Account & data

The headshot desk does not maintain user accounts — and what to do if you have one elsewhere

The headshot site is an editorial newsroom. The desk does not maintain user accounts, does not collect passwords, and does not host a wallet. This page documents the data and account removal request pattern for any third-party surface where a reader has registered a headshot-related account.

Data and account removal request illustration

No headshot account

Why the desk does not maintain a user account

The headshot site is a public newsroom. Reading any desk, any guide, any newsroom brief is free and does not require a user account. The desk does not collect a username, password, email or phone number. The desk does not host a wallet. The desk does not maintain a "headshot account" surface of any kind.

If a reader believes they have a "headshot account" on a third-party surface, the most likely explanation is that the surface is not a headshot surface at all. The desk asks such readers to verify the URL bar, run the phishing checklist on the official-website page and contact the third-party surface directly to request account removal.

Third-party surfaces

The removal request pattern for any third-party account

For any third-party surface that has a "headshot account" or a "headshot wallet" attached to a real or invented identity, the standard removal request pattern is the same. The reader writes to the third-party surface's customer care, requests account removal under the relevant data protection regulation, and asks for confirmation in writing.

The desk does not act as an intermediary. The desk does not have legal authority to remove an account on a third-party surface. The desk's role is to publish the verification standard and to route any security report to the desk's security contact.

Data the desk holds

What the desk knows about a reader, by design

Nothing by default

The desk does not require a reader to submit personal data to read any desk. The desk does not run a newsletter signup that is required to read the desks.

What a reader chooses to send

If a reader chooses to write in via the contact page, the desk holds the inbound message for as long as it is operationally needed. The desk deletes the message after the inquiry is closed.

What the desk never holds

The desk does not hold passwords, payment data, KYC documents, government identifiers or any piece of information that the desk does not need to publish a desk.

What the desk holds

A walk-through of every piece of data the desk may hold

The desk does not hold a password. The desk does not hold a payment instrument. The desk does not hold a government identifier. The desk does not hold a phone number unless the reader chose to share one in a contact-page submission. The desk does not hold a date of birth unless the reader chose to share one. The desk does not run analytics that identifies a reader.

If a reader chooses to write in via the contact page, the desk holds the inbound message and the email address for as long as it is operationally needed. The desk deletes the message after the inquiry is closed. The desk does not share the message with any third party for advertising or marketing. The desk's only use of the message is to reply to the reader.

Response window

What a typical response window looks like for a removal request

For a removal request under GDPR, the data controller has thirty days to respond. The response is either a confirmation of removal, a request for additional identification, or a refusal with a legal basis. The reader's role is to wait for the response and to follow up if the response is late. The desk's role is to publish the standard response window; the reader's role is to apply the standard.

For a removal request under the California Consumer Privacy Act, the data controller has forty-five days to respond. The response is either a confirmation of removal, a request for additional identification, or a refusal with a legal basis. The reader's role is to wait for the response and to follow up if the response is late. The desk's role is to publish the standard response window; the reader's role is to apply the standard.

For a removal request under a different regulation, the response window is set by the regulation. The desk's standard practice is to surface the regulation in this section and to ask the reader to verify the response window on the relevant public source. The desk does not have the legal authority to act as a data controller for any third-party surface. The desk's editorial role is to publish the standard; the reader's role is to apply the standard.

What happens after

What the desk does after a removal request is completed

After a removal request is completed, the desk deletes the inbound message and the email address from the desk's records. The desk's standard retention period is thirty days after the last reply. The desk does not retain the message for marketing, for analytics, or for any other purpose. The desk's role is to reply to the reader, and the desk's only use of the reply is to close the inquiry.

For readers who want to verify that the removal request was completed, the desk's standard practice is to reply to the reader with a confirmation of removal. The confirmation includes the date of the request, the date of the removal, and the data that was removed. The confirmation is the desk's editorial record of the request, and the confirmation is the desk's commitment to the reader.

Alternative

Why the desk's editorial surface is a no-account alternative

The headshot desk's editorial surface is a no-account alternative to any third-party surface that uses the headshot brand. The desk's editorial role is to publish reads; the desk does not require a reader to register an account, submit a password, or share personal data. The reader can read every desk, every guide, every newsroom brief without leaving a trace.

The no-account alternative is the desk's editorial discipline. The discipline keeps the desk's role simple: the desk publishes reads, the reader reads the desk, the URL is the limit of the surface. The discipline also keeps the desk's data minimal: the desk holds only the data the desk needs to publish a desk, and the desk holds no personal data for a reader who has not written in.

For a reader who wants to leave a third-party surface but keep reading the desk, the desk's standard practice is to surface the verification step on the official-website page and the canonical list on the same page. The reader can read the desk on the editorial surface while the third-party surface is being verified, and the reader can apply the verification step to any third-party surface that claims to be a headshot surface.

Reader rights, deeper

What a reader's data rights are in a third-party context

In a third-party context, the reader's data rights are set by the relevant regulation. Under GDPR, the reader has the right to access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object, and the right to lodge a complaint with a supervisory authority. The rights are enforced by the data controller; the desk's role is to surface the rights; the reader's role is to exercise the rights.

Under the California Consumer Privacy Act, the reader has the right to know, the right to delete, the right to opt out of sale, and the right to non-discrimination. The rights are enforced by the data controller; the desk's role is to surface the rights; the reader's role is to exercise the rights.

For a reader who wants to exercise a data right, the desk's standard practice is to write to the third-party surface's data protection contact. The reader should include the data subject's name, the data subject's contact details, and a description of the right being exercised. The data controller has thirty to forty-five days to respond, depending on the regulation. The desk's role is to surface the standard; the reader's role is to apply the standard.