← All documents

Your Rights

How to access, correct, export or delete your data · version 0.9, 27 August 2026

Access, rectification, erasure, restriction, portability, objection and withdrawal

ControllerMORU-TECH Ltd., UIC 208895389
ProductMoru: web application/PWA and desktop widget
Version and date0.9 / 27 August 2026
StatusInternal procedure with ready-to-use text — working draft

Legal framework: Regulation (EU) 2016/679 (GDPR), the Bulgarian Personal Data Protection Act, applicable rules on electronic communications, and the national implementing legislation.

1. Channels and responsibilities

RoleResponsibilityAssigned person
Process ownerReceives, records, monitors the deadline and coordinates the response.[To be assigned]
DeputyTakes over the process in the owner’s absence.[To be assigned]
Technical ownerSearches/exports/rectifies/deletes first-party data and logs.[To be assigned]
Vendor ownerSends and tracks requests to PostHog/Google/Meta and other providers.[To be assigned]
Legal/privacyAssesses restrictions, objections, identity verification and refusals.[To be assigned]

Main public channel: [email protected]. Requests may also arrive through the application, [email protected], by post or another clear channel. Any employee receiving a request forwards it on the same working day.

2. Deadlines

StageDeadline
Registration and acknowledgementWithin 2 working days.
Completion/reasoned responseWithout undue delay and generally within 1 month of receipt.
ExtensionUp to 2 additional months for complexity or multiple requests; notify within the first month and explain the reasons.
Request for additional identificationAs early as possible; the deadline is managed in accordance with the GDPR and documented.
Immediate actionWithdrawal of consent, stopping marketing and blocking new health measurements are implemented without undue delay.

3. Request register

FieldContent
Request IDUnique number
Date/channelReceipt date and source
Person/accountEmail and UUID after verification
Right/scopeAccess, deletion, rectification, export, etc.
IdentificationMethod and outcome; no unnecessary ID copies
Systems/providersWhere searches/actions were performed
Due dateOne month and any extension
DecisionCompleted/partly completed/refused with grounds
EvidenceExport hash, deletion logs, vendor confirmations, sent response

4. Identity verification

A request made by a logged-in user is treated as reliable if the session is secure and the action is re-confirmed.

For an email request, send a confirmation link or one-time code to the registered address.

A copy of an identity document is requested only where there is justified doubt and no less intrusive method is available; unnecessary fields are redacted and the copy is deleted after verification.

No third-party data are disclosed. Where a representative acts, verify both identity and authority to represent.

5. Process by right

RightAction
Information/access (Arts. 13–15)Confirm whether data are processed; provide categories, purposes, legal bases, recipients, retention, sources, rights, automated logic; provide a copy of personal data.
Rectification (Art. 16)Correct name/profile/settings; change email after re-verification; correct or delete inaccurate self-assessment without altering audit facts.
Erasure (Art. 17)Cascade delete first-party data, GoTrue account, local buffers and vendor data; document exceptions and backup expiry.
Restriction (Art. 18)Mark record restricted; block use and access except storage/legal claims; notify before lifting restriction.
Portability (Art. 20)CSV/JSON for provided and observed data processed automatically on contract/consent; human-readable README.
Objection (Art. 21)Assess processing based on legitimate interests; stop direct marketing immediately.
Withdrawal of consentStop health/analytics/marketing processing for the relevant category; evidence record remains; delete on request.
Automated assessment (Art. 22/transparency)Explain input categories, rules-v1/version, limitations and result; allow human review of a complaint. The current score has no legal or similarly significant effects.

6. Manual export until a self-service function is built

The technical owner extracts data only by UUID/sub from the verified account mapping.

Export includes profile, consent history, onboarding, trainings, measurements, scores, surveys, calibration, preferences, feedback and relevant audit records.

The file is created in CSV/JSON with a human-readable index; trade secrets, data of other persons and security secrets are excluded.

The archive is encrypted; the key is sent through a separate channel. The link expires within 7 days.

Temporary export files are deleted within 7 days after delivery.

The action is recorded in the DSAR register with a hash/identifier without keeping a full duplicate of the export.

7. Deletion and restrictions

Deletion may exclude minimal records necessary for a legal obligation, proof of consent, fulfilment of the request or defence of legal claims. In that case, the data are restricted and minimised, and the specific legal basis and period are recorded. Data in backups expire in the 14-day cycle and are not actively used.

8. Providers

PostHog: delete/reset person profile and related events by distinct_id/UUID where applicable.

Google/Meta: use available controller/processor tools for applicable requests; marketing consent is withdrawn immediately.

Cloudflare/Google Workspace: forward the request only if the provider holds data on behalf of Moru and this is necessary.

Every vendor response is recorded in the DSAR register.

9. Grounds for refusal or fee

A refusal or reasonable fee is permitted only where a request is manifestly unfounded or excessive, in particular because of repetitive character, and only after a documented assessment. The controller bears the burden of demonstrating this. The response states the grounds and the right to complain.

10. Ready-to-use text

Acknowledgement of receiptWe have received your personal data request under reference number [ID]. We will respond without undue delay and generally by [date]. If we need additional information to verify your identity or clarify the scope, we will contact you.
Extension noticeBecause of [specific complexity/number of systems], we need to extend the period by [up to two] months. We expect to complete the request by [date]. You may lodge a complaint with the Bulgarian Commission for Personal Data Protection or another competent supervisory authority.
Deletion confirmationWe have deleted the data covered by your request from active systems and sent the applicable requests to our providers. The data will expire from rotating backups within 14 days. We retain only minimal records necessary to prove completion/comply with a legal obligation until [period and legal basis].

11. Review and accountability

The Process owner conducts a monthly review of open requests and a quarterly test of export/delete processes. Management receives reports on number, type, average time, overdue cases, refusals, recurring issues and required product changes.

ApprovalDetails
ManagerName: ____________________Signature: __________________Date: ___________________

Sources and legal basis

Regulation (EU) 2016/679, in particular Articles 5, 6, 7, 9, 12–22, 24–25, 28, 30, 32–36 and 44–49.

EDPB Guidelines 01/2022 on data subject rights — Right of access.