Trust hub · Hosted privacy operations

Your privacy page, your way.

A hosted trust hub at privacy.yourdomain.com: unified DSR inbox, versioned policies, auto-updated sub-processor list, and an incident + certifications log. Customers see a serious operator. Regulators see a responsive one.

Why teams buy Privacy Center

One place for everything privacy.

01

Stop answering security questionnaires by hand.

Enterprise buyers open privacy.yourco.com and half their questions are already answered — policies, sub-processors, certifications, incident log, all versioned and timestamped. Your sales cycle gets its week back.

02

Turn DSRs from a backlog into a flow.

Identity-verified requests land in a real inbox with SLA timers, language detection, and one-click responses. Nobody's Gmail thread. No missed deadlines. No "who's handling this?" Slack messages at 9pm.

03

Show regulators and buyers the same page.

The trust hub your CNIL case officer sees is the same one your largest prospect's procurement team sees. Consistent, archived, audit-ready — and the second layer of your compliance posture after representation.

What you get

A centralized privacy control center that puts customers in charge.

01

Hosted privacy hub

A branded page at privacy.yourdomain.com — serves your policies, DSR intake and certificates from one surface.

02

Unified DSR inbox

Access, erasure, rectification, portability, restriction, and objection requests all route to one verified inbox with deadline tracking.

03

Policy library

Store all your policies in one place, publish them to your Privacy Center, and maintain a full version history so you always know what changed, when, and why.

04

Certifications management

Publish your compliance certifications on your public Privacy Center so prospects can verify your status instantly, no more PDFs on request.

05

Identity verification

Fraudulent DSRs waste your team's time and expose you to risk. EU Presence verifies every requester's identity automatically so you only respond to legitimate requests.

06

Powerful analytics

See how many requests you've received, which regulations they fall under, and how quickly your team is responding, all in one dashboard.

Preview

Looks like this, out of the box.

Give your users a branded portal to submit data requests, verify their identity, and access your privacy policies while you stay compliant without lifting a finger.

privacy.acme.com Live preview
DSR Requests
Policies
Sub-processors
Incidents

Open DSR requests

6 open · 142 resolved this quarter
DE
Subject access request · anna.m@gmail.com
Opened 2 h ago · verified · source: web form
ACCESS ✓ In review
FR
Erasure request · lucas.d@orange.fr
Opened 8 h ago · verified · source: email
ERASURE ✓ Fulfilled
IT
Rectification request · sofia.r@fastwebnet.it
Opened 1 d ago · verified · source: web form
RECTIFY ⋯ Awaiting user
ES
Portability request · carla.v@yahoo.es
Opened 2 d ago · verified · source: DPA forward
PORTABILITY ✓ Fulfilled
NL
Objection · rik.v@xs4all.nl
Opened 3 d ago · verified · source: web form
OBJECTION ✓ Acknowledged
IDV
Identity verification, built-in

Every request is verified before it reaches you — no impersonation, no drive-by deletions, no manual email ping-pong.

SLA
Statutory deadline tracking

Art. 12's 30-day clock tracked per request, with early-warning at day 20 and automated escalation at day 27.

API
Webhook + API for your ops

Route requests into Jira, Linear, or your data warehouse. Every state change fires a webhook; full audit log available via API.

LOC
24 EU languages

Requests come in local language, routed to you with an English summary. Responses can go out in-language with one click.

SEC
SOC 2 + EU-hosted infra

Data residency in Frankfurt, SOC 2 Type II, ISO 27001, GDPR-native. Full sub-processor list on our own trust hub.

Analytics

See everything, at a glance.

Request volume, response time, SLA compliance, regulation mix, and team workload — in one dashboard you can drop in front of your board or DPA without prep.

Requests (last 30d)
142 +18%
vs. previous period
Avg response
2.1 h −34 m
Well under 30-day SLA
SLA compliance
100%
0 late, trailing 90 days
Fulfilled
138 / 142
4 in review

Requests by regulation

Last 30 days
GDPR92
UK GDPR26
CCPA18
LGPD4
PIPL2

Recent activity

  • Erasure fulfilled for lucas.d@orange.fr2h
  • Access fulfilled for anna.m@gmail.com4h
  • Rectify awaiting user response8h
  • Portability exported for carla.v@yahoo.es1d
  • Policy v12 published (cookies)2d
Integrations

Works with the stack you already run.

Route requests to the tools your privacy team lives in. 200+ native integrations on Pro, plus Zapier and a REST API for anything we don't cover.

Slack
Jira
Linear
Asana
Notion
Monday
Salesforce
HubSpot
Segment
Zendesk
Intercom
Front
Okta
Auth0
Google Workspace
Microsoft 365
GitHub
Webhook
Zapier
+ 180 more
How it works

Live in an afternoon, not a quarter.

  1. Connect your domain

    Add one CNAME pointing to cname.eupresence.com. We provision the TLS certificate, the subdomain, and the cookie propagation automatically.

  2. Import your policies

    Paste an existing policy, import from a URL, or start from our template library. We version it, timestamp it, and serve it at your branded subdomain.

  3. Embed the DSR widget

    One script tag on your site. Visitors submit requests via a branded form; we verify identity, log the request, and route it to your inbox.

  4. Go live & monitor

    Publish your trust hub. Every request, policy revision, and sub-processor change is archived with an audit trail regulators can inspect.

Two ways to integrate
// 1 · Drop-in embed for your marketing site
<script src="https://cdn.eupresence.com/dsr.js"
        data-tenant="acme"
        data-lang="auto"></script>

// 2 · REST API — for app-internal flows (Pro)
POST https://api.eupresence.com/v1/dsr
Authorization: Bearer $EUP_API_KEY
Content-Type: application/json

{
  "type":    "erasure",
  "subject": { "email": "user@acme.com" },
  "source":  "in-app"
}
Drop-in embed works on every plan. REST API + webhooks unlock on Pro — route requests into Jira, Linear, or your data warehouse and fire webhooks on every state change.
Built for your whole team

One surface. Four audiences.

LEGAL

Legal & privacy

  • Versioned policy library with full diff history
  • DSR workflow with 30-day SLA tracking
  • Exportable audit log, regulator-ready
ENG

Engineering

  • One-CNAME setup — no infra to maintain
  • REST API + webhooks for every state change
  • SSO, SAML, audit log streaming
OPS

Privacy ops

  • Assign requests to owners, track response time
  • Workflows for erasure, portability, access
  • Dashboard for volume, SLA, regulation mix
GTM

Sales & success

  • Public trust hub cuts security-q&a cycles
  • Verified certifications on display
  • Permalinks to drop into RFPs and MSAs
Proof

Teams running privacy like product.

From pre-launch startups to enterprise buyers, teams adopting a hosted trust hub ship faster, sell to bigger customers, and sleep better.

"We went from handling DSRs in Gmail threads to a real inbox with SLAs and verification. Night and day."
Derek Kim Head of Ops · D2C brand, EU-only
"CNIL asked for our privacy notice and ROPA. The trust hub had both versioned and timestamped. Ten-minute reply."
Maya Aro CTO · AI tools startup
"The sub-processor auto-notify alone pays for this. Our customers stopped asking us who moved what, and when."
Theo Lange GC · Enterprise SaaS, 3 continents
1,200+Trust hubs live
2.1 hAvg DSR response
< 1 dayTime to go live
99.98%Uptime, trailing 12 months
Pricing

Start free. Scale when you need more.

Free
$0/month
Forever · no credit card

Everything a small team needs to publish a real privacy page and start handling DSRs on day one.

Included
  • 10 privacy requests / month
  • Custom branding
  • Unlimited users
  • Unlimited entities
  • Basic chat & email support
Start free →
Most chosen
Plus
$57/month
Month-to-month · cancel anytime

For growing companies with real volume — integrations, workflows, and a custom domain.

Everything in Free, plus
  • 100 privacy requests / month
  • 5 integrations
  • 1 workflow
  • Custom domain
  • Assign privacy requests to team members for faster fulfillment
Start 14-day trial →
Pro
$147/month
Unlimited volume · API access

For scaled privacy ops — unlimited everything, 200+ integrations, and API access.

Everything in Plus, plus
  • Unlimited privacy requests
  • 200+ integrations
  • Unlimited workflows
  • API access
  • Multi-language support for policies
Talk to sales →
Often purchased together

Companies who take Privacy Center also take.

Common questions

What teams ask us first.

Does Privacy Center replace my existing privacy policy?

It hosts, versions, and serves it. You can bring your existing policy, start from our template, or we can redline yours. The difference is every visitor is served the version that applied on their visit date — and that archive is regulator-ready.

How does the DSR inbox verify identity?

Email challenge plus optional stronger signals (magic link, phone OTP, or enterprise-SSO for B2B). You can tune the verification level per request type — access requests are lighter, erasure requires stronger proof.

Can we self-host or use our own domain?

You use your own subdomain (privacy.yourcompany.com) by default — one CNAME. Fully self-hosted is available on Enterprise for regulated-industry customers who need it.

Does Privacy Center include a cookie consent banner?

Not yet. Cookie consent is on the roadmap but isn't live today. Most of our customers run a dedicated CMP — Cookiebot, Usercentrics, OneTrust — alongside Privacy Center and we integrate with any of them. The four surfaces we do cover today (DSR inbox, sub-processor registry, policy library, incident log) are where most compliance work actually lives.

Do you handle regulator correspondence?

If you also have our GDPR Representative engagement, yes — we respond in-language to every DPA inquiry and log it in your trust hub. Privacy Center alone gives you the surface and archive; representation is a separate product.

What happens if we leave?

Full export of every policy version, DSR record, sub-processor change, and incident entry — plus a JSON dump of your raw data. 30-day termination, no punitive clauses, you keep everything.

Ship privacy, Monday.

30-minute discovery call. Trust hub provisioned inside a day. A real privacy page, DSR inbox, and sub-processor registry, live by end of week.