YOUR PRIVACY RIGHTS

You're in Control

BESA Coaching respects your privacy rights under GDPR, UK GDPR, CCPA, PIPEDA, LGPD, and other applicable laws. Use the tools below to exercise your rights at any time.

Effective Date: May 25, 2026·Last revised: May 25, 2026

Continued use of the BESA Coaching platform constitutes acceptance of the current version.

Your Data Rights

Select any right below to submit a formal request. We respond within 30 days (GDPR) or 45 days (CCPA/PIPEDA) of receipt.

Right of Access

Request a full copy of all personal data we hold about you, including how it is used and with whom it is shared.

GDPRUK GDPRCCPAPIPEDALGPDAPPIPOPIAPDPA

Right to Rectification

Request correction of any inaccurate or incomplete personal data we hold about you.

GDPRUK GDPRCCPAPIPEDALGPD

Right to Erasure

Request deletion of your personal data where it is no longer necessary, or where you withdraw consent. Some data may be retained for legal obligations.

GDPRUK GDPRCCPALGPDPOPIA

Right to Data Portability

Receive your personal data in a structured, machine-readable format to transfer to another service.

GDPRUK GDPRLGPDQuébec Law 25

Right to Object / Restrict

Object to processing based on legitimate interests or restrict processing while a dispute is resolved.

GDPRUK GDPRLGPDPOPIA

Opt Out of Marketing

Withdraw consent for marketing communications at any time. Transactional emails (receipts, booking confirmations) are unaffected.

GDPRUK GDPRCCPACASLCAN-SPAMAll regions

Response Timelines

GDPR / UK GDPR30 days+30 days if complex
CCPA / CPRA45 days+45 days if needed
PIPEDA (Canada)30 daysExtensions with notice
LGPD (Brazil)15 business daysFrom verified request
POPIA (South Africa)30 days+30 days if complex
PDPA (Singapore)30 daysFrom verified request
APPI (Japan)Without delayPromptly upon verification
India DPDP Act30 daysGrievance: 1 month

Identity Verification

To protect your data from unauthorized access, we verify your identity before processing rights requests. Here's what to expect:

1

Submit Request

Use the portal above (logged in) or email [email protected]

2

Verification Email

We send a verification email to your registered address within 2 business days

3

Confirm Identity

Click the verification link or reply with your account email and last 4 digits of your registered phone (if provided)

4

Processing Begins

Once verified, the response clock starts. We may request additional documentation for sensitive requests (e.g., deletion of financial records)

5

Response Delivered

We deliver your data export, confirmation of deletion, or other response within the applicable legal timeframe

We will not charge a fee for reasonable requests. Manifestly unfounded or excessive requests may incur a reasonable administrative fee or be refused, with written explanation.

Appeal Process

If we decline your request or you are unsatisfied with our response, you have the right to appeal.

Step 1 — Internal Appeal

Email [email protected] with subject "Privacy Rights Appeal" within 30 days of our response. Include your original request reference and the reason for your appeal. We will respond within 30 days.

Step 2 — Supervisory Authority

If unsatisfied with our appeal response, you may lodge a complaint with your local data protection authority (see the Supervisory Authorities section below). This right is available at any time — you do not need to exhaust our internal process first.

CCPA Appeal Rights

California residents: if we deny your CCPA request, we will provide a written explanation. You may appeal to the California Privacy Protection Agency (CPPA) at cppa.ca.gov.

EU/UK Judicial Remedy

EU and UK residents have the right to an effective judicial remedy against BESA Coaching if we fail to comply with applicable data protection law, without prejudice to any administrative remedy before a supervisory authority.

Contact Our Privacy Team

For privacy rights requests, data breach notifications, or any privacy concern, contact our Privacy Officer directly. We are committed to responding within the timeframes required by applicable law.

Privacy Officer — B.E.S.A

Email: [email protected]

Security incidents: [email protected]

Response time: 30 days (GDPR/UK GDPR) · 45 days (CCPA/PIPEDA) · 15 business days (LGPD)

Identity verification may be required before processing requests.

Supervisory Authorities

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority:

EU / EEA

Your Member State DPA

Visit

United Kingdom

Information Commissioner's Office (ICO)

Visit

Canada

Office of the Privacy Commissioner

Visit

Québec

Commission d'accès à l'information

Visit

Brazil

ANPD — Autoridade Nacional de Proteção de Dados

Visit

Australia

Office of the Australian Information Commissioner

Visit

South Africa

Information Regulator

Visit

Singapore

Personal Data Protection Commission

Visit

California

California Privacy Protection Agency

Visit

Your Data is Secure

All personal data is encrypted at rest (AES-256) and in transit (TLS 1.3). We conduct regular security audits and maintain strict access controls. In the event of a data breach that poses a risk to your rights, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR.