Silvia Data Subject Request Procedure

Last Updated: September 2026

1. Introduction

Silvia, Inc. and its subsidiaries (collectively, “Silvia,” “we,” “us,” or “our”), respect your right to control your personal information. This Data Subject Request Procedure (“Procedure”) explains how you can exercise your privacy rights under applicable data protection laws, including the General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and other U.S. state and international privacy laws.

This Procedure applies to all Silvia products and services. It supplements our Privacy Policy and Terms of Service. Capitalized terms not defined here have the meanings assigned in those documents.

2. Your Rights

Depending on your jurisdiction, you may have some or all of the following rights with respect to your personal information. Not all rights are available in all jurisdictions.

RightDescriptionApplicable LawsHow to Exercise
Right to Know / AccessRequest confirmation of whether we process your personal information and, if so, receive a copy of the specific data we hold.GDPR Art. 15; CCPA/CPRA §1798.100, .110; VCDPA; CPA; CTDPA; TDPSA; LGPDSubmit a request per Section 3.
Right to PortabilityReceive your personal information in a structured, commonly used, machine-readable format (JSON or CSV).GDPR Art. 20; CCPA/CPRA §1798.100; VCDPA; LGPDSubmit a request per Section 3. Specify preferred format.
Right to CorrectionRequest correction of inaccurate or incomplete personal information. For AI-generated content (e.g., transaction categorizations in CFO Silvia), you can also make corrections directly within the Services.GDPR Art. 16; CCPA/CPRA §1798.106; VCDPA; CPA; CTDPA; TDPSA; LGPDEdit in-app (Silvia), or submit a request per Section 3.
Right to DeletionRequest deletion of your personal information, subject to exceptions (legal obligations, fraud prevention, legal claims, contractual obligations).GDPR Art. 17; CCPA/CPRA §1798.105; VCDPA; CPA; CTDPA; TDPSA; LGPDSubmit a request per Section 3, or delete your account via Account Settings.
Right to Restrict ProcessingRequest that we limit how we process your personal information in certain circumstances.GDPR Art. 18; LGPDSubmit a request per Section 3.
Right to ObjectObject to processing based on legitimate interests or for direct marketing. We will stop direct marketing processing immediately.GDPR Art. 21; LGPDSubmit a request per Section 3, or unsubscribe from marketing emails directly.
Right to Withdraw ConsentWhere processing is based on consent, withdraw it at any time. Withdrawal does not affect lawfulness of prior processing.GDPR Art. 7(3); LGPDAccount Settings, or submit a request per Section 3.
Right to Opt Out of Sale / SharingOpt out of the “sale” or “sharing” of personal information as defined under applicable law. Note: Silvia does not sell personal information. We commercialize Anonymized Data, which is not personal information.CCPA/CPRA §1798.120; CPA; CTDPA; TDPSA; VCDPASubmit a request per Section 3. We also honor Global Privacy Control (GPC) signals.
Right to Opt Out of ProfilingOpt out of profiling that produces legal or similarly significant effects. Note: Silvia does not currently engage in such profiling.CCPA/CPRA; CPA; CTDPA; TDPSA; VCDPASubmit a request per Section 3.
Right to Opt Out of AI Model Training (CFO Silvia)Opt out of having your Inputs and Outputs used to train Silvia’s AI models. Opting out does not affect your use of the Services or the creation of Anonymized Data.Silvia policy (see Privacy Policy and Terms of Service)Email privacy@cfosilvia.com.
Right to Non-DiscriminationWe will not discriminate against you for exercising any privacy right. You will not receive different pricing, quality, or service levels.CCPA/CPRA §1798.125; VCDPA; CPA; CTDPA; TDPSAAutomatic. No action required.
Right to AppealIf we decline your request, you may appeal our decision.CCPA/CPRA; VCDPA; CPA; CTDPA; TDPSASee Section 8.

3. How to Submit a Request

3.1 Submission Channels

ChannelDetailsBest For
Emailprivacy@cfosilvia.com. Include “Data Subject Request” in the subject line.All request types.
Web Formwww.silvia.com/dsr (when available). Guided form ensures you provide the information needed for efficient processing.All request types.
In-App Self-Service (CFO Silvia)Within the Silvia app. Available for: delete conversations, manage marketing preferences, disconnect linked accounts, delete your account (see Section 3.3). To opt out of AI model training or download your data, use Email.Silvia users. Immediate processing for supported actions.
Postal MailSilvia, Inc., Attn: Privacy Team, 600 Lexington Avenue, New York, NY 10022Formal requests where electronic communication is not preferred.

3.2 Information to Include

To help us process your request efficiently, please include:

  • Your identity: Full name and the email address associated with your account.
  • Which product: Whether the request relates to Silvia, Silvia Insights, or both.
  • Request type: Which right you are exercising (e.g., access, deletion, correction, opt-out).
  • Specifics: If applicable, describe the specific data or processing activity your request relates to.
  • Preferred format: For access and portability requests, indicate your preferred format (JSON or CSV). Default is JSON.
  • Authorized agent: If someone is submitting on your behalf, include proof of authorization (see Section 5).

3.3 Self-Service Options

Many privacy actions can be completed immediately within Silvia without submitting a formal request:

  • Delete conversations: delete any conversation from your chat history.
  • Manage marketing preferences: Settings > Notifications, or click “unsubscribe” in any marketing email.
  • Disconnect linked accounts: disconnect a financial account from its page under Accounts, and Google or Trove under Settings > Connectors.
  • Delete your account: Settings > Security > Delete account, or email security@cfosilvia.com.
  • Correct transaction categories: Edit directly within the transaction view.

4. Verification

4.1 Why We Verify

Before processing a Data Subject Request, we must verify your identity to ensure we are acting on a legitimate request and not disclosing, modifying, or deleting someone else’s personal information. This protects you and complies with applicable law.

4.2 Verification Methods

LevelWhen UsedMethodConfidence Required
StandardRequests from the email address on file, for non-sensitive actions (opt-out, marketing preferences, general inquiries).Matching the requestor’s email to the account email. We may send a confirmation link.Reasonable certainty that the requestor is the account holder.
EnhancedAccess requests, portability requests, or requests involving delivery of personal information.Email verification plus at least one additional data point: account creation date, last four digits of linked payment method, a recent transaction amount, or a security question.Reasonably high degree of certainty.
HeightenedDeletion of entire account, requests involving sensitive financial data, or requests from authorized agents.Email verification plus two additional data points, or email verification plus re-authentication through the Services (logging in with MFA).High degree of certainty.

4.3 Unable to Verify

If we cannot verify your identity after reasonable efforts, we will notify you and explain what additional information is needed. If verification remains unsuccessful, we may be unable to process the request. We will not deny a request solely because the verification process is burdensome; we will work with you to find a reasonable alternative.

5. Authorized Agents

5.1 Who May Act as an Authorized Agent

You may designate an authorized agent to submit a Data Subject Request on your behalf. An authorized agent may be a natural person or a business entity registered with the appropriate Secretary of State.

5.2 Proof of Authorization

We require the following to process a request from an authorized agent:

  1. A signed written authorization from you (the data subject) that specifically authorizes the named agent to submit the identified type(s) of request on your behalf. The authorization must include your full name, the agent’s full name (or business name), the types of requests authorized, and the date of authorization.
  2. Proof of the agent’s own identity (government-issued photo ID or, for business entities, articles of organization or similar documentation).
  3. We may also contact you directly at the email address on file to confirm authorization.

5.3 Power of Attorney

If the agent holds a valid, legally enforceable power of attorney under applicable law, we will accept it in lieu of the signed written authorization. We may still verify the agent’s identity and the validity of the power of attorney.

6. Response Timeline

6.1 Acknowledgment

We will acknowledge receipt of your request within five (5) business days. The acknowledgment will confirm the type of request, the verification steps required (if any), and the expected timeline for a substantive response.

6.2 Response Deadlines

JurisdictionInitial DeadlineExtensionExtension Notice
GDPR (EEA, UK, Switzerland)30 days from verified request.Up to 60 additional days for complex or voluminous requests.Within the initial 30-day period.
CCPA/CPRA (California)45 calendar days from verifiable request.Up to 45 additional calendar days.Within the initial 45-day period.
VCDPA (Virginia)45 calendar days.Up to 45 additional calendar days.Within the initial 45-day period.
CPA (Colorado)45 calendar days.Up to 45 additional calendar days.Within the initial 45-day period.
CTDPA (Connecticut)45 calendar days.Up to 45 additional calendar days.Within the initial 45-day period.
TDPSA (Texas)45 calendar days.Up to 45 additional calendar days.Within the initial 45-day period.
LGPD (Brazil)15 business days.Extensions permitted with justification.Required.
Other JurisdictionsWithin the timeframe required by applicable law, or 45 calendar days if no specific timeframe.As permitted by applicable law.As required by applicable law.

6.3 Complex Requests

If your request is complex (involves data across multiple systems, requires coordination with service providers, or is part of a large volume of concurrent requests), we will notify you within the initial response period, explain why an extension is needed, and provide an estimated completion date.

7. How We Fulfill Requests

7.1 Access and Portability

We will provide: the categories of personal information we hold, the specific data elements (in JSON or CSV), the sources, the processing purposes, the categories of third-party recipients, and the applicable retention period. Data will be delivered through a secure download link sent to your verified email address, expiring after 30 days.

7.2 Deletion

We will: delete personal information from active production systems; direct service providers to delete from their systems; delete from backup systems when backups cycle in the ordinary course (typically within 90 days).

Exceptions to deletion: We may retain data where required by applicable law (financial recordkeeping, tax obligations, anti-money laundering); necessary to complete a transaction you initiated; necessary to detect or prevent fraud or security incidents; necessary to exercise or defend legal claims; or where data exists in encrypted backups pending ordinary rotation.

If we retain data after a deletion request, we will inform you of the specific categories retained and the legal basis. Retained data remains subject to all protections in the Privacy Policy and will be deleted when the basis no longer applies.

Anonymized Data: Deletion requests do not apply to Anonymized Data. Once personal information has been irreversibly anonymized in accordance with the Privacy Policy, it is no longer personal information and is not subject to deletion.

7.3 Correction

We will update the identified information in our active systems and notify service providers to update their records. Certain data elements (such as historical transaction records received from third-party financial institutions) may not be modifiable by us; we will explain the limitation and direct you to the appropriate source. AI-generated categorizations and labels in Silvia can be corrected directly within the Services without a formal request.

7.4 Opt-Out

We will process opt-outs within 15 business days of verification, apply them prospectively, confirm in writing, and not ask you to re-consent for at least 12 months unless you affirmatively choose to do so.

7.5 Restriction

We will mark affected data as restricted, cease processing except for storage (unless you consent to further processing, or processing is necessary for legal claims, protection of rights, or important public interest), and notify you before lifting the restriction.

8. Denials and Appeals

8.1 When We May Deny a Request

We may deny or partially deny a request if: we cannot verify your identity after reasonable efforts; the request is manifestly unfounded or excessive; fulfilling it would require us to violate applicable law; fulfilling it would adversely affect the rights of another person; the request falls outside the scope of rights under applicable law; or a legal exception applies.

8.2 Denial Notice

If we deny your request, we will notify you in writing within the applicable response deadline. The notice will include the specific reasons, the categories of data affected, and instructions for how to appeal.

8.3 How to Appeal

Send an email to privacy@cfosilvia.com with the subject line “DSR Appeal.” Include your original request reference number, a description of the decision you are appealing, and the reasons you believe it should be reconsidered. Submit the appeal within 30 days of receiving the denial notice.

8.4 Appeal Review

Appeals are reviewed by a member of the Privacy Team who was not involved in the original decision. Response timelines:

  • GDPR: 30 days from receipt of appeal.
  • CCPA/CPRA: Within a reasonable time, not to exceed 45 days.
  • VCDPA, CPA, CTDPA, TDPSA: 60 days from receipt.
  • LGPD: Within a reasonable time.

If we uphold the denial, we will provide a written explanation and inform you of your right to lodge a complaint with the applicable supervisory authority or regulatory body.

8.5 Supervisory Authority Complaints

If you are not satisfied with the outcome, you may lodge a complaint with:

  • EEA: Your local data protection authority (directory at edpb.europa.eu).
  • UK: The Information Commissioner’s Office (ICO) at ico.org.uk.
  • California: The California Privacy Protection Agency (CPPA) at cppa.ca.gov.
  • Virginia: The Office of the Attorney General at oag.state.va.us.
  • Colorado: The Office of the Attorney General at coag.gov.
  • Connecticut: The Office of the Attorney General at portal.ct.gov/AG.
  • Texas: The Office of the Attorney General at texasattorneygeneral.gov.
  • Brazil: The Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.

9. Fees

We process Data Subject Requests free of charge. Where permitted by applicable law, we may charge a reasonable administrative fee if a request is manifestly unfounded or excessive, or if you request additional copies beyond the first. If we intend to charge a fee, we will notify you of the amount before processing, and you may withdraw or modify the request.

10. Record Keeping

We maintain internal records of all Data Subject Requests, including the date of receipt, request type, verification method, response provided, and response date. Records are maintained for a minimum of 24 months and are available for supervisory authority review upon request.

In accordance with the CCPA/CPRA, we compile annual metrics on the number of requests received, complied with (in whole or in part), and denied, broken down by request type. These metrics are published annually.

11. Changes to This Procedure

We may update this Procedure from time to time to reflect changes in applicable law, regulatory guidance, or our internal processes. When we make material changes, we will update the “Last Updated” date and, where appropriate, provide notice through our websites or other reasonable means.

12. Contact

For Data Subject Requests or questions about this Procedure:

Silvia, Inc.

600 Lexington Avenue, New York, NY 10022

Privacy Team: privacy@cfosilvia.com

DSR Web Form: www.silvia.com/dsr (when available)