Consent & User Rights Policy
Last updated: January 2025
Your rights regarding data access, deletion, portability, and consent management across global privacy frameworks.
TL;DR
- •You have the right to access, correct, and delete your personal data
- •You can export your data in portable formats
- •You can withdraw consent for processing (where applicable)
- •Immutable provenance records cannot be deleted once created
- •Rights vary by jurisdiction (GDPR, CCPA, LGPD, etc.)
- •We respond to rights requests within 30-60 days
1. Your Rights Overview
Depending on your jurisdiction, you have various rights regarding your personal data. This policy explains your rights and how to exercise them within the SOVEREIGN\PROVENANCE ecosystem.
Important: Some rights may be limited by the immutable nature of provenance records, which are essential to the platform's function and cannot be deleted.
2. Right to Access
A. What You Can Access
You have the right to access:
- Your account profile and personal information
- All artifacts and content you have uploaded
- Provenance records associated with your account
- Audit logs and activity history
- Processing activities involving your data
- Third-party sharing information
B. How to Request Access
Submit a request to weare@modernancients.com with:
- Your account email
- Verification of identity
- Specific data categories you want to access
We will respond within 30 days (GDPR) or as required by applicable law.
3. Right to Rectification (Correction)
A. Correcting Your Data
You can request correction of inaccurate personal data, including:
- Account profile information
- Metadata you provided
- Authorship declarations
B. Limitations
Immutable provenance records cannot be retroactively corrected. Corrections create new lineage entries rather than modifying existing records. This preserves the integrity of the provenance chain.
4. Right to Erasure (Deletion)
A. What Can Be Deleted
You can request deletion of:
- Your account and profile data
- User-uploaded content (non-immutable copies)
- Non-essential metadata
- Operational logs (subject to retention requirements)
B. What Cannot Be Deleted
Immutable provenance records cannot be deleted. This includes:
- Cryptographic hashes
- Timestamp receipts
- Provenance manifests
- Lineage logs
- Archival identifiers (IPFS CIDs, OTS commitments)
- Synthetic visibility metadata
This limitation is necessary for provenance integrity and is recognized under GDPR Article 17(3) and similar provisions in other privacy laws.
C. Pseudonymization
When deletion is not possible, we may pseudonymize personal identifiers in immutable records where feasible, removing direct identifiers while preserving provenance integrity.
5. Right to Data Portability
A. Exporting Your Data
You can request a portable copy of your data in machine-readable formats, including:
- Account data (JSON, CSV)
- Uploaded content files
- Provenance manifests and metadata
- Lineage logs
- Timestamp receipts
B. Export Formats
Exports are provided in standard formats (JSON, CSV, ZIP) that can be imported into other systems or used for backup purposes.
6. Right to Restrict Processing
You can request restriction of processing in certain circumstances, such as:
- When you contest data accuracy
- When processing is unlawful but you don't want deletion
- When we no longer need the data but you need it for legal claims
Note: Restriction may limit platform functionality, as some processing is necessary for provenance operations.
7. Right to Object
You can object to processing of your personal data for:
- Direct marketing
- Profiling or automated decision-making
- Processing based on legitimate interests
Note: We do not use your data for advertising or marketing. Objections to processing necessary for provenance operations may limit platform functionality.
8. Consent Management
A. Withdrawing Consent
Where processing is based on consent, you can withdraw consent at any time. Withdrawal does not affect:
- Processing that occurred before withdrawal
- Processing based on other legal bases (contract, legal obligation, etc.)
- Immutable provenance records already created
B. Consent Preferences
You can manage consent preferences in your account settings for:
- Analytics cookies
- Optional features
- Marketing communications (if applicable)
9. Jurisdiction-Specific Rights
A. GDPR (EU/UK)
All rights listed above apply. Response time: 30 days (extendable to 60 days for complex requests).
B. CCPA/CPRA (California)
Additional rights include:
- Right to know what personal information is collected
- Right to opt-out of "sale" or "sharing" (we do not sell data)
- Right to non-discrimination for exercising rights
Response time: 45 days.
C. LGPD (Brazil)
Similar rights to GDPR, with response time of 15 days (extendable).
D. PIPEDA (Canada)
Right to access and correction, with response time of 30 days.
10. How to Exercise Your Rights
To exercise any of these rights:
- Email weare@modernancients.com
- Include your account email and verification of identity
- Specify which right(s) you wish to exercise
- Provide any additional context needed
We will verify your identity before processing requests to protect your privacy and security.
11. Response Times
We respond to rights requests within:
- GDPR: 30 days (extendable to 60 days for complex requests)
- CCPA/CPRA: 45 days
- LGPD: 15 days (extendable)
- Other jurisdictions: As required by applicable law
12. Appeals & Complaints
If you are not satisfied with our response, you can:
- Appeal to our Data Protection Officer at weare@modernancients.com
- File a complaint with your local data protection authority:
- EU: Your national DPA or EDPB
- UK: ICO
- California: California Attorney General
13. Updates
This policy may be updated to reflect changes in privacy laws, platform capabilities, or user rights. The "Last Updated" date reflects the most recent revision.