Handling visitor rights requests
A visitor asks you to access or delete “their analytics data.” With BobRay the honest answer is short, and here is how to give it properly.
- Key takeaways
- Given an email or IP, there is no lookup, the dataset holds no identifiers.
- Respond citing Article 11: data not attributable to a person limits access/erasure duties.
- We'll provide a written processor statement for your records on request.
Why there is usually nothing to return
BobRay stores no identifiers: no IPs, no cookies, no names. Given an email address or IP, there is no lookup that can find “their” rows, the data is anonymous aggregates plus day-scoped tokens whose inputs were destroyed. Under GDPR Article 11, when data cannot be attributed to a person, access and erasure duties are correspondingly limited.
How to respond
- Acknowledge the request within your normal DSAR timeline.
- Explain that your analytics provider collects no personal data and holds nothing attributable to them; feel free to link Exactly what BobRay collects.
- If they insist on a processor confirmation, forward the request to privacy@bobray.com and we will provide a written statement for your records.
Account holders are different
Your own account (name, email, billing) is real personal data with full rights, export or deletion of that is handled any time via privacy@bobray.com.
Common pitfalls
The mistakes we see most often on this topic, so you can skip them entirely.
- Promising 'deletion of their analytics data' you can't perform, explain non-attribution instead.
- Forwarding the visitor to us for their site relationship; you remain their contact.
- Conflating visitor requests with account-holder requests, the latter have full rights.
Quick reference
| Lookup possible | No, nothing identifiable |
| Legal hook | GDPR Art. 11 |
| Statement | privacy@bobray.com |
| Account holders | Full rights, separate flow |
Did this solve it? If not, write to support with your site ID, a real person replies within one business day.