Skip to main content

If you do not know exactly where personal data gets processed inside your own product, you cannot say whether there is a lawful basis for it or how long the data may be kept. The inventory creates that clarity, feature by feature.

Every feature gets examined individually: lawful basis, purpose and retention period per data category, plus a gap list covering processor agreements, third-country transfers, data-subject rights and the deletion function. When an AI call carries personal data, real names and other identifying details get replaced with anonymous identifiers beforehand. That way, real customer data never reaches the AI provider, not even after a change of vendor.

The result is a privacy notice ready to publish, plus two checklists for different audiences.

What ports as-is

  • Every feature gets checked against the seven DSGVO principles
  • The right lawful basis gets set for every processing purpose
  • A list of all processors with open points on the Art. 28 agreements
  • The review of third-country data transfers, with anonymized identifiers right at the interface instead of real data
  • The check on whether data-subject rights are technically workable: access, rectification, erasure, restriction, portability, objection
  • The finding on how long data stays stored, and whether deletion can actually be carried out technically
  • The baseline security check under Art. 32 and the technical and organizational measures
  • Two checklists, one for everyone involved and one for management sign-off

What we build for you

  • The business's own data model and feature list
  • The lawful basis per purpose, confirmed by management
  • The list of processors with the status of their agreements
  • The transfer mechanism for each third-country call
  • The wording of the privacy notice in the business's own language and register
  • Legal review or review by the data protection officer, before any statement is used externally as proof of compliance