Skip to main content
Settle, for every feature of your application, on what legal basis it processes which data and for how long. Before a request goes to an AI provider, anonymous identifiers stand in place of personal data. At the end you hold a publication-ready privacy notice and two checklists.

The Agentic Part

An agent checks every feature against lawful basis, purpose and retention period per data category. Before a request goes to an AI provider, it replaces personal data with anonymous identifiers. At the end, it assembles the publish-ready privacy notice from the result.

Main Features

  • Check against the seven DSGVO principles per feature
  • Lawful basis set for every processing purpose
  • List of processors with open Art. 28 points
  • Review of third-country transfers with anonymized identifiers
  • Check on data-subject rights: access, erasure, portability
  • Finding on retention periods and deletion capability
  • Baseline security check under Art. 32
  • Team checklist and management sign-off checklist

Use Cases

  • A business isn't sure exactly which features actually process personal data. Every feature is checked against lawful basis, purpose and retention.
  • A customer query needs to go to an AI provider, but the name and address must not arrive there. Personal data is replaced with anonymous identifiers first.
  • A processor doesn't have a current Art. 28 agreement in place. The processor list shows exactly where that point is still open.
  • The website is about to launch without an up-to-date privacy notice. The review ends with a publish-ready version.

What we build for you

  • The business's own data model and feature list
  • Lawful basis per purpose, confirmed by management
  • List of processors and their agreement status
  • Transfer mechanism for each third-country call
  • Privacy notice wording in the business's language
  • Legal or DPO review before external use