Request For Access Forms Templates
| Field | Value |
|---|---|
| Version | 1.0 |
| Effective Date | April 2026 |
| Review Cycle | Annual |
| Document Owner | Chief Information Security Officer (CISO) |
| Classification | CONFIDENTIAL — Internal Use Only |
| Applicable Standard | SOC 2 Type II — Security, Availability, Confidentiality |
1. Purpose and Scope
This document defines the template and content requirements for the Data Subject Request (DSR) form used by individuals to submit access requests (and other privacy rights requests) to QA Touch. It ensures requests are clear, complete, and consistent, supporting efficient processing while protecting against fraudulent submissions. Supports SOC 2 Privacy criterion P6.1.
2. DSR Form Overview
QA Touch maintains a web-based Data Subject Request form accessible at [VERIFY URL] and linked from the Privacy Policy, User Settings, and Help Centre. The form is available to any individual who believes QA Touch holds their personal information.
- The form is available 24/7 without requiring a QA Touch account (as the requestor may be a former user).
- Form submissions generate an automated acknowledgement email with a unique DSR tracking ID within 24 hours.
- Form data is encrypted in transit (TLS 1.2+) and stored securely; access restricted to the Privacy/Compliance team.
3. Data Subject Request Form — Field Specification
| Field | Required? | Type | Purpose / Guidance |
|---|---|---|---|
| Full Name | Required | Text (max 200 chars) | Used to locate your records in QA Touch systems. |
| Email Address | Required | Email format validated | Used for identity verification and to deliver your response. |
| Request Type | Required | Dropdown (single select) | Select: Access to My Data / Correct My Data / Delete My Data / Data Portability / Restrict Processing / Object to Processing / Withdraw Consent / Other |
| Description of Request | Required | Textarea (max 2,000 chars) | Describe what you are requesting and which data it relates to. The more specific you are, the faster we can process your request. |
| QA Touch Account Email (if different from above) | Optional | Email format validated | If your QA Touch account uses a different email address, provide it here to help us locate your records. |
| Organisation / Workspace Name (if applicable) | Optional | Text (max 200 chars) | If your data was held in a specific company’s QA Touch workspace, provide the organisation name to help us locate the correct records. |
| Country of Residence | Required | Dropdown | Used to determine which privacy laws apply to your request and our response obligations. |
| Preferred Response Language | Optional | Dropdown | Language in which you would like to receive our response (English default; other languages where available). |
| Supporting Documentation | Optional | File upload (PDF / JPG / PNG, max 5 MB) | If acting on behalf of another person, upload signed authorisation here. If you cannot verify via email, upload a redacted government-issued ID. |
| Confirmation Checkbox | Required | Checkbox | ’I confirm that the information I have provided is accurate and I am the data subject or their authorised representative.‘ |
| Privacy Policy Agreement | Required | Checkbox with link | ’I have read and understood QA Touch’s Privacy Policy [link].‘ |
4. Automated Acknowledgement Email Template
| Field | Content |
|---|---|
| Subject line | We’ve received your data request — Reference: DSR-[UNIQUE-ID] |
| Body | Dear [Name], Thank you for submitting your data request to QA Touch. Request Reference: DSR-[UNIQUE-ID] Request Type: [Type] Date Received: [Date] What happens next: 1. We will verify your identity within 5 business days. 2. Once verified, we will process your request and respond within 30 calendar days. 3. If we need more information, we will contact you at this email address. If you have questions, contact us at privacy@qatouch.com.QA Touch Privacy Team |
5. Request Type Reference Guide
| Request Type | What You Will Receive | Typical Response Format |
|---|---|---|
| Access to My Data | A copy of the personal data QA Touch holds about you, the purposes it is used for, who it is shared with, and how long it is retained. | Structured data export (JSON or PDF) plus a covering letter |
| Correct My Data | Inaccurate personal data corrected; confirmation of changes made. | Written confirmation of corrections made and their effective date |
| Delete My Data (Right to Erasure) | Personal data deleted where no legal basis for retention exists; confirmation of deletion. | Written confirmation of data deleted and any data retained with legal basis explained |
| Data Portability | Your personal data provided in a structured, machine-readable format (JSON or CSV) for transfer to another service. | Data export file (JSON / CSV) with covering letter |
| Restrict Processing | Processing of your data suspended while a dispute is resolved; you will be notified before restrictions are lifted. | Written confirmation of restriction applied and conditions for lifting |
| Object to Processing | Objection reviewed; processing based on legitimate interests assessed; processing stopped if objection is upheld. | Written outcome: objection upheld (processing stopped) or upheld in part or rejected (with reasons) |
| Withdraw Consent | Consent for optional processing (marketing, analytics) withdrawn immediately; confirmation sent. | Written confirmation of withdrawal and effective date |
6. Form Accessibility and Availability
- Form available in English; additional language versions provided where QA Touch serves significant non-English-speaking customer bases [VERIFY].
- Form designed to meet WCAG 2.1 Level AA accessibility standards [VERIFY].
- Alternative submission method available via email to privacy@qatouch.com for individuals unable to use the online form.