Privacy
Data Deletion
How to request deletion of Personal Data associated with Gephra’s websites, products, platforms, and services.
Data deletion at Gephra
GEPHRA LTD (“Gephra,” “we,” “us,” or “our”) provides this page to explain how individuals may request deletion of Personal Data associated with Gephra’s websites, products, platforms, and services.
This process applies to Personal Data processed through:
- gephra.com
- Gephra HOPILLA
- Gephra Sustaina
- other Gephra Services that reference this deletion process
Requesting deletion from Gephra
Where Gephra controls the Personal Data concerned, you may request deletion by contacting privacy@gephra.com.
Your request should include sufficient information for Gephra to identify the relevant data or account, such as:
- your name
- your email address or other account identifier
- the Gephra Service concerned
- a brief description of the information you would like deleted
Please do not send passwords, authentication secrets, payment credentials, or other unnecessary sensitive information with your request.
Identity verification
Gephra may request reasonable information to verify your identity or authority before processing a deletion request. Verification is intended to prevent unauthorized persons from deleting or obtaining information associated with another individual or organization.
Gephra will request only information reasonably necessary for this purpose.
Customer-controlled data
Some Gephra Services are provided to businesses and organizations that control the Personal Data processed through those Services.
For example, a hotel, lodge, resort, serviced apartment, guest house, or other hospitality business may use Gephra HOPILLA to process information relating to its guests, employees, or operations.
Where the relevant Customer determines how and why Personal Data is processed, the Customer generally controls that data and Gephra processes it on the Customer’s behalf. If your deletion request concerns Personal Data held by a Gephra Customer, you should normally submit the request directly to that Customer.
Examples may include:
- hotel guest records
- reservations
- stay information
- Customer-managed employee records
- Customer-managed transaction records
- information submitted to a Customer through a Gephra-powered service
Gephra will support the relevant Customer in carrying out valid deletion requests where required by applicable law or contractual obligations.
Account deletion
Where a Gephra Service provides an account-deletion function within the application, you may use that function to initiate deletion. Where no self-service deletion function is available, a request may be submitted to privacy@gephra.com.
Deletion of an account may result in loss of access to associated Services, settings, records, or other information linked to that account. Where the account is controlled by an organization, certain account actions may need to be performed or authorized by that organization.
What happens after a request
After receiving a deletion request, Gephra may:
- 1verify the identity or authority of the requester
- 2determine whether Gephra or a Customer controls the relevant Personal Data
- 3identify the information covered by the request
- 4determine whether any information must or may lawfully be retained
- 5delete, anonymize, or otherwise remove applicable Personal Data
- 6communicate the outcome of the request where appropriate
Requests will be handled in accordance with applicable data protection and privacy requirements.
Information that may be retained
Deletion does not necessarily require immediate removal of every record associated with an individual. Gephra may retain information where reasonably necessary for purposes including:
- compliance with legal or regulatory obligations
- tax and accounting requirements
- security and fraud prevention
- investigation of abuse or security incidents
- establishment, exercise, or defence of legal claims
- enforcement of contractual obligations
- maintenance of required audit records
- other purposes permitted by applicable law
Where possible, Personal Data that is no longer required may be deleted or anonymized.
Backups
Personal Data deleted from active systems may remain temporarily within protected backups until those backups are overwritten or expire through established retention processes.
Backup data will not ordinarily be restored or otherwise processed except where required for legitimate recovery, security, or legal purposes.
Third-party services
Where Personal Data has been provided directly to an independent third-party service, such as a payment provider, communications provider, or other external platform, deletion may also be subject to that third party’s privacy and deletion procedures.
A request submitted to Gephra does not automatically delete information independently controlled by another organization.
Deletion requests connected to external platforms
Gephra Services may integrate with external platforms that require a publicly accessible data-deletion instructions URL. Unless a product-specific deletion process is provided, this page serves as Gephra’s general deletion instructions at https://gephra.com/data-deletion.
Requests arising from an external platform integration may be submitted to privacy@gephra.com. The requester should identify the relevant Gephra Service and external platform to allow the request to be located and processed appropriately.
Privacy Policy
Additional information about how Gephra handles Personal Data is available in the GEPHRA LTD Privacy Policy.
Contact
© Gephra Ltd. All rights reserved.