1. How to make a request
Email privacy@sydgig.com from your account email with the subject "Privacy request", or use in-product tools when available. Tell us which right you want to exercise and your country of residence. We will verify your identity. Authorised agents (for example, under CPRA) must provide proof of authority. Last updated 1 September 2026.
We will not discriminate against you for exercising a privacy right. We may charge a reasonable fee or refuse only as the applicable statute allows (manifestly unfounded, excessive, or legally prohibited).
2. Europe
EEA / EU
GDPR rights: access, rectification, erasure, restriction, objection, portability, withdraw consent, lodge a complaint with your supervisory authority, and not be subject to certain solely automated decisions. Member-state laws (for example, German BDSG, French Loi Informatique et Libertés, Italian Privacy Code, Spanish LOPDGDD, Nordic and CEE implementations) apply on top. Microstates that apply GDPR or equivalent (Liechtenstein, Iceland, Norway via EEA; Andorra, San Marino, Monaco as applicable) are treated similarly.
United Kingdom, Crown Dependencies, Gibraltar
UK GDPR and Data Protection Act 2018; PECR for cookies. Complaints: Information Commissioner's Office (ICO). Guernsey, Jersey, and Isle of Man have their own DPAs with substantially similar rights.
Switzerland
Federal Act on Data Protection (FADP / nFADP). Complaints: FDPIC.
Western Balkans, Ukraine, Moldova, Georgia, and other Council of Europe states
Many have GDPR-style laws aligned with Convention 108+. We honour access, correction, deletion, and complaint rights under those statutes when they apply.
Russia and Belarus
Localisation and processing rules may apply where we lawfully offer the service. Availability is also limited by the Sanctions policy. We do not offer the Platform where doing so would breach sanctions.
3. The Americas
United States
Federal: we follow COPPA (we do not serve children), CAN-SPAM, and sector rules when triggered. We are not a HIPAA covered entity; do not upload protected health information. State: California CCPA/CPRA (including categories, sale/share opt-out, sensitive PI limitation, authorised agent, 45-day response); Virginia VCDPA; Colorado CPA; Connecticut CTDPA; Utah UCPA; Texas TDPSA; Oregon; Montana; Delaware; Iowa; Nebraska; New Hampshire; New Jersey; Tennessee; Minnesota; Maryland; and other comprehensive state laws as they enter force. Illinois BIPA: do not use SydGiG to collect biometrics without a compliant written policy — we do not seek biometrics except identity liveness if a provider requires it, disclosed at that point. Nevada and others: opt-out of sale via privacy@sydgig.com. GPC honoured where required.
Canada
PIPEDA; Quebec Law 25 (including privacy-impact assessments and consent for certain profiling); Alberta PIPA; B.C. PIPA. Access and correction on request.
Mexico, Central America, Caribbean
Mexico LFPDPPP (ARCO rights, INAI); Costa Rica; Panama; Dominican Republic; Jamaica Data Protection Act; Trinidad and Tobago; Barbados; Bahamas; and other CARICOM DPAs. We honour ARCO-style rights and local complaint bodies.
South America
Brazil LGPD (ANPD); Argentina PDPA 25.326 (AAIP); Colombia Law 1581 (SIC); Chile Law 19.628 and successor; Peru Law 29733; Uruguay Law 18.331; Ecuador; Paraguay; Bolivia; Venezuela (service may be limited by sanctions).
4. Africa
We honour rights under, among others: Ghana Data Protection Act 2012 (Data Protection Commission); Nigeria NDPR and the Nigeria Data Protection Act (NDPC); South Africa POPIA (Information Regulator) — information officer dpo@sydgig.com; Kenya Data Protection Act 2019 (ODPC); Egypt Personal Data Protection Law; Morocco Law 09-08; Tunisia; Rwanda Law 058/2021; Tanzania; Uganda; Côte d'Ivoire; Senegal; Mauritius; and other AU member-state laws including the AU Malabo Convention where implemented. Transfer restrictions are met via contracts and security, or we limit the feature.
5. Middle East and North Africa (additional)
UAE PDPL (including DIFC and ADGM regimes if you use those free-zone laws); Saudi PDPL (SDAIA); Qatar; Bahrain PDPL; Israel Protection of Privacy Law; Türkiye KVKK (Kişisel Verileri Koruma Kurulu); Jordan; Oman; Kuwait. Local representative filings will be made if a statute requires them for our activities, or we will geolimit.
6. Asia-Pacific
- Mainland China: PIPL (individual rights, separate consent for certain processing and exports, CAC complaints). CSL/DSL for network and important data. We may be unable to offer some features without a local operator.
- Hong Kong PDPO (PCPD); Macau PDPA; Taiwan PDPA.
- Japan APPI (PPC); Korea PIPA (PIPC) including overseas-transfer consents; Singapore PDPA (PDPC); Malaysia PDPA; Thailand PDPA; Indonesia UU PDP; Philippines DPA (NPC); Vietnam PDPD / Decree 13; Cambodia, Laos, Myanmar as applicable.
- India DPDP Act 2023 (Data Protection Board) and IT Act SPDI rules while they remain relevant. Grievance officer: legal@sydgig.com.
- Australia Privacy Act 1988 (OAIC), including APP 8 cross-border rules; New Zealand Privacy Act 2020 (Privacy Commissioner).
- Pacific Islands (Fiji, PNG, Samoa, Tonga, and others): local statutes where enacted; otherwise this Policy's baseline plus any applicable common-law confidentiality.
7. Caucasus and Central Asia
Laws of Armenia, Azerbaijan, Georgia, Kazakhstan, Kyrgyzstan, Tajikistan, Turkmenistan, Uzbekistan, and Mongolia apply when you are resident there. We honour local access and deletion rights on request.
9. Typical timelines
| Regime | Typical response time |
|---|---|
| GDPR / UK GDPR | 1 month, extendable by 2 months for complex requests |
| CCPA/CPRA and many US states | 45 days, extendable as the statute allows |
| LGPD | Immediate confirmation if possible; access in 15 days |
| POPIA | Reasonable time, generally within 30 days of a PAIA/POPIA request pattern |
| PIPL / APPI / PDPA family | As the local statute sets, often 15–30 days |
| Where no statute sets a clock | We aim for 30 days |
