Skip to content

Solution

GDPR compliance for software

Most of the GDPR is solved through engineering decisions taken in time. When they are left to the end, the bill is a redesign.

The problem

Compliance was designed backwards

The user sign-up was built with care and the sign-off was left for "when someone asks". When they ask, the data is in six places and deleting it is a manual script.

Signs this is you

  • No inventory of which personal data is stored and where it ends up
  • Fully deleting a person requires manual work
  • You cannot export everything about a user without rebuilding it by hand
  • External services touching data with no signed DPA
  • An AI or analytics provider outside the EU with no transfer assessment

What we do

What we do

Processing inventory

A map of which personal data is collected, for what, where it is stored and which providers it reaches (database, logs, email, analytics, backups).

Minimisation and retention

Which fields are unnecessary, what can be anonymised, and a retention policy per data type with automatic deletion.

Data-subject rights

So the system can answer access, rectification, erasure and portability without manual intervention.

Security (Article 32)

Encryption, role-based access, logging of access to sensitive data, tested backups and a breach plan (72 hours).

Technical focus
data architecture, not legal advice
Prioritised plan
by risk and effort, not a generic list
Privacy by design
the protective option, enabled out of the box

How we do it

How we do it

  1. Technical review

    We analyse the data model, the infrastructure and the providers. Without touching code yet.

    DeliverableProcessing and risk report

  2. Prioritised plan

    A list of changes ordered by risk and effort, with what must be done before going live marked separately.

    DeliverablePlan of changes

  3. Implementation (optional)

    We carry out the technical changes or support your team while it does.

    DeliverableChanges deployed and verified

Technologies

  • PostgreSQL
  • Encryption at rest and in transit
  • IAM
  • Audit log
  • Backups
  • EU providers

FAQ

What people ask us

Do you act as a Data Protection Officer (DPO)?

No. We cover the technical side: data, security, minimisation and rights. The DPO role and legal advice are handled by a legal professional we coordinate with.

Does using a US AI provider break the GDPR?

Not automatically, but it is an international transfer that needs a legal basis and a risk assessment, and it is best to minimise the personal data sent to it.

How long does the review take?

The technical review usually takes between one and three weeks depending on the size of the application. Implementation is quoted separately.

Next step

Half an hour well spent

Walk us through the problem on a short call. You leave with a first read on how we'd approach it and what it would involve — no commitment, no sales deck.