-in users, require a re-authentication or second-factor challenge. For requests involving financial account data we require an elevated (multi-factor) session. We do not ask for government identity documents unless no other method is available, and we delete any verification material as soon as the request is closed. We will not act on a request we cannot verify, and we will tell you why.

5. Timelines

  • Acknowledgement within 5 business days.
  • Substantive response within 30 calendar days (CCPA: 45 days), extendable once by a further 60 days for complex requests, with reasons given before the original deadline expires.
  • Deletion executed within 30 days of verification; backups expire on a rolling 35-day cycle.
  • Requests are handled free of charge unless manifestly unfounded or excessive, in which case we explain any fee before proceeding.

6. What we do internally

  1. Intake. The request is logged in our privacy register with a unique reference, timestamp and deadline.
  2. Triage. The DPO determines whether Assenture is controller or processor and which systems are in scope.
  3. Verify. Identity is confirmed as described above.
  4. Locate. Data is retrieved across the primary database, object storage, logs, support systems and subprocessors using our data inventory.
  5. Review. Third-party personal data and legally exempt records are redacted or excluded; exclusions are documented.
  6. Fulfil. The export, correction or deletion is executed and propagated to subprocessors.
  7. Respond. We reply over a secure channel and confirm precisely what was provided or removed.
  8. Record. The request, verification method, actions and evidence are retained for 24 months as proof of compliance, then disposed of.

7. Limits

We may decline or partially fulfil a request where retention is required by law (for example tax and accounting records), where fulfilment would infringe another person's rights, or where the request is manifestly unfounded. We always explain the reason and your right to complain to a supervisory authority.

8. Escalation

If you are dissatisfied, reply to the response and it will be escalated to our Data Protection Officer for review within 10 business days. You may also lodge a complaint with your local data protection authority.

9. Contact

Data Protection Officer: privacy@assenture.app.