CEMFORGE · Commercial policies

Data Requests and Deletion — CF-SCOPED-2026-09-21.1

Versioned text. A sales agreement applies only if this version was incorporated into an accepted order. Retention of this page does not establish any customer’s acceptance.

Policy suite CF-SCOPED-2026-09-21.1 · Version date: September 21, 2026

You can request a review of information held about you, including information associated with an earlier CEMFORGE transaction.

Submit a request

Email privacy@sunn3d.com with your request and a useful order or correspondence reference. Do not include passwords, API keys, payment-card details or unnecessary identity documents. You do not need an active account or a purchase to make a privacy request. We may ask for proportionate identity or authority verification.

Specify whether you seek access, correction, deletion, restriction, portability or an objection. The rights available depend on the processing and applicable law. Requests may cover the static site, email, scoped work or historical gateway records; these systems do not all hold the same data.

Response and lawful exceptions

We aim to acknowledge within 10 business days and respond without undue delay, normally within 30 calendar days and within one month from receipt where GDPR applies. Any permitted extension or identity clarification follows applicable law; verification does not automatically restart the response clock. We explain a delay, exception or refusal and any review or complaint route within the required time.

Eligible personal data in active systems is deleted or irreversibly deidentified through the request process. Some records may be retained where necessary for legal obligations, accounting, sanctions, security or a dispute. We limit the retained information and its use and explain the applicable reason. A historical contract receipt need not retain unrelated project data forever.

Backups, providers and confirmation

Our recovery-copy policy calls for encryption, restricted access, exclusion from ordinary processing and expiry within 90 days after removal from active use, except for a documented retention duty or lawful hold. Automated enforcement and coverage have not been verified across every historical system. For each request we check relevant copies, explain remaining deletion steps and timing or any lawful exception, and reapply approved deletion if a copy is restored. A technical gap is not a lawful retention exception. Shorter legal deadlines prevail. We distinguish completed deletion from a scheduled recovery-copy expiry or lawful hold.

Providers acting independently may have their own lawful records. We instruct processors and notify recipients when required, and help identify the relevant request route. Sunnyday cannot erase public blockchain records or copies independently and lawfully held by another person. No public-chain submission is needed to buy a scoped Datapack.

See the Privacy Notice for purposes, rights, transfer conditions and complaints, and the Data Handling Statement for project-content terms.

See the current policy register · Back to top