12 - GDPR Compliance

A data subject request has a 30-day deadline. Without a register, that cannot be proved.

The DPO reviews a spreadsheet, nobody knows where personal data is stored, and an erasure request sits in an inbox for three weeks. GDPR compliance is not a document - it is a system that works every day.

Similar challenge?

We respond within one business day.

Send inquiry
Why it hurts

A spreadsheet is not a processing register. An email is not proof of consent. And when a request arrives, the clock starts.

30 days

The statutory deadline for responding to a data subject request under GDPR - the right of access, erasure, rectification, or portability. You must respond in writing. Without a request-tracking system and a central register of personal data, meeting this deadline reliably is extremely difficult.

up to 20 M EUR

Maximum fine under Article 83(5) GDPR (Regulation EU 2016/679) for serious infringements - or 4% of total global annual turnover, whichever is higher. In Slovenia, enforcement is by the IP (Information Commissioner); in Croatia, by AZOP.

72 hours

Deadline for notifying a personal data breach to the supervisory authority under Article 33 GDPR. Without an incident register, documented procedures, and internal contact points, this deadline cannot be met reliably.

What you get

GDPR compliance - implemented, not just documented.

Record of Processing Activities (RoPA) under Article 30 GDPR
Consent management with proof and timestamp
Data subject request portal (access, erasure, rectification, portability)
Retention period tracking and anonymisation on expiry
Data Protection Impact Assessment (DPIA) templates
Register of data processing agreements with processors
Incident register for personal data breaches
Email alerts for pending data subject requests
DPO compliance report
CRM integration for customer anonymisation

Similar challenge?

We respond within one business day.

Send inquiry
Comparison

Before: spreadsheets, email, nobody knows. After: a register with evidence and traceable requests.

Before
Consents in Excel RoPA Word/PDF Requests by email DPO does not know where data is or if consent is valid Request waits 3 weeks → 30-day deadline missed → complaint to supervisory authority
After
GDPR module art. 30 ✓ RoPA register Consent with proof Request portal Incident register DPO report Retention anon. 30-day deadline met ✓
Pricing

Three plans for different organisation sizes.

Every plan includes the RoPA register, consent management, and the data subject request portal. Larger plans add integrations and advanced reporting.

Startup
Setup 1.490 €
+ 49 €/mo.

RoPA register, consent management with proof, data subject request portal, incident register, email alerts.

Business
Setup 2.490 €
+ 99 €/mo.

Everything in Startup plus retention period tracking, anonymisation on expiry, processor register, DPIA templates, DPO report.

Enterprise
from 4.500 €
by arrangement

CRM integration for customer anonymisation, advanced DPO dashboard, multilingual request portal, API access.

FAQ

Questions about GDPR compliance.

Ownership & Terms

What is yours. What is not.

Your data is yours at all times. When you leave, you receive a complete export - no delays.

You receive
Unlimited access to the platform for the duration of your subscription
Full export of your data at any time (CSV, Excel, JSON)
30-day data-transfer window after subscription cancellation
SLA by agreement - response time and uptime guarantees
Daily backups with 7-day retention
You can switch to custom development at any time - we migrate your data to your own system.
You cannot demand
The source code of our platform - this is SaaS, not a software licence; buying out the code is not possible, not even retrospectively
Continued access after subscription expiry without payment
Transfer of the subscription to a third party without written consent
Access to other tenants' data - each database is fully isolated

The next GDPR request is coming. Will you be ready to respond within 30 days?