Skip to content
Policy center/Data rights

Phillforce legal framework

Data Rights Request Policy

How to request access, correction, or deletion of your personal information.

EffectiveSeptember 8, 2026
Last updatedSeptember 8, 2026
Sections57

Data Access, Correction, Deletion & Privacy Requests Effective Date: September 8, 2026 Last Updated: September 8, 2026

1. Our Approach to Your Data Rights

At Phillforce, we believe people should be able to understand what personal information is held about them and, where applicable, exercise meaningful control over that information. Phillforce, Inc. (“Phillforce,” “we,” “our,” or “us”) has established this Data Rights Request Policy to explain how individuals can make requests relating to their personal information and how Phillforce handles those requests. Depending on where you live and the laws that apply to your information, you may have rights relating to access, correction, deletion, portability, restriction, objection, consent, certain advertising activities, automated decision-making, and other privacy matters. Privacy laws vary by jurisdiction. Not every right described in this Policy applies to every individual in every circumstance. Where an applicable law gives you a privacy right, Phillforce intends to respect that right in accordance with the law.

2. Who We Are

Phillforce is operated by: Phillforce, Inc. 8 Wading Bird Loop Blythewood, SC 29016 United States Website: phillforce.com Privacy requests: privacy@phillforce.com Legal enquiries: legal@phillforce.com General enquiries: philip@phillforce.com

3. Scope of This Policy

This Policy applies to privacy and personal-data requests relating to information processed through Phillforce services, including, where applicable:

  • phillforce.com;
  • Phillforce Intelligence;
  • Phillforce user accounts;
  • profile information;
  • authentication information;
  • Ask Phill;
  • customer-support communications;
  • billing and transaction records;
  • diagnostic activity;
  • platform usage;
  • website interactions;
  • marketing records;
  • account settings;
  • and other Phillforce products or services governed by our Privacy Policy.

This Policy should be read together with the Phillforce Privacy Policy.

4. What Is a Data Rights Request?

A Data Rights Request is a request from an individual concerning personal information that Phillforce processes about that individual. Depending on applicable law, this may include a request to:

  • access personal information;
  • obtain a copy of personal information;
  • correct inaccurate information;
  • delete personal information;
  • restrict processing;
  • object to processing;
  • obtain portable information;
  • withdraw consent;
  • opt out of certain advertising or sharing activities;
  • exercise rights relating to automated decision-making;
  • appeal certain privacy decisions;
  • or exercise another right provided under applicable privacy law.

A person does not necessarily need to use legal terminology such as “DSAR,” “CCPA Request,” or “GDPR Request” for Phillforce to recognize a valid privacy request. If it is reasonably clear that you are asking to exercise a privacy right relating to your personal information, we will seek to treat the request appropriately.

5. Right to Access

Where applicable law provides a right of access, you may ask Phillforce whether we process personal information about you and request access to that information. Depending on the applicable law and circumstances, a response may include information such as:

  • categories of personal information;
  • specific personal information;
  • purposes of processing;
  • categories of recipients;
  • sources of information;
  • applicable retention information;
  • information about relevant privacy rights;
  • information concerning certain automated processing where required.

We may also provide a copy of personal information where required.

6. Right to Know

Certain privacy laws, including laws in some U.S. states, may provide a right to know more about how an organization collects and uses personal information. Where such a right applies, you may be entitled to information concerning matters such as:

  • categories of information collected;
  • purposes for collection and use;
  • categories of sources;
  • categories of third parties receiving information;
  • categories of information disclosed;
  • and other information required under applicable law.

Our Privacy Policy already provides substantial information about our processing practices. A Data Rights Request can be used where you are entitled to additional information concerning your own personal information.

7. Right to Correction

If personal information Phillforce maintains about you is inaccurate or materially incomplete, you may request that we correct it where applicable law provides that right. Some information may be directly editable through Phillforce account settings. For example, depending on available functionality, you may be able to update:

  • your name;
  • profile information;
  • job title;
  • organization;
  • timezone;
  • certain preferences.

Changes to sensitive account information, such as an email address or authentication method, may require additional verification.

8. Right to Deletion

Where applicable law provides a right to deletion or erasure, you may request that Phillforce delete qualifying personal information. Account deletion is available through: Settings → Privacy & Data → Delete Account. The product may require fresh identity verification, and a workspace owner may need to transfer ownership before deletion can be completed. A deletion request does not necessarily require Phillforce to delete every record immediately or in every circumstance. Applicable law may allow or require certain information to be retained for purposes such as:

  • completing transactions;
  • complying with legal obligations;
  • maintaining financial records;
  • detecting fraud;
  • preventing abuse;
  • protecting security;
  • exercising legal rights;
  • resolving disputes;
  • enforcing agreements;
  • maintaining necessary business records.

Additional information is provided in the Phillforce Account & Data Deletion Policy.

9. Right to Data Portability

Where applicable law provides a data-portability right, you may be entitled to receive certain personal information in a structured, commonly used, machine-readable, or otherwise legally required format. The precise information covered by portability rights depends on applicable law. Phillforce may provide information using formats such as:

  • CSV;
  • JSON;
  • PDF;
  • another commonly used electronic format;

where appropriate to the nature of the information and legal requirement. A portability request does not necessarily cover Phillforce intellectual property, proprietary analytical methodology, internal models, security information, or information belonging to another person.

10. Right to Restrict Processing

Where applicable law gives you a right to restrict processing, you may request that Phillforce temporarily limit certain uses of your personal information. This right may apply in particular circumstances, such as where:

  • you contest the accuracy of information;
  • processing is disputed;
  • the information is no longer needed for ordinary purposes but may be required for a legal claim;
  • or another circumstance recognized by applicable law exists.

Restriction does not necessarily require deletion. Some processing may continue where legally permitted or required.

11. Right to Object

Where applicable law provides a right to object, you may object to certain processing of your personal information. For example, depending on jurisdiction and legal basis, this may include processing based on certain legitimate interests or processing for direct marketing. Phillforce will evaluate an objection according to the applicable law and circumstances. Where a valid objection to direct marketing applies, Phillforce will stop the relevant direct marketing processing as required.

Where Phillforce relies on your consent as the legal basis for particular processing, you may withdraw that consent. Withdrawal applies to future processing based on that consent. It does not make processing that lawfully occurred before withdrawal unlawful. Some Phillforce services may depend on information that is necessary to provide the service. If you withdraw consent for processing that is essential to an optional feature, the feature may no longer be available.

13. Marketing Choices

You may unsubscribe from promotional email using the unsubscribe mechanism included in applicable marketing communications. Marketing preferences are separate from essential communications. Even after you unsubscribe from marketing, Phillforce may continue sending necessary communications relating to:

  • your account;
  • authentication;
  • security;
  • billing;
  • purchases;
  • diagnoses;
  • reports;
  • material service changes;
  • legal notices.

14. Sale, Sharing, and Targeted Advertising Rights

Phillforce does not sell personal information for monetary consideration. Certain U.S. state privacy laws define terms such as “sale,” “sharing,” or “targeted advertising” more broadly. Where Phillforce participates in processing that triggers a legally applicable opt-out right, we will provide an appropriate mechanism for exercising that right. Depending on the applicable law, this may include:

  • a privacy preference center;
  • a “Do Not Sell or Share My Personal Information” mechanism where legally required;
  • cookie settings;
  • recognition of supported universal opt-out signals;
  • another legally appropriate control.

If Phillforce does not engage in the regulated activity, the existence of this Policy does not imply that such activity occurs.

15. Universal Privacy Signals

Certain jurisdictions recognize browser or device-based mechanisms that communicate a privacy preference automatically. Where Phillforce is legally required to honor a supported universal opt-out mechanism, such as Global Privacy Control, we intend to process the signal as required by applicable law. The availability and legal treatment of such signals varies by jurisdiction.

16. Automated Decision-Making and Profiling

Phillforce uses automated systems and artificial intelligence to analyze businesses and customer acquisition information. Depending on applicable privacy law, individuals may have rights relating to certain forms of automated decision-making or profiling. Phillforce Intelligence is designed primarily to make analytical recommendations about businesses and commercial acquisition systems. It is not intended to make solely automated decisions determining an individual's eligibility for:

  • employment;
  • credit;
  • housing;
  • insurance;
  • healthcare;
  • criminal justice outcomes;
  • or other similarly significant individual rights.

Where an applicable law provides a relevant right concerning automated decision-making, you may contact: privacy@phillforce.com to exercise that right.

17. Requests Concerning Ask Phill

You may submit a Data Rights Request concerning qualifying personal information associated with your Ask Phill usage. Depending on the request and applicable law, this may include certain information such as:

  • account-associated conversation history;
  • messages you submitted;
  • stored personal information contained in relevant interactions.

A request concerning Ask Phill does not automatically entitle a requester to:

  • Phillforce system prompts;
  • proprietary instructions;
  • internal model configuration;
  • security controls;
  • trade secrets;
  • information belonging to another customer;
  • confidential Phillforce intellectual property.

We will separate personal-data rights from proprietary and security information where necessary.

18. Business and Commercial Information

Phillforce may process commercially confidential information that does not constitute personal information. Examples may include:

  • company revenue information;
  • funnel data;
  • acquisition spend;
  • customer acquisition cost;
  • organizational strategy;
  • conversion rates;
  • offer performance.

Privacy rights generally concern personal information about identifiable individuals. A Data Rights Request does not automatically create a right to obtain all business information belonging to an organization. Organizational data may instead be governed by the applicable Phillforce account, workspace, contract, or customer agreement.

19. Organizational Workspaces

Where Phillforce is used through a business or organizational workspace, the organization may control some information within that workspace. If you request information that Phillforce processes primarily on behalf of your employer or another organization, Phillforce may need to refer the request to that organization or work with that organization to fulfill it. This is particularly relevant where Phillforce acts as a processor or service provider rather than the organization determining why the personal information is processed.

20. When Phillforce Acts as a Processor

A business customer may use Phillforce to process information relating to its own customers, leads, employees, representatives, or other individuals. In those circumstances, the business customer may be the data controller or equivalent organization responsible for determining the purposes of processing. Phillforce may act as a processor or service provider on that customer's behalf. If you submit a request directly to Phillforce concerning information controlled by one of our customers, we may:

  • identify the relevant customer;
  • notify the customer;
  • refer your request to the customer;
  • or assist the customer in responding;

as appropriate under our agreement and applicable law. We will not improperly disclose one customer's information simply because a third party requests it.

21. How to Submit a Data Rights Request

You may submit a privacy request by contacting: privacy@phillforce.com Where available, you may also use privacy controls or a Data Rights Request form provided through the Phillforce website or application. You do not need to create a new Phillforce account solely to make a privacy request where applicable law prohibits such a requirement.

22. What to Include in Your Request

Providing enough information can help us identify the relevant records and respond efficiently. Where appropriate, your request may include:

  • your full name;
  • email address associated with Phillforce;
  • company or organization;
  • Phillforce account information;
  • the type of privacy right you want to exercise;
  • the information or service your request relates to;
  • relevant date range, if helpful;
  • sufficient information to help us locate the applicable records.

Please do not send passwords, authentication codes, full payment-card information, or unnecessary sensitive personal information.

You do not need to cite a statute, regulation, or legal section to make a request. For example: “I would like a copy of the personal information Phillforce holds about me.” may be sufficient to communicate an access request. Similarly: “Please correct my email address.” or: “I want to delete my Phillforce account and associated personal information.” may be enough to communicate the relevant request. We aim to focus on what you are asking us to do rather than whether you used a particular legal phrase.

24. Verification of Identity

Protecting information from unauthorized disclosure is part of respecting privacy rights. Before providing, correcting, deleting, or otherwise acting on certain personal information, Phillforce may need to verify that the requester is the person entitled to exercise the relevant right. Verification may involve factors such as:

  • confirming access to the email address associated with the account;
  • authentication through a logged-in account;
  • confirming information associated with the account;
  • another reasonable verification method.

We will seek to make verification proportionate to the sensitivity and risk associated with the request. We do not want to collect excessive identity information merely to process a privacy request.

25. Requests for Sensitive Information

If a request involves particularly sensitive information or creates a higher risk of unauthorized disclosure, Phillforce may require stronger verification. The purpose of verification is to protect the requester. Information collected specifically for verification will be used for the verification and request-handling process and other legally permitted security purposes.

26. Authorized Agents

Where applicable law allows it, you may authorize another person or authorized agent to make a privacy request on your behalf. Phillforce may require reasonable evidence that the agent has authority to act for you. Depending on the request and applicable law, we may also:

  • verify your identity directly;
  • confirm the authorization with you;
  • request signed authorization;
  • accept legally valid power-of-attorney documentation.

We will not disclose personal information to an unauthorized person merely because that person claims to represent you.

27. Requests on Behalf of Another Person

If you are making a request for another individual, please explain your authority to do so. Examples may include:

  • authorized agent;
  • legal guardian;
  • attorney;
  • person acting under a valid power of attorney;
  • another legally recognized representative.

We may request evidence of that authority before processing the request.

28. Acknowledging Requests

Where reasonably practicable, Phillforce may acknowledge receipt of a Data Rights Request and provide information concerning next steps. An acknowledgement does not necessarily mean that the requested right applies or that the request has been fully verified.

29. Response Time

Phillforce intends to respond to valid Data Rights Requests within the period required by the law applicable to the request. Because Phillforce serves users globally, response periods may differ. For example: European Economic Area Applicable GDPR requests generally require a response without undue delay and within one month, subject to legally permitted extensions. United Kingdom Applicable UK data-protection requests generally require a response without undue delay and within one calendar month, subject to legally permitted extensions. California Where the California Consumer Privacy Act applies, certain verified access, deletion, and correction requests generally require a response within 45 calendar days, with a legally permitted extension where applicable. Nigeria Where Nigerian data-protection requirements apply, Phillforce intends to respond promptly and within applicable legal or regulatory timeframes. For other jurisdictions, Phillforce will follow the period required by applicable law.

30. Extensions

Some laws permit additional time where a request is complex, numerous, or otherwise qualifies for an extension. Where Phillforce relies on a legally permitted extension, we will provide notice where required and explain the reason for the extension. We will not use extensions merely to delay legitimate privacy requests.

31. Clarification

If a request is unclear or extremely broad, we may ask you for additional information reasonably necessary to understand the request. For example, if an account contains substantial information and you are seeking records from a particular period or feature, clarification may help us locate the relevant material. Where applicable law affects the response timeline while clarification is pending, we will follow the applicable rule. We will not require a person to unnecessarily narrow a request where the law does not permit us to do so.

32. Fees

Phillforce generally does not charge individuals merely to exercise a valid privacy right. Where applicable law permits a reasonable fee for a request that is manifestly unfounded, excessive, repetitive, or involves additional copies, Phillforce may charge a legally permitted fee. If a fee applies, we will provide appropriate information before proceeding where required.

33. Requests That May Be Limited or Refused

Privacy rights are important, but they are not always absolute. Applicable law may allow or require Phillforce to limit or refuse a request in circumstances such as where:

  • we cannot reasonably verify the requester;
  • the request would disclose another individual's protected information;
  • disclosure would compromise security;
  • information is protected by legal privilege;
  • retention is legally required;
  • information is needed to establish, exercise, or defend legal claims;
  • the request is manifestly unfounded or excessive where applicable law recognizes that standard;
  • another lawful exemption applies.

Where legally required, we will explain the reason for a refusal or limitation and provide available appeal or complaint information.

34. Protecting Other People's Information

Your privacy rights do not automatically override the privacy rights of another person. If responsive material contains information about another individual, Phillforce may:

  • redact information;
  • separate information;
  • seek consent where appropriate;
  • withhold portions where required or permitted by law.

Our objective is to honor the request without unnecessarily exposing another person's personal information.

35. Security Information

A privacy request does not automatically create a right to receive sensitive security information. Phillforce may protect information such as:

  • passwords;
  • authentication secrets;
  • security tokens;
  • encryption keys;
  • defensive configurations;
  • internal security architecture;
  • vulnerability findings;
  • detailed anti-abuse controls;
  • confidential incident-response procedures.

This protects both the requester and other Phillforce customers.

36. Phillforce Intellectual Property

Data rights concern personal information. They do not generally require Phillforce to disclose proprietary intellectual property merely because personal information is processed within a proprietary system. We may therefore protect, where legally permitted:

  • proprietary algorithms;
  • analytical methodology;
  • software code;
  • internal AI instructions;
  • trade secrets;
  • model architecture;
  • proprietary scoring systems;
  • confidential product-development information.

Where personal information is embedded within such material, we will seek to provide the personal information in an appropriate form without unnecessarily disclosing protected intellectual property.

37. How We Provide Requested Information

Where we provide information in response to an access or portability request, we aim to provide it in an understandable and reasonably secure manner. Delivery methods may include:

  • secure account access;
  • protected electronic download;
  • encrypted or protected file;
  • email where appropriate;
  • another reasonably secure method.

The method may depend on the sensitivity and volume of the information.

38. Data Format

Where appropriate, information may be provided in formats such as:

  • PDF;
  • CSV;
  • JSON;
  • structured text;
  • another appropriate electronic format.

The exact format may depend on the nature of the request, technical feasibility, and applicable legal requirements.

39. Deletion From Active Systems

Where a valid deletion request applies, qualifying information may be removed, anonymized, deactivated, or otherwise deleted from active Phillforce systems as appropriate. Deletion may include information such as:

  • profile data;
  • account information;
  • saved diagnoses;
  • Ask Phill history;
  • certain account-linked business evidence;
  • authentication connections;
  • other qualifying personal information.

The scope depends on the applicable request and legal requirements.

40. Backups

Deleted information may remain temporarily in secured backup systems until those backups are overwritten or expire according to their normal lifecycle. Information retained solely in backup systems is not intended to be restored to ordinary active processing merely because it remains in a backup. If a backup must be restored for legitimate disaster-recovery or security purposes, Phillforce will take reasonable steps to ensure previously deleted information is not improperly returned to ordinary active use.

41. Records We May Need to Retain

Even after a deletion request, Phillforce may retain limited information where reasonably necessary and legally permitted for purposes such as:

  • demonstrating compliance with a privacy request;
  • financial and tax requirements;
  • fraud prevention;
  • security;
  • legal obligations;
  • dispute resolution;
  • contract enforcement;
  • establishing or defending legal claims.

We aim to limit retained information to what is reasonably necessary for the applicable purpose.

42. Correction Requests

When you request correction of inaccurate personal information, Phillforce may consider:

  • the nature of the information;
  • why it is processed;
  • available supporting information;
  • the likelihood that it is inaccurate.

Where appropriate, we may ask for information reasonably necessary to establish the correct value. We will not request excessive evidence where a simpler verification is sufficient.

43. Appeals

Some U.S. state privacy laws provide a right to appeal certain decisions concerning privacy requests. Where an applicable law gives you an appeal right, Phillforce will provide a reasonable method for submitting that appeal. Unless another method is specified, an appeal may be sent to: privacy@phillforce.com with the subject: Privacy Request Appeal Please include the request reference number where available and explain why you believe the decision should be reconsidered.

44. Complaints

If you believe Phillforce has not handled your Data Rights Request appropriately, contact: privacy@phillforce.com We would like the opportunity to investigate and address your concern. Depending on where you live, you may also have the right to complain to a competent privacy or data-protection authority.

45. European Economic Area

Individuals covered by the GDPR may have rights including:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • portability;
  • objection;
  • withdrawal of consent;
  • certain rights relating to automated decision-making.

Applicable requests will be handled according to the GDPR and other relevant law. Individuals may also have the right to complain to the competent supervisory authority.

46. United Kingdom

Individuals covered by UK data-protection law may have rights including:

  • access;
  • correction;
  • deletion;
  • restriction;
  • objection;
  • portability;
  • certain automated-decision rights.

You may also have the right to complain to the United Kingdom Information Commissioner's Office.

47. California

Where the California Consumer Privacy Act, as amended, applies to Phillforce and to you, you may have rights including:

  • the right to know;
  • access;
  • deletion;
  • correction;
  • opt-out rights relating to certain sale or sharing;
  • rights concerning certain sensitive personal information where applicable;
  • protection against unlawful discrimination for exercising applicable privacy rights.

California residents may also use an authorized agent where permitted by law. Phillforce will process qualifying California requests according to applicable California requirements.

48. Other United States States

A growing number of U.S. states provide privacy rights to qualifying residents. Where an applicable state law applies to Phillforce and to you, we will honor the rights required by that law. These may include rights concerning:

  • access;
  • correction;
  • deletion;
  • portability;
  • targeted advertising;
  • sale of personal information;
  • certain profiling;
  • appeal.

Because state requirements differ, the specific rights and response procedures may depend on the state involved.

49. Nigeria

Where the Nigeria Data Protection Act applies, individuals may have rights relating to matters including:

  • information;
  • access;
  • rectification;
  • restriction;
  • objection;
  • data portability;
  • erasure;
  • complaints;
  • automated decision-making.

Phillforce intends to facilitate the exercise of applicable rights in accordance with Nigerian data-protection law where it applies to our processing.

50. Other Countries

Phillforce serves users globally. Users in Canada, Brazil, Australia, countries throughout Africa, Asia, Latin America, the Middle East, and other jurisdictions may have rights under local privacy legislation. Where a local privacy law applies to Phillforce and provides rights beyond those expressly described here, we intend to honor those rights according to applicable law.

51. No Discrimination

Phillforce will not unlawfully discriminate against an individual merely because that person exercised a privacy right protected by applicable law. Exercising a privacy right should not result in an unlawful difference in service. However, if deletion or restriction removes information that is genuinely necessary for a particular Phillforce feature, that feature may no longer be technically available. That is a functional consequence of the data no longer being available, not retaliation for exercising a privacy right.

52. Request Records

Phillforce may maintain limited records concerning Data Rights Requests. These records may include:

  • date received;
  • type of request;
  • verification status;
  • actions taken;
  • response date;
  • applicable legal basis;
  • decision;
  • appeal information;
  • compliance documentation.

We may retain these records where reasonably necessary to demonstrate compliance, protect security, manage disputes, or satisfy legal requirements.

53. Privacy of Request Information

Information provided specifically to make or verify a Data Rights Request will be used for purposes such as:

  • identifying the requester;
  • locating responsive records;
  • processing the request;
  • preventing fraud;
  • maintaining legally required records;
  • protecting Phillforce and its users.

We will not use identity-verification information for unrelated marketing merely because it was submitted through the privacy-request process.

54. Accessibility of the Request Process

Phillforce wants the privacy-request process to be reasonably accessible. If a disability prevents you from using an available request method, please contact: accessibility@phillforce.com or: privacy@phillforce.com and explain the accessibility barrier. We will seek to provide a reasonable alternative where appropriate.

55. Security of Data Rights Requests

Data Rights Requests can involve sensitive information. Phillforce therefore treats the request process as a security-sensitive workflow. We may use safeguards including:

  • identity verification;
  • secure links;
  • protected files;
  • access controls;
  • request logging;
  • authorization checks;
  • expiration of download links.

We do not publicly disclose detailed security controls that could undermine the protection of requests or customer information.

56. Changes to This Policy

Privacy laws, Phillforce products, and our information practices may change. Phillforce may update this Data Rights Request Policy where appropriate. The “Last Updated” date at the top of the Policy will indicate the current version. Material changes may also be communicated through another appropriate method where required.

57. Contact Phillforce

To submit a Data Rights Request or ask a question about this Policy: Phillforce, Inc. 8 Wading Bird Loop Blythewood, SC 29016 United States Privacy requests: privacy@phillforce.com Legal enquiries: legal@phillforce.com Accessibility: accessibility@phillforce.com General enquiries: philip@phillforce.com Website: phillforce.com

Phillforce, Inc. Clarity before activity.

End of Data Rights Request Policy