SAR Prep Assistant (Subject Access Requests)

What it is — and what it is not

The SAR Prep Assistant gathers the personal information Bliply holds about one member into a reviewable pack. It is a preparation tool. It does not decide what is legally disclosable and it never sends anything to the member. The gym is the data controller and remains responsible for reviewing completeness, third-party information, exemptions and records held outside Bliply before disclosing.

Use this wording with gyms, never "everything the member is entitled to receive".

Where it lives

On the member's page inside the gym. Platform staff can run it on a gym's behalf — access is limited to gym admin and gym manager equivalents, which platform staff hold when inside a gym.

The workflow

  1. Received — the request is logged with the date it arrived. The response deadline is set to one month later and shown throughout; extend it explicitly if the gym is relying on an extension.
  2. Preparing — Gather runs the sar-package function, which collects records across every category (profile, contact, membership, payments, bookings and attendance, communications, waivers and contracts, notes, marketing preferences and more) and counts them.
  3. Review required — each item can be marked Include, Redact (naming the fields) or Exclude, with a note. Items flagged as containing third-party information must be judged by a person — nothing is auto-disclosed.
  4. Approved — builds the ZIP: cover sheet, disclaimer, a response-information template listing what the gym still has to supply (purposes, categories, recipients, retention, sources, automated decision-making), per-category PDFs, a summary of exclusions and redactions, and the original attachments.
  5. Supplied / Closed — recorded by the gym once they have delivered the pack their own way.

Storage and retention

Packs are written to the private sar-packages bucket and expire after 30 days. Downloads use a 120-second signed link. The daily purge deletes the expired ZIP but keeps the request record and its full audit trail, so the history of who did what survives after the file has gone.

Environments

The sar-packages bucket must exist in each environment. A missing bucket surfaces as a 404 "Bucket not found" on approval — create it with the one-off script in docs/dev-create-sar-packages-bucket.sql. The bucket is included in the nightly storage backup, and purges mirror across to the backup, which is what we want for GDPR.

Audit trail

Every gather, item decision, approval and download is written to member_sar_audit and shown in the panel. Never edit records to "tidy" a SAR — the trail is the point.