Data Subject Rights (DSR) Procedure

Company: Abbara Sounds, Inc.Effective Date: January 1, 2026Owner: Abbara Sounds, Inc.Version: 1.0

1. Purpose

This document sets out Abbara Sounds, Inc.’s (“Abbara”) internal procedures for receiving, verifying, responding to, and documenting requests from individuals (“Data Subjects”) to exercise privacy rights under applicable data protection laws, including the GDPR and UK GDPR, and—where relevant—U.S. state privacy laws (e.g., CCPA/CPRA, Virginia, Colorado, Connecticut, Utah).

2. Scope

This procedure applies to:

all Data Subject Rights requests relating to personal data processed by Abbara in connection with abbarasounds.com and its subdomains, and related services; and

all Abbara personnel and contractors who may receive, route, or handle DSRs.

This procedure does not replace legal advice. If a request is complex, high risk, or involves sensitive issues, escalate per Section 12.

3. Definitions

DSR: Data Subject Rights request (access, deletion, rectification, portability, restriction, objection, etc.).

Requester: the individual submitting the DSR, or their authorized agent.

Personal Data: information relating to an identified or identifiable person.

Verification: steps to reasonably confirm the Requester’s identity.

4. Roles and Responsibilities

DSR Owner (Privacy Lead): Yusuf Demir AkcayResponsible for intake oversight, deadline tracking, approvals, and final responses.

Support Team: receives inbound requests, creates a ticket, and routes to DSR Owner.

Engineering/IT: executes data pulls/deletion/rectification, and provides system notes.

Legal Counsel: reviews escalations, denials, and high-risk requests.

Vendors/Subprocessors: provide assistance where Abbara is controller and vendor is processor.

5. Accepted Intake Channels

DSRs may be received through:

Email: notice@abbarasounds.com

Support portal: https://abbarasounds.com/pages/contact

Mail: 2093 Philadelphia Pike #8865 Claymont, DE 19703

Other channels (social media, general support inboxes): must be forwarded within 1 business day to the DSR Owner.

6. Initial Triage (Within 2 Business Days)

Upon receipt:

Create a DSR ticket.

Record: date/time received, channel, request type(s), jurisdiction (if known), and any identifiers (email, account ID, order ID).

Confirm whether request relates to Abbara (vs. third party).

Send acknowledgement (Template A).

Determine whether verification is required and appropriate (Section 7).

Start deadline tracking (Section 8).

7. Identity Verification Standard

7.1 General Rule Verify identity to a reasonable degree based on:

sensitivity of data requested;

risk of harm from unauthorized disclosure; and

whether the request is for access/portability (higher risk) vs. general inquiries.

7.2 Verification Methods (Preferred Order)

Logged-in account: Require request submission from the account email and confirm via authenticated session.

Email verification: Reply to the account email and require confirmation via a verification link or code.

Order verification: Confirm an order number plus billing email and last 4 digits of payment method (if available through processor metadata).

Additional verification (only if needed): request an additional piece of information already on file (do not request new sensitive data unless strictly necessary).

7.3 Authorized Agents If an agent submits a request:

require proof of authorization (signed permission or power of attorney); and

verify the Data Subject’s identity separately where required by law.

7.4 Insufficient Verification If identity cannot be verified, request additional information (Template B). If still unverifiable, deny (Template E) and document the basis.

8. Deadlines and Extensions

8.1 GDPR/UK GDPR

Respond within 1 month of receipt.

Extension: up to 2 additional months for complex or numerous requests, with notice within the original 1 month explaining reasons.

8.2 U.S. State Privacy (If Applicable)

Track state-specific deadlines (e.g., 45 days under CPRA, with extensions in some cases).

Where a user’s location is unclear, default to the stricter timeline.

8.3 Internal Targets

Acknowledge receipt: within 2 business days.

Complete verification: within 7 calendar days (target).

Fulfill simple requests: within 21 calendar days (target).

9. Request Types and Handling Steps

9.1 Right of Access (GDPR Art. 15)

Goal: Provide a copy of personal data and required disclosures.Steps:

Confirm scope (account data only vs. all systems).

Export data from systems (Section 10).

Review for third-party personal data and redact where required.

Provide required disclosures: purposes, categories, recipients, retention, source, transfers, and rights.

Deliver securely (Section 11).

9.2 Right to Rectification (GDPR Art. 16)

Steps:

Confirm what data is inaccurate.

Update in source systems (account profile, billing records where permitted).

Where data must be retained unchanged for legal reasons (e.g., invoices), record a note/correction rather than altering the record.

Confirm completion.

9.3 Right to Erasure / Deletion (GDPR Art. 17)

Steps:

Confirm whether an exception applies (e.g., legal obligation, establishment/defense of claims, fraud prevention).

If eligible, delete or irreversibly anonymize across systems where feasible.

Maintain a suppression list entry (e.g., hashed email) if needed to respect opt-outs and prevent re-collection, to the extent permitted by law.

Confirm completion and note any retained data categories and basis.

9.4 Right to Restriction (GDPR Art. 18)

Steps:

Flag account and limit processing (e.g., pause marketing, limit profiling/analytics where applicable).

Implement technical restriction where feasible.

Notify Requester when restriction is lifted (if applicable).

9.5 Right to Data Portability (GDPR Art. 20)

Steps:

Provide data the Data Subject provided to Abbara and data processed by automated means based on contract/consent.

Provide in a structured, commonly used, machine-readable format (e.g., JSON/CSV).

Deliver securely.

9.6 Right to Object (GDPR Art. 21)

Steps:

Direct marketing objection: honor promptly (unsubscribe/suppress).

Legitimate interests objection: assess and document balancing test; stop processing unless compelling legitimate grounds exist.

9.7 Withdraw Consent (GDPR)

Steps:

Identify processing based on consent (e.g., non-essential cookies; marketing where consent-based).

Apply withdrawal (cookie settings / email preference).

Record completion.

9.8 Automated Decision-Making (GDPR Art. 22)

If applicable, provide information and enable human review. If not used, confirm “not applicable.”

10. Data Map: Systems to Search (Template)

Minimum systems to review for most requests:

User Accounts/DB: [SYSTEM NAME]

Admin/CRM: [SYSTEM NAME]

Email marketing: [SYSTEM NAME]

Support platform: [SYSTEM NAME]

Payments processor: [SYSTEM NAME]

Analytics: [SYSTEM NAME]

File delivery/logs (downloads): [SYSTEM NAME]

Security logs: [SYSTEM NAME]

For each DSR, record:

systems searched,

data exported/deleted,

exceptions, and

the person completing each step.

11. Secure Delivery Standards

Provide access/portability exports via: encrypted file + separate password channel, secure portal, or time-limited link.

Do not include sensitive credentials.

Do not send personal data exports as unencrypted email attachments.

Keep a record of delivery method and date.

12. Exceptions, Refusals, and Escalations

Escalate to Legal Counsel and the DSR Owner before refusing or limiting a request when:

identity cannot be verified;

the request is manifestly unfounded or excessive;

requests involve suspected fraud or account takeover;

fulfilling would disclose third-party personal data or trade secrets; or

Abbara must retain data for legal obligations (tax/accounting, chargebacks, litigation hold).

Any refusal or partial refusal must include:

the reason (legal basis);

what was not provided/deleted and why; and

instructions on how to complain to a supervisory authority (GDPR/UK GDPR) where applicable.

13. Recordkeeping and Audit Log

Maintain a DSR log with:

ticket ID,

requester identifiers (minimized),

request type,

verification steps,

dates (received/verified/responded),

outcome (fulfilled/partial/denied),

systems involved,

any vendors contacted,

response template used, and

reviewer approvals (if applicable).

Retention of DSR logs: 3 YEARS (or as required by law).

14. Vendor/Subprocessor Coordination

If a vendor processes personal data as Abbara’s processor:

Send a vendor assistance request with the ticket ID and scope.

Track vendor SLA.

Collect vendor confirmation of completion (deletion/export) and attach to the DSR ticket.

15. Templates

Template A — Acknowledgement

Subject: We Received Your Privacy Request

Hello [NAME],We have received your privacy request on [DATE]. To protect your information, we may need to verify your identity before completing the request. We will respond within the time period required by applicable law.

If you have questions, contact us at notice@abbarasounds.com— Abbara Sounds, Inc.

Template B — Verification Needed

Subject: Verification Required for Your Privacy Request

Hello [NAME],To process your request, we need to verify your identity. Please reply from the email address associated with your account and confirm the following: [E.G., USERNAME AND MOST RECENT ORDER ID].

Once verified, we will proceed with your request.— Abbara Sounds, Inc.

Template C — Fulfilled (Access/Portability)

Subject: Response to Your Privacy Request

Hello [NAME],We have completed your request. Your personal data file is available here: [SECURE LINK] (expires [DATE]). The password will be provided via [CHANNEL].

If you have questions, contact us at contact@abbarasounds.com.— Abbara Sounds, Inc.

Template D — Fulfilled (Deletion)

Subject: Confirmation of Deletion Request

Hello [NAME],We have processed your deletion request. We deleted or anonymized personal data associated with your account to the extent required and permitted by law. We may retain certain information where necessary for legal obligations (e.g., accounting/tax records) or to protect against fraud.

— Abbara Sounds, Inc.

Template E — Denial or Partial Denial

Subject: Response to Your Privacy Request

Hello [NAME],We are unable to fully complete your request because: [REASON]. Where applicable, we have completed the portions of your request that we can.

If you are located in the EU/EEA or UK, you may lodge a complaint with your local supervisory authority (or the UK ICO). You may also contact us at notice@abbarasounds.com— Abbara Sounds, Inc.

16. Training and Review

Train relevant staff annually and upon material changes.

Review this procedure at least annually and after any material changes to data systems or applicable laws.

17. Appendices

Appendix 1 — DSR Intake Checklist

Ticket created and categorized

Jurisdiction assessed (EU/UK/US/Other)

Verification completed (or not required)

Systems identified

Vendor requests sent (if needed)

Response drafted and approved

Response delivered securely

Log updated and closed

Appendix 2 — Balancing Test Note (Legitimate Interests Objection)

Processing purpose: [PURPOSE]

Legitimate interest: [INTEREST]

Impact on individual: [IMPACT]

Safeguards: [SAFEGUARDS]

Outcome: [CONTINUE/STOP]