Practical controls for organizations handling personal data.
Organizations that handle personal data — customer records, patient files, staff information — need practical safeguards, not paperwork for its own sake. Software providers with access to that data carry processor responsibilities, and we help you meet them in the systems themselves.
The personal data lifecycle
What we do
Four service areas- 01Controller & Processor MappingClarifying who decides about personal data and who processes it on their behalf, across your systems and vendors.
- 02Protection AssessmentsHow personal data flows through your applications, where it rests, who can reach it, and where the gaps are.
- 03Privacy & Security ControlsAccess control, audit trails, encryption and retention — implemented in the software, not just written in a policy.
- 04Policies & DPIA SupportSecurity policies and the technical input a data protection impact assessment needs.
Controller & Processor Mapping
The first question is not technical: who decides about personal data, and who merely processes it on someone else's behalf? Get that wrong and every downstream obligation is attached to the wrong party.
As controller
You decide the purposes and the means. That carries a lawful basis and purpose limitation — the obligation to only process data for a reason you can point to, and only for that reason.
As processor
You act on another party's instructions. That carries contract terms and security duties instead — what you are required to do with the data while you hold it.
Protection Assessments
Reviewing how personal data flows through your applications, where it rests, who can reach it, and where the gaps are — reported plainly, in priority order rather than as a wall of findings.
Where it enters
The forms, imports and integrations that bring personal data into your systems in the first place.
Where it rests
The databases, file stores and backups holding it, including the copies nobody remembers making.
Who can reach it
Roles, shared accounts and service access — which is usually where the gaps are.
Where it leaves
Exports, third-party services and vendor transfers, and what happens to it once it is outside.
Privacy & Security Controls
Implemented in the software rather than written in a policy and hoped for. A control that is not in the system is not a control.
Access control
Enforced in the application and the data layer, not only described in a document.
Audit trails
Who accessed or changed personal data, and when — answerable after the fact.
Encryption at rest & in transit
Applied where the data actually sits, including backups and exports.
Retention handling
Personal data is removed when it should be, rather than kept indefinitely by default.
Policies & DPIA Support
Security policies and the technical input a data protection impact assessment needs: what the system actually does with the data, where it lives, and who can reach it — the evidence an assessment depends on.
Security policies
Written against what your systems actually do, so they can be followed.
DPIA technical input
The engineering evidence your DPO or counsel needs to make the legal call.
Security awareness
For the people who handle the data day to day, which is where most of it goes wrong.
Technical support, not legal advice. We supply the engineering and operational evidence your DPO or counsel needs to make the legal calls. The legal interpretation — lawful basis, consent, whether a processing activity is proportionate — is theirs, not ours.
Handling personal data?
Tell us what you process and where it lives. We will map the flows, name the gaps and prioritise the fixes — in the systems, not on paper.