1. Who is responsible for your data
Brilliant Systems LLC, 1500 N Grant St Ste R, Denver, CO 80203, USA, is the data controller for personal data processed through Open Lance. Where the EU or UK GDPR applies to you, the rights below are yours regardless of where we are established.
Our full Privacy Policy sets out what we collect, why, the legal bases we rely on, and how long we keep it. This page is about exercising your rights over that data.
2. The rights you have
Subject to the conditions in the legislation, you can ask us to:
- Access — give you a copy of the personal data we hold about you, and explain what we do with it.
- Rectify — correct anything inaccurate, or complete anything incomplete.
- Erase — delete your data, where we have no overriding obligation to keep it.
- Restrict — pause processing while a dispute about accuracy or legitimacy is resolved.
- Object — stop processing we carry out on the basis of legitimate interests, including profiling.
- Port — hand over your data in a structured, machine-readable format, or send it to another provider where technically feasible.
- Withdraw consent — for anything we do on the basis of consent, such as analytics cookies. Withdrawing is as easy as giving it and does not affect processing that already happened lawfully.
You are never charged for exercising a right, and exercising one never affects how you are treated on the platform.
3. How to make a request
Email privacy@openlance.io from the address on your Open Lance account, and say which right you are exercising. If you cannot use that address, tell us and we will find another way to establish who you are.
We will ask for enough information to be confident the request is genuinely yours. This is a protection for you rather than an obstacle: a data access request that anybody can make in your name is a data breach waiting to happen. We ask for the minimum that establishes identity and nothing more.
If you are asking on behalf of somebody else, include evidence you are authorised to do so.
4. What happens next, and when
We acknowledge the request, confirm your identity, and respond within one month of that confirmation. Where a request is complex or you have made several, the law allows a further two months; if we need that, we will tell you within the first month and explain why.
If we cannot do what you asked, we will say so plainly and give the reason — usually that a legal or accounting obligation requires us to keep specific records, such as transaction and tax history.
5. Where a right has limits
Some data cannot simply be deleted on request, and it is better to say so here than at the point of refusal:
- Transaction, invoice and tax records are kept for the period our legal and accounting obligations require.
- Records relating to a dispute are kept while it is live and for a period afterwards, so an outcome can be evidenced.
- Some data belongs to more than one person. A contract, a message thread or a review involves a counterparty whose rights and records also matter, so erasing your side of it is not always possible.
- Data needed to prevent fraud or abuse may be retained where the law permits, including to stop a closed account being reopened under another name.
Closing your account is not the same as erasure, and we will explain the difference if you ask for one and mean the other.
6. Where your data goes
Open Lance is operated from the United States, and our processors — payment, email, storage and analytics providers — may process data outside your country. Where personal data moves out of the EEA or the UK, we rely on the safeguards the legislation provides for, including the European Commission's Standard Contractual Clauses and the UK Addendum, together with the additional measures those require.
The Privacy Policy lists the categories of processor we use and what each does.
8. If you are not satisfied
Tell us first, at privacy@openlance.io — most complaints are a misunderstanding we can resolve quickly, and we would rather hear it directly.
You also have the right to complain to a supervisory authority without going through us. In the EU that is the authority in the country where you live, work, or where you believe the issue occurred. In the UK it is the Information Commissioner's Office. Contacting them does not require our involvement or agreement.
9. If the GDPR does not apply to you
Rights comparable to these are available to residents of California under the CCPA and CPRA, and to residents of several other jurisdictions with similar legislation. As a matter of practice we handle requests the same way wherever they come from, so you are welcome to use the process above regardless of where you live.