Data Subject Access Request (DSAR) Policy
How individuals can exercise privacy rights regarding personal data processed by Lisaiceland, and how requests are handled.
Scope and Covered Properties
This policy applies to Lisaiceland DBA and all websites, applications, products, services, documentation, APIs, affiliate programs, creator programs, AI systems, integrations, and future offerings, including:
References to "Lisaiceland," "we," "us," or "our" mean Lisaiceland DBA.
Purpose
This Data Subject Access Request ("DSAR") policy describes how individuals can exercise privacy rights with respect to personal data processed by Lisaiceland, and how Lisaiceland handles those requests. It supplements the Privacy Policy and the Data Processing Agreement.
Rights Covered
Depending on the individual's jurisdiction, rights may include the right to access personal data, the right to rectification, the right to deletion or erasure, the right to restriction of processing, the right to data portability, the right to object to processing, the right to opt out of "sale" or "sharing" of personal data, and the right not to be subject to certain decisions based solely on automated processing.
Who to Contact
If Lisaiceland processes personal data about an individual as a Controller (for example, account profile information for a Lisaiceland direct user), requests may be submitted through Support | Get Help. Where Lisaiceland acts as a Processor on behalf of a customer (for example, end-user data submitted by a business customer), individuals should contact that business directly; Lisaiceland will assist the business as described in the Data Processing Agreement.
How to Submit a Request
- Identify the personal data or account involved.
- Describe the right being exercised (access, deletion, etc.).
- Provide enough information for Lisaiceland to verify the requester's identity.
- Indicate any preferred delivery format for an access request (where applicable).
Identity Verification
To protect personal data from unauthorized disclosure, Lisaiceland will take reasonable steps to verify the identity of the requester. The verification method is proportionate to the sensitivity of the data and the nature of the request, and may include confirming control of the account email, validating account-specific information, or requesting additional documentation.
Response Timelines
Lisaiceland aims to acknowledge requests within a reasonable period and to respond substantively within the timelines required by applicable law (such as one month under GDPR, with a permitted extension where appropriate). Lisaiceland will inform the requester if more time is required.
Fees
DSARs are generally handled without charge. Lisaiceland may charge a reasonable fee or refuse to act on requests that are manifestly unfounded, excessive, or repetitive, as permitted by applicable law.
Outcomes and Refusals
Where a request can be fulfilled, Lisaiceland will do so. Where a request must be refused or restricted (for example, where granting the request would adversely affect the rights of others, or where retention is required by law), Lisaiceland will explain the basis for the decision and inform the requester of the right to lodge a complaint with a competent supervisory authority.
Authorized Agents
Where permitted by law, individuals may use an authorized agent to submit a DSAR. Lisaiceland may require evidence of the agent's authority and may still verify the underlying individual's identity.
General Legal Terms
Reservation of Rights
Lisaiceland DBA reserves all rights not expressly granted and may update, restrict, suspend, remove, review, or terminate access, content, workflows, affiliate participation, commissions, rewards, or AI functionality where needed to protect users, customers, legal compliance, product integrity, or brand trust.
No Professional Advice
Lisaiceland DBA products, documents, automations, and AI outputs are not legal, medical, financial, tax, employment, emergency, or professional advice.
Limitation of Liability
To the maximum extent permitted by law, Lisaiceland DBA will not be liable for indirect, incidental, consequential, special, exemplary, punitive, lost-profit, lost-data, or reputational damages.
Governing Law
Unless mandatory law requires otherwise, this policy is governed by the laws of the State of Texas, United States, without regard to conflict-of-law principles.
Contact
Questions, requests, or concerns about this policy may be directed to Support | Get Help.