If you have a CloakAPI account you don't need to email anyone — both rights are built into the product:
Access / export (Article 15) — request a machine-readable JSON export of everything we hold about you: profile, API keys, sessions, usage records, receipts and receipt chain, invoices and billing history, org membership, privacy tiers and more. You receive a signed, time-limited download link.
Erasure (Article 17) — request deletion. Session, token and key data are deleted; financial records are retained under legal-hold in pseudonymised form (invoices, ledgers); receipts are retained in hash-chain-preserved form; your account row is anonymised. Audit records are erased by crypto-shredding: your personal data in the audit log is held only as AES-256-GCM ciphertext under a key unique to you, and that key is destroyed. The stored bytes are never altered — the ciphertext simply becomes permanently unopenable, by anyone including us — and the erasure is written as two new appended chain events rather than a rewrite. What remains readable is an opaque pseudonym plus the action, resource and timestamp, so the log still works as a security log. Because encrypted backups are retained for 30 days, the shred is fully effective 30 days after the key is destroyed; your receipt states that date. You receive an erasure receipt that records that the deletion job ran — check it against the published JWKS when one is issued — and that records what was deleted, what was retained under legal-hold, when the shred becomes fully effective, and why — without ever containing your personal data. Anyone can verify it independently at POST /api/v1/receipts/verify.
Both requests are confirmed out-of-band (a verification token sent to your registered email) before anything runs, so no one can export or erase your data without control of your inbox.
By email
You can also email dpo@cloakapi.io with the subject line DSAR — the right route if you are not a registered user (for example an outreach contact). Include enough detail to verify your identity (we ask the minimum necessary; usually the email address we contacted you on).
Response timeline
We respond within the 30-day statutory window; requests approaching that deadline are flagged automatically so they are never silently missed. If a request is genuinely complex we may extend by a further 60 days and tell you why.
Categories of personal data we hold
The full, category-by-category map of everything CloakAPI holds — what it is, why, where, and for how long — is published as our data map & record of processing. In summary:
Outreach contact: company name, role, public work email, public signal evidence.
On the standard client-side paths, your AI prompt and response content is tokenised on your device before it reaches our gateway — we never receive raw personal data in it. On that architecture, many customers conclude we are not a processor of that content — evaluate this with your own counsel (not legal advice). The data map documents the two narrow, transient exceptions (opt-in gateway-managed multi-turn maps, 30-day TTL; and tokenised buffered responses, purged hourly).
Erasure
Full erasure (Article 17): registered users run it self-service (above) and receive an erasure receipt. For outreach contacts we delete your data and add your email to the suppression list so you never receive outreach from us again — the suppression list itself is a lawful-basis Article 6(1)(f) record and is retained.
Right to complain
You may complain to your national Data Protection Authority. We are based in Norway; the lead authority for cross-border complaints is the Norwegian Datatilsynet.