Complaints and Inquiry Handling Procedures

Version1.0
Effective DateApril 2026
Review CycleAnnual
Document OwnerChief Information Security Officer (CISO)
ClassificationCONFIDENTIAL — Internal Use Only
Applicable StandardSOC 2 Type II

1. Purpose

This document describes the end-to-end process for receiving, acknowledging, investigating, and resolving privacy-related complaints, inquiries, and disputes submitted by data subjects, customers, third parties, or regulators in relation to DCKAP Integrator’s handling of personal data.

2. Scope

  • Complaints from end consumers whose data has been processed via a customer’s integration flow.
  • Complaints from DCKAP portal users regarding their own personal data.
  • Inquiries from customers about how DCKAP handles data in their integration pipelines.
  • Complaints or notices from data protection regulators or supervisory authorities.
  • Third-party disputes relating to data shared or received via DCKAP Integrator.

3. Complaint Intake Channels

ChannelContact / URLMonitored By
Emailprivacy@dckap.comPrivacy Team (daily review)
Online Formdckap.com/privacy/complaintPrivacy Team (daily review)
Product PortalHelp → Contact Us → Privacy ConcernSupport Team (triaged to Privacy)
Postal[DCKAP Registered Address] — marked ‘Privacy Complaint’Privacy Team (weekly scan)
Regulator / Legal Noticelegal@dckap.com or registered addressLegal Counsel + CISO (immediate)
Support TicketTickets tagged ‘Privacy’ auto-escalatedSupport Team → Privacy Team

4. Complaint Handling Process

StepStageActionsTimeline
1Receipt & LoggingLog complaint in privacy register; assign reference number; categorise (Complaint / Inquiry / Regulator Notice)Day 0
2AcknowledgementSend acknowledgement to complainant with reference number, expected timeline, and point of contactWithin 3 business days
3Initial AssessmentPrivacy Lead assesses complaint: Is it within DCKAP’s scope? Urgent? Regulatory?Days 3–5
4Escalation (if needed)Regulatory notices or P1 data incidents escalated immediately to CISO + LegalDay 3 (if applicable)
5InvestigationGather relevant records (logs, configuration, communications). Interview relevant staff if necessary.Days 5–20
6Resolution DeterminationDetermine whether complaint is upheld (fully, partially, or not upheld). Identify remediation actions.Days 20–25
7Response to ComplainantProvide written response with: outcome, reasoning, actions taken or planned, and right to escalate to supervisory authority.By Day 30
8RemediationImplement any agreed changes, corrections, or security improvements.Per action plan
9Record ClosureUpdate privacy register with outcome. Record any systemic issues for privacy risk register.On completion

5. Response Timelines

Complaint TypeAcknowledgementResolution TargetExtension Permitted?
Standard privacy complaint3 business days30 calendar daysYes — up to 60 extra days with notice
Simple inquiry (non-complaint)1 business day10 business daysYes — with notice
Regulatory / supervisory noticeSame dayPer regulator’s deadlineOnly if regulator grants extension
Data breach complaintSame day72 hours (notification); 30 days (full resolution)No — regulatory obligation
Third-party dispute3 business days30 calendar daysYes — 60 extra days with notice

6. Escalation Paths

6.1  Internal Escalation

  • Complaints involving potential data breach: immediately to CISO + Legal.
  • Complaints involving senior management conduct: to the CEO / Board.
  • Regulatory notices: to Legal Counsel within 24 hours of receipt.

6.2  External Escalation — Data Subjects’ Rights

If a data subject is not satisfied with DCKAP’s response, they have the right to:

  • Escalate to the relevant Data Protection Authority / Supervisory Authority in their jurisdiction (e.g., ICO in the UK, DPC in Ireland).
  • Seek judicial remedy through the courts.

DCKAP will always inform data subjects of this right in our complaint response letters.

7. Complaint Register Template

ReferenceDate ReceivedComplainant TypeNatureStatus / Outcome
COMP-2026-001[Date]Data SubjectErasure request disputeResolved — data deleted
COMP-2026-002[Date]RegulatorSubject access complaintUnder investigation
INQ-2026-001[Date]CustomerData retention questionResolved — guidance provided

8. Continuous Improvement

  • Privacy complaints are reviewed quarterly by the Privacy Lead for systemic trends.
  • Recurring complaint types trigger a root cause analysis and product/process improvement.
  • Annual complaint statistics (anonymised) are reviewed by the CISO and fed into the privacy risk register.

9. Placement in Product

Product LocationScreen / PageAudience
Public Websitedckap.com/privacy/complaint (complaint form)All Data Subjects, Third Parties
Product PortalHelp → Contact Us → Privacy ConcernPortal Users
Privacy Policydckap.com/privacy → How to Complain SectionAll Data Subjects
Internal WikiLegal → Privacy Ops → Complaint Handling ProcedurePrivacy Team, Support, Legal
Compliance FolderSOC 2 Evidence → Privacy Complaints RegisterExternal Auditors, CISO