Data Subject Access Request (DSAR) Procedure

This procedure describes how AlcheMagic handles requests under GDPR Arts. 15-22 (access, rectification, erasure, restriction, portability, objection). It is the operational appendix to the Privacy Policy §8.

We answer every valid DSAR within 30 days of receipt (extendable to 90 days under Art. 12(3) for complex requests — we notify the requester in writing before extending).

1. Self-service flow (fastest, recommended)

Most DSARs can be answered without any contact with us.

RightSelf-service path
Access (Art. 15) / Portability (Art. 20)In-app: Settings → Account → Download my data. Returns td-account-export-<date>.json saved locally. Includes hashed player id, sessions metadata, full cloud save, purchase records, telemetry consent state.
Erasure (Art. 17)In-app: Settings → Account → Delete my account. Type "DELETE" to confirm. Cascade described in the Account Deletion Policy.
Rectification (Art. 16) — display name, language, consentIn-app: Settings → edit field.
Objection to analytics (Art. 21) / consent withdrawal (Art. 7(3))In-app: Settings → Privacy → toggle Share analytics OFF.

Self-service requests complete in seconds and require no human intervention. They are logged to the audit log (anonymized after account deletion) for compliance proof.

2. Email channel (for everything else)

For requests the self-service flow cannot satisfy (rectification of fields not editable in app; restriction; objection on legitimate-interest grounds; complex access requests; requests by parents/guardians), email:

- The right you are exercising (access / rectification / erasure / restriction / portability / objection). - Your Game Center display name or hashed player id from a prior export. - A description of the data you want to see / change / delete. - A copy of an ID document only if we cannot otherwise verify your identity (we will ask first).

We do not ask for ID up-front because most requesters can be verified via the active session (Apple Game Center proof + valid session token). ID is requested only when the request comes from an unauthenticated channel and we cannot match it to an account.

3. SLA

StepTime
Acknowledge receipt5 business days.
Verify identity (if needed)10 business days.
Provide substantive answer30 calendar days from receipt.
Extend (complex case)Up to 90 days, with written notice before day 30.

Self-service requests bypass this SLA — they complete in real time.

4. Handling steps (internal)

For each request received via email, the on-call Legal/Product responder:

  1. Log the request in the DSAR registry (date, requester pseudonym, type of right, due date).
  2. Acknowledge within 5 business days using the standard template (see §7).
  3. Verify identity if the request is not from an authenticated session: ask for Game Center display name and one identifier from a prior export (hashed player id, last purchase product id, last login timestamp ±1 day). Escalate to ID document only if all heuristic checks fail.
  4. Gather data — for access requests, query for players/<hashed-id>, sessions/* (filtered by player), player-progress/<hashed-id>, entitlements/<hashed-id>, audit-log entries.
  5. Redact any third-party data (e.g., a session id that another user briefly shared on a debugging thread).
  6. Format as JSON matching the self-service td-account-export-<date>.json schema.
  7. Deliver via secure email (encrypted attachment) or a one-time signed download URL (expires 7 days).
  8. Log completion in the DSAR registry; close the ticket.

For erasure requests, the same steps apply but the response is a confirmation that the cascade ran. We must retain pseudonymized audit-log entries indefinitely (see the Account Deletion Policy §3).

For restriction requests, we flag the player record restricted=true within 7 days and exclude it from analytics, log mining, and processor uploads until the restriction is lifted.

5. Right-of-complaint reminder

Every substantive response includes the following text:

If you believe we have not handled your request in line with the GDPR, you have the right to lodge a complaint with your national Data Protection Authority. A list of EU/EEA authorities is at edpb.europa.eu/about-edpb/board/members_en.

6. Children's DSARs (parental requests)

If a parent emails on behalf of a child:

7. Templates

7.1 Acknowledgement (within 5 business days)

Subject: Re: DSAR — <right> — <date> [ack]

Hello,

We have received your data subject request regarding AlcheMagic.

Type of request: <right>.
Reference: <DSAR-YYYY-MM-DD-NN>.
Due date: <ack date + 25 calendar days>.

If we need any further information to act on your request, we will reply
to this email within the next 5 business days. Otherwise, you will hear
from us with the substantive answer by the due date above.

You may also exercise the most common rights without contacting us:
  Settings → Account → Download my data  (access / portability)
  Settings → Account → Delete my account (erasure)
  Settings → Privacy → Share analytics   (objection / consent withdrawal)

Kind regards,
AlcheMagic Privacy team
privacy@arcaneduck.com

7.2 Substantive access response

Subject: Re: DSAR — Access — <date> [response]

Hello,

Attached is the data we hold about your account (reference <DSAR-...>).
The file is a JSON document matching the schema used by the in-app
"Download my data" function. The fields are documented at
https://arcaneduck.com/legal/privacy#data-export-schema.

Retention summary:
  - Cloud save:        retained until you delete your account.
  - Purchase records:  retained 7 years for tax/audit obligations.
  - Server access log: retained 30 days.
  - Audit log:         retained indefinitely (anonymized on deletion).

If you believe we have not handled your request in line with the GDPR,
you have the right to lodge a complaint with your national Data
Protection Authority. The list is at:
  https://edpb.europa.eu/about-edpb/board/members_en

Kind regards,
AlcheMagic Privacy team
privacy@arcaneduck.com

7.3 Erasure confirmation

Subject: Re: DSAR — Erasure — <date> [done]

Hello,

We have erased your account from AlcheMagic. The following data is
gone:
  - Player record (hashed Game Center id binding).
  - Active and expired session records.
  - Cloud save (game progress, settings, owned upgrades).
  - Entitlement ledger entries linkable to your account.

Retention exceptions:
  - Purchase records (originalTransactionId, product id, amount, refund
    state) are retained for 7 years to satisfy tax and accounting
    obligations. They are unlinked from any identifier that could be
    tied back to you.
  - The audit log of this deletion is retained as an anonymized record
    (no identifier present, only a timestamp and the action).

If you believe we have not handled your request in line with the GDPR,
you have the right to lodge a complaint with your national Data
Protection Authority. The list is at:
  https://edpb.europa.eu/about-edpb/board/members_en

Kind regards,
AlcheMagic Privacy team
privacy@arcaneduck.com

8. Audit + metrics

We track the following internally:

Quarterly metrics are summarized in the DSA transparency report (see the EU Digital Services Act Contact Point §7).