Astra
Back to Legal Center
Platform

Data Subject Rights

How to exercise GDPR, CCPA, LGPD, and similar rights

Last updated · 2026-05-14

These terms are updated periodically; we email all users before material changes. This document is not legal advice for your specific situation — for that, consult your own counsel.

Data Subject Rights

Last updated: 2026-05-14 · These terms are reviewed by Astra periodically and effective on the Last updated date above.

This page is a practical walk-through for exercising the rights described in the Privacy Policy § 7. We use plain language here; the legal foundation is in the Privacy Policy.

1. Rights at a glance

Depending on where you live you may have rights to:

RightWhat it meansAvailable to
AccessGet a copy of your dataEU, UK, CA, BR, JP, KR (PIPA), most
RectificationCorrect inaccurate dataSame
Erasure ("right to be forgotten")Delete your account + dataEU, UK, CA (CCPA right to delete), most
PortabilityGet a machine-readable exportEU, UK, BR, CA (CPRA right to portability)
RestrictionPause processing during a disputeEU, UK
ObjectionOpt out of legitimate-interest processing or direct marketingEU, UK
Withdraw consentStop AI training, marketing, or birth-data processingUniversal
Opt-out of sale / sharingCCPA-style; we don't sell so always honouredCA, CT, CO, UT, VA, others
Limit use of sensitive PICPRA-specificCA
Non-discriminationWe won't penalise you for exercising rightsCA, EU
Lodge a complaintWith your supervisory authorityEU, UK, CA (CPPA)
Data-protection rights for the deceasedPer local lawVaries (e.g. France LIL Art. 84)

2. How to file a request

2.1 Self-service (fastest)

Most rights can be exercised directly:

  • Access / portability — Settings → Privacy → Export my data produces a ZIP within minutes.
  • Rectification — most fields editable in Settings → Profile.
  • Erasure — Settings → Account → Delete account.
  • Withdraw consent — toggles in Settings → Privacy:
    • AI training on my data
    • Marketing email
    • Birth-data processing (this also pauses chart features)
    • Analytics cookies
  • Opt-out of CCPA sale/sharing — we don't sell or share for cross-context behavioural advertising, so the opt-out is the default. If we ever change this, the option will appear here and in the footer.

2.2 Email

Email hello@astraplatform.ai with the subject:

Data rights request: [Access | Rectification | Erasure | Portability | Restriction | Objection | Withdraw consent | Opt-out | Limit sensitive PI | Complaint]

Include:

  • The email address of the account in question.
  • The right you want to exercise.
  • For erasure / restriction, the reason (we do not require a reason for valid GDPR / CCPA rights but it helps speed things up).

2.3 Postal

If you prefer postal mail:

Sunstone Venture Capital LLC dba Sunheir Culture Attn: Privacy / Data Rights Request [Sunstone Venture Capital LLC, address — fill in] United States

3. Identity verification

To protect you from impersonation, we may ask for one or more of:

  • Sign-in confirmation from the account's email
  • A code sent to the account's verified phone
  • A response to security questions
  • For high-risk requests, government-ID verification via Stripe Identity

We never share the data of one person with another person, and we will refuse a request we cannot verify.

4. Response timelines

RegimeInitial responseDecision
GDPR / UK GDPRAcknowledgement within 30 daysDecision within 30 days; extendable to 90 with notice
CCPA / CPRAAcknowledgement within 10 business daysDecision within 45 days; extendable to 90 with notice
LGPD (Brazil)Confirmation immediateUp to 15 days
PIPEDA (Canada)Within 30 daysWithin 30 days
Japan APPI / Korea PIPAPer local minimumsPer local minimums

5. Fees

We do not charge a fee for the first reasonable request in a 12-month period. Manifestly unfounded, excessive, or repetitive requests may incur a reasonable administrative fee or be refused (per GDPR Art. 12(5)).

6. If we decline a request

We may refuse on documented grounds, including:

  • Identity could not be verified.
  • The request would expose another person's data.
  • Legal retention obligations override (e.g. financial records kept for 7 years).
  • The right is not available under your jurisdiction.

We tell you the specific ground and your right to appeal or complain to your supervisory authority.

7. Lodging a complaint

You may complain to:

8. Authorised agents

You may designate an authorised agent to make a request on your behalf. We will require documentation of the agent's authorisation (signed letter, power of attorney, or a CCPA-compliant authorised- agent form) and verification of your identity, before action.

9. Deceased persons

For requests on behalf of a deceased account-holder, we follow applicable law (France LIL Art. 84, some US states' digital- fiduciary acts). Email hello@astraplatform.ai with proof of death and your authority.

10. Contact

  • Data rights: hello@astraplatform.ai
  • Postal: Sunstone Venture Capital LLC dba Sunheir Culture, [Sunstone Venture Capital LLC, address — fill in], USA

This document is reviewed by Astra periodically.

Questions about this document?

Email us — we reply within 24h (12h for Pro & creators).