Your Privacy Rights: GDPR, UK GDPR, and US State Privacy Laws
This page is the practical companion to Privacy Policy. The Privacy Policy explains what we do with data. This page explains what you can demand from us, and exactly how to get it.
Requests go to privacy@oraglegpt.org.
1. First, work out who holds your data
This determines who has to answer you, and it is the single most common source of delay.
| Your situation | Who is the controller | Where to send your request |
|---|---|---|
| You have a GPTpost account, or you are on a workspace | We are. GPT LLM ORAGLE Ltd. Liability Co. | privacy@oraglegpt.org |
| You commented on, messaged, or interacted with a brand that uses GPTpost to manage its social accounts | The brand is. We are only its processor | Contact the brand. If you contact us we will route your request to them and tell you we have done so |
You are a visitor to oraglegpt.org | We are | privacy@oraglegpt.org |
| Your data is held by the social platform itself | The platform is, as an independent controller | Contact Meta, TikTok, LinkedIn, Google, X, Pinterest, Reddit, or the relevant instance directly |
We cannot delete a person's data out of a customer's workspace on that person's say-so alone, because it is not our data to decide about. We can and do pass the request on, and we require our customers to handle it.
2. If GDPR or UK GDPR applies to you
You have the following rights. Each is free of charge unless a request is manifestly unfounded or excessive.
| Right | Article | What it means in practice here |
|---|---|---|
| Access | 15 | A copy of the personal data we hold about you, plus the purposes, recipients, retention, and sources |
| Rectification | 16 | Correction of inaccurate data, and completion of incomplete data |
| Erasure | 17 | Deletion, subject to the retention we are legally obliged to keep. See Data Deletion Policy |
| Restriction | 18 | We keep the data but stop processing it while a dispute is resolved |
| Portability | 20 | Your data in a structured, commonly used, machine-readable format, or sent directly to another provider where technically feasible |
| Objection | 21 | You can object to processing based on legitimate interests, and to direct marketing at any time and absolutely |
| Withdraw consent | 7(3) | Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect processing already carried out |
| Not be subject to automated decisions | 22 | We do not carry out solely automated decision-making producing legal or similarly significant effects |
| Complain | 77 | To the supervisory authority of your habitual residence, your place of work, or the place of the alleged infringement |
2.1 Our legal bases
Set out in full in Privacy Policy section 6. In summary we rely on performance of a contract, legitimate interests, legal obligation, and consent for marketing and any non-essential storage.
2.2 International transfers
Primary hosting is in Germany, and so is the object storage for uploaded media, which the Company runs itself rather than buying from a vendor. AI processing, where a customer has enabled it, may take place in the United States under the European Commission Standard Contractual Clauses (2021/914), the UK International Data Transfer Addendum, and the Swiss amendments, with the supplementary technical measures described in Security. A copy of the safeguards is available from privacy@oraglegpt.org.
2.3 Article 27 representative
The Company has no establishment in the EEA or the UK. Where Article 27 requires a representative to be designated, we will publish the designation on this page and notify affected customers before it takes effect. Until then, send Article 27 enquiries to privacy@oraglegpt.org.
3. If you are a California resident (CCPA / CPRA)
3.1 Notice at collection
At or before the point we collect it, this is what we collect and why.
| Category (Cal. Civ. Code 1798.140) | Examples we actually hold | Purpose | Retention |
|---|---|---|---|
| Identifiers | Name, email address, account and workspace IDs, IP address | Provide the Service, authenticate you, secure the account | Life of the account, then 30 days |
| Customer records | Billing contact and invoice records | Bill you, meet tax obligations | Typically 7 years for tax records |
| Commercial information | Plan, subscription state, usage counters | Deliver and meter the Service | Life of the account |
| Internet or network activity | Pages viewed, requests made, user agent, login and operator-action records | Security, abuse detection, reliability | 12 months by default. The append-only audit trail is the exception: it is retained for the life of the workspace, because each entry hashes its predecessor and removing old entries would make the rest unverifiable |
| Geolocation data | Coarse location inferred from IP address | Security and fraud detection | Typically 12 months |
| Professional information | Job title or role, where you provide it | Support and account management | Life of the account |
| Contents of electronic messages | Comments and direct messages the customer submits to its unified inbox. This build does not read them from a social platform | Provided only as a processor, on the customer's instructions | 24 months from last activity by default, enforced by a scheduled sweep. Set per deployment, not yet per tenant from inside the product |
| Sensitive personal information | Account credentials, in the form of a password hash and MFA secrets | Authenticate you. Used only for that purpose | Life of the account |
3.2 Your California rights
- Know the categories and specific pieces of personal information collected, the sources, the business purposes, and the categories of third parties.
- Delete personal information, subject to statutory exceptions.
- Correct inaccurate personal information.
- Limit the use of sensitive personal information. We already use it only for authentication, which is a permitted purpose, so there is nothing further to limit.
- Opt out of sale or sharing.
- Non-discrimination. We will not degrade your service or charge you more for exercising a right.
3.3 We do not sell or share personal information
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA. We have not done so in the preceding 12 months. There is therefore no "Do Not Sell or Share My Personal Information" mechanism for us to operate. You may still write to us to have that confirmed in writing.
We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age.
3.4 Authorised agents
An authorised agent may submit a request on your behalf with written proof of authorisation. We may still contact you directly to verify the request.
4. Other United States state laws
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, and other states with comprehensive privacy laws have rights to access, correct, delete, obtain a copy, and opt out of targeted advertising, sale, and certain profiling.
We do not conduct targeted advertising, we do not sell personal data, and we do not profile individuals for decisions producing legal or similarly significant effects. Where a state law grants a right to appeal a refused request, you may appeal to legal@oraglegpt.org, and we will respond in writing with our reasoning.
5. Other jurisdictions
Residents of Brazil (LGPD), Canada (PIPEDA and Quebec Law 25), Switzerland (revFADP), Australia (Privacy Act), Japan (APPI), and South Korea (PIPA) have broadly equivalent rights. We apply the same process to every request regardless of where it comes from, rather than making you prove which law protects you.
6. How to make a request
- Email
privacy@oraglegpt.orgfrom the address on the account. Email is the route for every right on this page. The product itself offers only the narrower self-serve actions listed in Data Deletion Policy sections 3.1 and 3.2 - disconnect a connected account, delete its account record, delete an individual record - and no screen in this release raises a full erasure request. - Tell us which right you are exercising and, if it helps, which data you mean.
- We acknowledge within 72 hours.
- We verify your identity proportionately: for a low-risk request, control of the account email is enough; for erasure or a copy of sensitive data, we ask for more. We will not ask you to create an account in order to make a request, and we will not ask for a government identity document unless the risk of wrongful disclosure genuinely requires it.
- We respond within 30 days. Where the request is complex we may extend once by a further 60 days, and we will tell you why before the first 30 days expire.
- Our response is free. We charge only where a request is manifestly unfounded or repetitive, and we tell you before doing so.
7. If you are unhappy with our answer
- Reply and ask for a review. A different person reviews the decision.
- Escalate to
legal@oraglegpt.org. - Complain to your supervisory authority or state attorney general. You do not have to exhaust our process first, and we will not treat a complaint as a reason to restrict your account.
8. Related pages
| Page | What it covers |
|---|---|
| Privacy Policy | What we collect, why, and who we share it with |
| Data Deletion Policy | Step-by-step deletion, including platform deletion callbacks |
| Cookie and Local Storage Policy | Cookies and browser storage |
| Subprocessors | Every vendor that may process your data |
| Data Processing Addendum | The Data Processing Addendum and the Standard Contractual Clauses |
| Security | How the data is protected |
9. Contact
| Topic | Address |
|---|---|
| Data subject requests, privacy questions | privacy@oraglegpt.org |
| Appeals and legal notices | legal@oraglegpt.org |
| DPA and Standard Contractual Clauses | dpa@oraglegpt.org |
GPT LLM ORAGLE Ltd. Liability Co.
30 N Gould St, Ste N
Sheridan, WY 82801
United States