Solution
GDPR compliance for software
Most of the GDPR is solved through engineering decisions taken in time. When they are left to the end, the bill is a redesign.
The problem
Compliance was designed backwards
The user sign-up was built with care and the sign-off was left for "when someone asks". When they ask, the data is in six places and deleting it is a manual script.
Signs this is you
- No inventory of which personal data is stored and where it ends up
- Fully deleting a person requires manual work
- You cannot export everything about a user without rebuilding it by hand
- External services touching data with no signed DPA
- An AI or analytics provider outside the EU with no transfer assessment
What we do
What we do
Processing inventory
A map of which personal data is collected, for what, where it is stored and which providers it reaches (database, logs, email, analytics, backups).
Minimisation and retention
Which fields are unnecessary, what can be anonymised, and a retention policy per data type with automatic deletion.
Data-subject rights
So the system can answer access, rectification, erasure and portability without manual intervention.
Security (Article 32)
Encryption, role-based access, logging of access to sensitive data, tested backups and a breach plan (72 hours).
- Technical focus
- data architecture, not legal advice
- Prioritised plan
- by risk and effort, not a generic list
- Privacy by design
- the protective option, enabled out of the box
How we do it
How we do it
Technical review
We analyse the data model, the infrastructure and the providers. Without touching code yet.
DeliverableProcessing and risk report
Prioritised plan
A list of changes ordered by risk and effort, with what must be done before going live marked separately.
DeliverablePlan of changes
Implementation (optional)
We carry out the technical changes or support your team while it does.
DeliverableChanges deployed and verified
Technologies
- PostgreSQL
- Encryption at rest and in transit
- IAM
- Audit log
- Backups
- EU providers
FAQ
What people ask us
Do you act as a Data Protection Officer (DPO)?
No. We cover the technical side: data, security, minimisation and rights. The DPO role and legal advice are handled by a legal professional we coordinate with.
Does using a US AI provider break the GDPR?
Not automatically, but it is an international transfer that needs a legal basis and a risk assessment, and it is best to minimise the personal data sent to it.
How long does the review take?
The technical review usually takes between one and three weeks depending on the size of the application. Implementation is quoted separately.
Related
Related services
Custom software
Tailored software solutions for when off-the-shelf does not fit: applications and platforms designed to last, documented, and with no lock-in to whoever built them.
Learn moreDevOps and systems
Server, database and deployment administration so infrastructure stops being the company’s blind spot.
Learn moreApplied AI
Language-model automation wired into your data and your processes. Measurable use cases, not laboratory demos.
Learn more
Related
Related industries
Health and wellbeing
Patient management, scheduling and clinical data for clinics, practices and psychology professionals, with compliance leading the design.
Learn moreSoftware and SaaS
Third-party API integrations, multi-tenant architecture and engineering capacity for SaaS product companies.
Learn more
Next step
Half an hour well spent
Walk us through the problem on a short call. You leave with a first read on how we'd approach it and what it would involve — no commitment, no sales deck.