Data Subject Requests
Last Updated: December 17, 2019
What is a "Contact"?
A "Contact" is anyone on a Member's Distribution List or about whom a Member has given us information. For example, if you have subscribed to one of our Members’ email marketing campaigns, you would be considered a Contact.
What are my privacy rights?
- The right of access– this is a right to ask us for a copy of the information that we, as controller, hold about you, along with certain other information. You can exercise this right using the form below.
- The right to data portability – this is a right to ask us to provide you with a copy of your information you have provided in a structured, commonly used, and machine readable form in certain circumstances. You can exercise this right using the form below.
- The right to rectification – this is a right to rectify (put another way, change or correct) any personal information that you believe we are holding about you that is inaccurate or incomplete. You can exercise this right by writing to us at firstname.lastname@example.org.
- The right to erasure – this is the right to have your personal information deleted if it is no longer required for the purposes for which it was collected or if other certain conditions apply (commonly called "the right to be forgotten"). You can exercise this right using the form below.
- The right to restrict processing – this is a right to request the restriction or suppression of your personal information in limited circumstances. We do not believe that this right will ordinarily apply to our processing of your personal information, however if you believe you can exercise this right, please write to us at email@example.com.
- The right to object – this is a right to object to the processing of your personal information in certain limited circumstances, such as when we are relying on 'legitimate interests' to process your personal information. If you would like to exercise this right in relation to our data analytics program, please use the form below. If you would like to exercise this right in any other circumstances, you can write to us at firstname.lastname@example.org setting out the grounds for your objection.
- The right to make a complaint to your Data Protection Authority – this is a right to complain to a data protection authority about our use of your Personal Information. For more information, please contact your local data protection authority. Contact details for data protection authorities in the EEA are available here.
When can I exercise my privacy rights?
Certain data protection laws (like those in Europe) make the distinction between those who act as 'controllers' and those who act as 'processors' of personal information. Put simply, a controller is the organization who determines how and why your personal information are to be used for certain purposes. A processor is an organization who acts as a service provider and only processes personal information on behalf of the controller under their instruction.
The reason we point this out is because for many of our services, our Members are the controller and we are simply acting as their processor. For instance, if you signed up to receive a newsletter from one of our Members, that Member may ask us to help them send out their newsletters by using our services. In that case, the Member is the controller of your personal information and Mailchimp is merely a processor.
Under the law, it is up to the controller to make sure you can exercise your rights over your personal information. If you have questions about how your personal information is handled by our Members (the business or organization contacting you through the Service), you will need to review their privacy notices and, if necessary, contact them directly.
Submit your request:
Please select the right(s) you wish to exercise:
Access/Portability Request - Please provide me with a copy of my personal information. If you select this option, we will provide you with a copy of the personal information we hold about you as a controller, to the extent required by law.
Global Erasure Request - Please Forward My Deletion Request to the Mailchimp customer who is the Data Controller. If you choose this option, we will notify the relevant Mailchimp customers that you would like your personal information deleted from their Mailchimp account. The notice will include instructions the Member can follow for permanently deleting your personal information from their Mailchimp account. We suggest that you separately follow up with the relevant Mailchimp customers directly to request deletion of the personal information they process about you through their Mailchimp account. We will also provide you with a copy of the contact information for each of the Mailchimp customers where your personal information is found.
Mailchimp Erasure Request - Please Delete My Personal Information. If you select this option we will delete any Personal Information Mailchimp processes about you as a controller at the time of your request and to the extent required by law.