Data inventory & mapping
Know what personal data you hold, where it lives and who receives it.
- Systems, storage locations & vendors
- Record of processing activities
- Auto-generated data-flow map
Map personal data, publish versioned notices, keep a tamper-evident consent ledger, answer every rights request on time and report breaches inside the 72-hour window, all from one secure workspace.
Each module maps to a section of the Act or a Rule, so your team always knows what is required and the evidence is collected as work happens.
Know what personal data you hold, where it lives and who receives it.
Versioned notices with a validator for every mandatory item.
Collect, prove and withdraw consent with a tamper-evident record.
Handle access, correction, erasure and nomination requests on time.
From first report to Board intimation, with the clock always visible.
Delete on time, everywhere, and prove it.
A living register of requirements, owners, due dates and evidence.
Board-ready reports and an audit log that cannot be edited.
A self-service privacy portal for your customers.
Four stages, each feeding the next, so nothing depends on someone remembering to update a spreadsheet.
Inventory systems, data and vendors, and record every processing activity with its purpose and lawful basis.
Publish notices and collect consent through the portal or API, each tied to the exact notice version.
Work rights requests, grievances, breaches and erasure jobs with timers, assignments and alerts.
Track every requirement, attach evidence and export reports backed by an append-only audit trail.
Role-based access with organisation, department or own-record scope. Each person sees only what their role allows.
Runs rights requests, grievances, notices and breaches, with every deadline in view.
Owns requirements, evidence and the compliance score, and approves erasure jobs.
Reviews the audit trail and exports reports without being able to change a thing.
Customers view and withdraw consent, raise requests and follow them to closure.
Every sensitive action passes four checks: who you are, which organisation, what you may do, and whether you may touch that record. The checks run on the server, never only in the browser.
Each organisation's data is separated in the app and, on PostgreSQL, by row-level security.
Admins, DPOs, compliance managers and auditors must use two-factor sign-in.
Consent and audit records are append-only and hash-chained.
Personal data is kept out of URLs, logs, notifications and error messages.
Granular permissions with organisation, department or own-record scope.
Whoever raises an erasure job cannot approve it.
Set up your organisation in minutes, invite your team with the right roles and start with a ready-made catalogue of 84 requirements.