Skip to content

Data Protection Rights

Last updated: 12 June 2026

This page summarises the rights available to individuals whose personal data is processed by pmgix under the EU General Data Protection Regulation (GDPR), the UK GDPR, the Turkish Personal Data Protection Law (KVKK), and comparable frameworks. It is a practical guide to help you submit a request. For full details on our processing activities, please read our Privacy Policy.

Contents

  1. Your rights at a glance
  2. How to submit a request
  3. Identity verification
  4. Response times
  5. When we may decline a request
  6. Raising a complaint

1. Your rights at a glance

Depending on where you live and the nature of our relationship with you, you may have some or all of the following rights:

Right What it means
Access Request confirmation of whether we process your data and obtain a copy of relevant information.
Rectification Ask us to correct inaccurate or incomplete personal data.
Erasure Request deletion of your data in certain circumstances, such as where it is no longer necessary.
Restriction Ask us to limit processing while a dispute or review is ongoing.
Objection Object to processing based on legitimate interests or to direct marketing.
Portability Receive personal data you provided in a structured, machine-readable format where technically feasible.
Withdraw consent Withdraw consent at any time where processing is based on consent, without affecting prior lawful use.

2. How to submit a request

To exercise a data protection right, email privacy@pmgix.com with the subject line “Data protection request”. Please include:

  • your full name and preferred contact details;
  • the right you wish to exercise;
  • enough information for us to locate your records (for example, organisation name, recent enquiry date, or project reference);
  • any preferred format for a response or data export.

If you are making a request on behalf of another person, we may require evidence of your authority to act, such as a signed letter of authority or power of attorney.

3. Identity verification

We take reasonable steps to confirm the identity of requestors before disclosing or changing personal data. This helps protect your information from unauthorised access. We may ask for additional details if your initial request does not provide sufficient context.

4. Response times

We respond to valid requests without undue delay and, in any event, within one month of receipt unless applicable law permits an extension. If an extension is necessary due to complexity or volume, we will inform you within the initial one-month period and explain the reason.

There is no fee for most requests. We may charge a reasonable administrative fee or refuse manifestly unfounded or excessive requests as permitted by law.

5. When we may decline a request

In some situations, we may be unable to fulfil a request fully. Examples include where:

  • we are required to retain data for legal, regulatory, or professional record obligations;
  • the information contains confidential details about another individual or client matter;
  • the request is manifestly unfounded, repetitive, or excessive;
  • an exemption applies under GDPR, UK GDPR, KVKK, or other relevant law.

If we decline a request, we will explain our reasoning and inform you of your right to complain to a supervisory authority.

6. Raising a complaint

We encourage you to contact us first at privacy@pmgix.com so we can address your concern. You also have the right to lodge a complaint with a supervisory authority, including:

  • Türkiye — Personal Data Protection Authority (KVKK)
  • EEA — the authority in your country of habitual residence or place of work
  • United Kingdom — Information Commissioner’s Office (ICO)

Related legal information

  • Privacy Policy
  • Cookie Policy
  • Terms of Use