You have the right to ask ManySignal to delete your personal data. This page explains how to make that request, how we verify it, how long we take, and what happens after we complete it. We do not make this process unnecessarily hard.
Your right to erasure
Under the EU General Data Protection Regulation (Article 17), the UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA), you may have the right to request that ManySignal delete the personal data we hold about you. This right applies to your personal data as a visitor to our website, a subscriber, a trial user, or a contact in our marketing system.
This right is sometimes called the "right to be forgotten" (GDPR) or the "right to delete" (CCPA). It is not absolute: we may be required to retain certain data for legal, contractual, or security reasons, and we will explain any applicable exceptions in our response to your request.
Note: if you are an employee or contractor of a ManySignal customer, your organisation controls the personal data that is processed as part of its use of the ManySignal platform (Customer Data). Data removal requests for Customer Data should be directed to the organisation's privacy or security team. ManySignal acts as a data processor in that context and will assist your organisation upon their instruction.
What data you can request removal of
You may request removal of any personal data that ManySignal holds about you as a data subject, including: account information (name, email, company, phone number); marketing contact records in ManySignal's CRM; website analytics identifiers (pseudonymous visitor IDs stored in PostHog); form submissions and demo-request records; email engagement history; and any other personal data you have provided directly to ManySignal.
We do not retain Customer Data about your employees without a subscription agreement. If you are a prospect or website visitor, your personal data is typically limited to the information above.
How to submit a request
To submit a data removal request, email [email protected] with the subject line "Data Removal Request" and include the following: (a) your full name; (b) the email address(es) associated with your ManySignal account or marketing contact record; (c) a brief description of the data you want removed; and (d) your jurisdiction (e.g., EU, UK, California), which helps us apply the correct legal framework.
Authorised agents submitting a request on your behalf under the CCPA must provide written authorisation signed by the consumer, or a power of attorney, along with verification of their own identity.
Identity verification
Before processing a data removal request, ManySignal will verify your identity to ensure we do not delete data belonging to another person. For most requests, we will send a one-time verification email to the address provided in the request. You must click the verification link within 24 hours.
For high-risk requests — such as deletion of an account with an active subscription, or requests involving sensitive data — we may require additional verification, such as answering account security questions or providing a copy of government-issued identification (processed securely and not retained beyond verification).
Timelines by jurisdiction
European Economic Area, UK, Switzerland (GDPR / UK GDPR / revFADP): We will respond to your request without undue delay and in any event within 30 calendar days of receiving your verified request. If the request is complex or numerous, we may extend this by a further 60 days and will notify you of the extension within the initial 30-day period.
California (CCPA / CPRA): We will respond within 45 calendar days. We may extend by a further 45 days where reasonably necessary, with prior notice and explanation.
All other jurisdictions: We will respond within 30 calendar days as a standard of practice, regardless of whether a specific statutory deadline applies.
Exceptions and partial deletion
ManySignal may decline to delete all or part of the data covered by your request where retention is necessary for: (a) compliance with a legal obligation (e.g., tax records, financial audit trails); (b) the establishment, exercise, or defence of legal claims; (c) the detection or prevention of security incidents, fraud, or illegal activity; or (d) other lawful and documented purposes permitted by applicable law.
Where an exception applies, ManySignal will delete or anonymise all data that is not subject to the exception and will explain in writing what data has been retained and on which legal basis.
After deletion — what happens next
Following a verified deletion request, ManySignal will: (a) delete or anonymise your personal data from production systems within 14 calendar days of completing identity verification; (b) propagate the deletion to backups within 30 days (backup data is overwritten on a rolling basis); (c) notify any sub-processors that hold copies of your data to delete those copies within 30 days; and (d) send you written confirmation that the deletion has been completed.
Following deletion, any services that depend on the deleted data — such as a ManySignal account — will be terminated. Prepaid subscription fees are non-refundable except where required by law.
Re-collection after deletion
If you continue to interact with the ManySignal website or services after a deletion request has been fulfilled, ManySignal may collect your personal data again from those future interactions, subject to the same consent and legitimate-interest bases described in the Privacy Policy. Deletion of past data does not prevent future data collection.
Appeals and supervisory authority
If you are dissatisfied with ManySignal's response to your data removal request — including a refusal to delete — you may: (a) appeal by replying to our response email and requesting a secondary review by our Data Protection Officer at [email protected]; (b) for EEA/UK/Swiss residents, lodge a complaint with the supervisory authority in your country of residence (e.g., the Irish Data Protection Commission, the UK ICO, or the Swiss Federal Data Protection and Information Commissioner); or (c) for California residents, contact the California Privacy Protection Agency (CPPA).
Questions about this document?
Contact our legal team at [email protected]. For security disclosure, use [email protected].