Limited access
Team members’ roles determine which requests they can access.
Security and trust
Requests can include personal data, evidence, response files, and delivery records. Privacy Requests helps you limit access, control delivery, and keep a clear history of what happened.
Security essentials
The right people can see the right request, and every important action is recorded.
Team members’ roles determine which requests they can access.
Share response files through expiring links, revocation, passcodes, and access logs instead of email attachments.
Important actions are recorded so you can review what happened later.
Use verification links, email codes, and documented review steps before sensitive materials move.
Response preparation stays reviewable. Attachment checks flag potentially sensitive information for a person to review before approval.
Built-in safeguards
These safeguards are available in the app today. They do not represent a security certification or guarantee legal compliance.
Team members stay signed in for up to 12 hours. Sign-in links expire after 15 minutes and can be used only once.
Delivery links default to 72 hours and can be configured from 1 to 720 hours. A delivery access session is limited to 30 minutes or the remaining link lifetime, whichever is shorter.
Staff can revoke an active delivery link. A passcode-protected link is revoked after ten failed passcode attempts, and the event is recorded.
The case history records when delivery links are created, opened, expire, or are revoked, and when files are downloaded. Records include who took the action and when, where that information is available.
Human approval
Verification, disclosure, deletion, correction, and final response decisions stay with your team, not hidden in the background.
Practical safeguards
Keep response files in one controlled place instead of sending them through email threads.
See who can access requests and how delivery links were used.
When a delivery link should no longer be available, revoke it and keep a record of that action.
People submit requests through a public portal while your team handles the response privately.
Requesters can follow a private status link without seeing internal notes, assignments, or case materials.
Closure checks keep verification, fulfillment, approval, delivery evidence, and the final export visible before a case is finished.
Shared responsibility
Before delivery, review the actual files and the intended recipient. An attachment check can flag content for review; it cannot decide whether disclosure is appropriate. Choose a link lifetime and passcode that fit the case, and share access details carefully.
Revoking a link prevents future access through that link. It cannot recall a file someone has already downloaded or copied. Plan retention and handling around that boundary.
Review service facts and available materials for hosting information and the status of contractual and assurance documents. Product controls do not imply a certification, a guaranteed hosting region, or an approved data processing agreement.
Contact
For questions about Privacy Requests security practices, contact support@privacyrequests.co.
Use this address to report a suspected security issue. Do not include requester records or identity documents in your message.