Privacy
GDPR representative under Article 27. Authority letters are always included, never metered.
$0
at 25 data-subject requests · 25 included
One intake for every data-subject request, one register of what you process and who you share it with, and a named Article 27 representative on record for the authorities. Built for companies that owe Europe something and have no entity there.
A hosted intake on your own privacy page, identity verification, routing to the systems that hold the data, and a clock on every request from the day it lands.
What you process and why, who you share it with, and the assessments behind the risky parts — the Article 30 record a supervisory authority asks for first.
A named Article 27 representative at an EU address, on your privacy notice and on record with every authority. The part of this you cannot do yourself from outside the EU.
From your privacy page, an email address, or the embedded SDK. Whichever regime it comes under, it arrives in the same inbox with the deadline that regime sets.
Identity checks before anything is disclosed, because handing someone else's data to an impostor is itself a breach.
The request is routed to the systems that actually hold the data, each with its own task and its own record of what came back. On Pro that routing runs itself.
An approval step before anything goes out, then a closed request with the full trail — what was asked, what was found, what was sent, and when.
// Access request · GDPR Art. 15 Received 14 Mar · via privacy page Verified 14 Mar · email + account match Due 13 Apr (one month, Art. 12(3)) Systems 6 queried · 6 returned crm · billing · support product · analytics · backups Approved 21 Mar · Elena Hoffmann Sent 21 Mar · encrypted bundle Closed 7 days before deadline
A European request and a Californian one differ in what they are called, what they oblige and how long you have. They do not need two inboxes, two processes and two sets of evidence.
Each regime brings its own request types and its own deadline. The intake applies the right one and the clock counts down accordingly. All fifteen are included in the fee — there is no per-regime charge.
Every processing activity with its purpose, its lawful basis, the categories of people and data, who receives it and how long you keep it. The first document requested in almost every investigation.
DPIAs for the processing that needs one, kept against the activity they assess rather than in a folder nobody opens, so the assessment and the activity cannot drift apart.
The register of who else touches the data, with the agreement behind each one and a public list on your privacy page that updates when the register does.
Where personal data physically goes and under which mechanism — adequacy, standard clauses, binding corporate rules or a derogation — drawn from the systems you have connected.
If you process the personal data of people in the EU and have no establishment there, Article 27 requires you to appoint a representative inside the Union. We become yours: a named entity at an EU address, published in your privacy notice, reachable by any supervisory authority and by any person whose data you hold.
Authority correspondence is handled for you and is never metered — a letter from a regulator is not a volume event.
Learn more about the Article 27 mandate →GDPR representative under Article 27. Authority letters are always included, never metered.
$0
at 25 data-subject requests · 25 included
In the fee
This is on top of your platform plan, which starts at $0. See every price →
If users post or trade on your platform — the Article 13 legal representative and the notice endpoint.
When Article 37 requires a named DPO, chosen from the marketplace at a published rate.
The public side of all this: policies, the request intake and the sub-processor list, on your own domain.
The representative is part of it. Privacy is the product: the request intake, the register, the data map and the Article 27 mandate together. If all you need is the mandate itself, that is the piece described on the GDPR Representative page — but it is bought as Privacy either way.
One request from one person, whatever they ask for — access, erasure, correction, portability, objection. Twenty-five a month are included; above that each one is priced at its own tier. Correspondence with a supervisory authority is not a request and is never metered.
Not to start. You can run requests by hand against the systems you list, and the record is the same. Connecting systems is what lets a request be routed and answered without someone chasing six teams, and it is what the Pro plan automates.
Yes, though the overlap is usually the point. What a privacy tool cannot do is be your representative: Article 27 requires an entity established in the Union, which is why companies outside it end up with a tool and a separate mandate. This is both.
Different role, different article. The representative is your point of contact inside the EU under Article 27; a DPO under Articles 37 to 39 is an independent officer who advises and monitors, and is required only for certain kinds of processing. Many companies need both, and Article 38(6) is why the same person should not be both.
The mandate ends on 30 days' notice, and we tell the authorities it has. Until it does, you stay covered: an Article 27 representative cannot lapse quietly without leaving you in breach.
Thirty minutes to map what you process and where it sits. A named representative on record the moment you sign.