Every data subject
request, automated.
Access, erasure, portability and the rest, all arriving through one hosted form into one register. Whisperly finds the data, tracks the one-month deadline and drafts the response, so nothing sits in an inbox.
The clock starts
whether you notice or not.
A request is valid however it arrives, including a reply to a marketing email or a message to a support agent. Handled by inbox and spreadsheet, the failure modes are predictable.
Days lost before anyone starts
The request sits in a shared inbox or with an agent who does not recognise it. By the time it reaches the DPO, a week of the month is gone.
Nobody knows where the data is
Finding every system holding one person's data becomes an email hunt across departments, repeated in full for the next request.
No record of what you did
If a complaint follows, you need to show when the request arrived, how identity was verified and why anything was withheld. Email threads do not prove it.
A single front door,
on your privacy notice.
Publish one hosted intake form and link it from your privacy notice, footer and cookie banner. Every submission opens a tracked case with the deadline calculated from the moment it lands, so nothing depends on someone recognising a request in an inbox.
Submit a request about your personal data. We respond within one month.
From submission
to response.
Five stages, each with an owner, a deadline and an audit entry.
Intake and acknowledgement
The form opens a case, records the receipt timestamp and sends an acknowledgement with a reference. Requests that arrive by email or post are logged manually into the same queue, so one register covers every channel.
Verify identity, proportionately
Verification is scaled to the sensitivity of the data rather than demanding a passport for every request. Where further information is genuinely needed, the clock pauses and resumes when it arrives, with both events recorded.
Find the data, using your RoPA
Your record of processing already lists which systems and processors hold which categories of data. The request is scoped against it automatically, producing a targeted list of places to search and owners to task instead of a company-wide email.
Review exemptions and third parties
Legal privilege, other people's personal data and retention obligations that override erasure are all flagged for a decision. Each redaction or refusal is recorded with its reasoning, because that is what a regulator asks for if the requester complains.
Respond and archive
The response is generated from templates in the requester's language, delivered securely, and the full case archived: what was received, when, who decided what and what was disclosed.
Every right has
its own workflow.
An access request and an erasure request are not the same task. Each follows the steps and checks that right actually requires.
Access
Collate the data with the required supplementary information: purposes, recipients, retention and the source it came from.
Erasure
Check retention obligations that override deletion, execute across systems, and notify processors that received the data.
Portability
Export the data the requester provided in a structured, machine-readable format, scoped to consent and contract processing.
Rectification
Correct the record at source and propagate the change to every system and recipient that holds the old version.
Restriction
Mark the data as restricted so it is retained but not processed, and log when restriction is lifted and why.
Objection
Weigh compelling legitimate grounds against the objection, and stop direct marketing processing without a balancing test.
Frequently asked questions
Never miss
another deadline.
See the intake form, the request queue and a full case walkthrough in 30 minutes.