Settle, for every feature of your application, on what legal basis it processes which data and for how long. Before a request goes to an AI provider, anonymous identifiers stand in place of personal data. At the end you hold a publication-ready privacy notice and two checklists.
The Agentic Part
An agent checks every feature against lawful basis, purpose and retention period per data category. Before a request goes to an AI provider, it replaces personal data with anonymous identifiers. At the end, it assembles the publish-ready privacy notice from the result.
Main Features
- Check against the seven DSGVO principles per feature
- Lawful basis set for every processing purpose
- List of processors with open Art. 28 points
- Review of third-country transfers with anonymized identifiers
- Check on data-subject rights: access, erasure, portability
- Finding on retention periods and deletion capability
- Baseline security check under Art. 32
- Team checklist and management sign-off checklist
Use Cases
- A business isn't sure exactly which features actually process personal data. Every feature is checked against lawful basis, purpose and retention.
- A customer query needs to go to an AI provider, but the name and address must not arrive there. Personal data is replaced with anonymous identifiers first.
- A processor doesn't have a current Art. 28 agreement in place. The processor list shows exactly where that point is still open.
- The website is about to launch without an up-to-date privacy notice. The review ends with a publish-ready version.
What we build for you
- The business's own data model and feature list
- Lawful basis per purpose, confirmed by management
- List of processors and their agreement status
- Transfer mechanism for each third-country call
- Privacy notice wording in the business's language
- Legal or DPO review before external use