// Platform

One connected,
auditable platform.

Assessments, records of processing, data agreements, vendors, subject requests, and audit evidence — running together, referencing each other, governed by construction.

Governed by constructionEvidence is captured as the work happens — not reconstructed at audit time.
Connected, not siloedEvery module references the others: a vendor links to its DPA, its transfers, its assessments.
Audit-ready continuouslyEvidence is collected and reviewed on a cadence, so the answer to "prove it" is already on file.
// The six modules

Every obligation has a home.

PIA / DPIA

Assessments generated from structured intake, scored for risk, and routed through approval workflows. Every assessment is versioned and linked to the processing activities, vendors, and transfers it covers.

  • Risk scoring with configurable thresholds
  • Approval workflows with named owners
  • AI use-case triage for new features
  • DPIA triggers flagged automatically from intake

Assessment · AI chat intake

Data sensitivityHIGH
Novel processingMED
Transfer exposureMED
Mitigations applied7 of 9
ApprovalWith DPO

RoPA

A continuously maintained map of processing activities — systems, purposes, lawful bases, retention, and transfers — that updates as the business changes instead of going stale in a spreadsheet.

  • Living Article 30 record, always export-ready
  • New activities detected from connected systems
  • Lawful basis and retention tracked per activity
  • Transfers linked to mechanisms and TIAs

Records of processing

Patient intake & schedulingContract6 systems
Model training & evaluationLegit. interest4 systems
Marketing analyticsConsent3 systems
Claims processingLegal duty5 systems

DPA Review

Data processing agreements parsed by Clause AI against your playbook — standard contractual clause checks, missing-term flags, and redline-ready output. Every reviewed agreement files itself against its vendor.

  • Clause AI parsing against your positions
  • SCC module checks with gap flags
  • Redline-ready output for counsel
  • Linked to vendor records and transfers

Clause AI · CloudCRM DPA

Sub-processor noticePass
SCC Module 2 annexPass
Breach notice window72h → 48h flag
Audit rightsReview
Deletion on terminationPass

Vendor Risk

A third-party inventory with risk scoring and remediation tracking — which processors touch personal data, what they signed, where they send it, and what still needs fixing.

  • Inventory with data-touch classification
  • Risk scoring across security and privacy posture
  • Remediation tracking with owners and dates
  • Renewals and DPA gaps surfaced before they bite

Vendor register

CloudCRM Inc.DPA signedLOW
AdMetrics LabsDPA missingHIGH
ModelServe AIIn reviewMED
SurveyLoopRenewal dueMED

DSAR

Rights requests tracked from arrival to answered — intake, identity verification, system-by-system data location, and response drafting, with every statutory clock counted down automatically.

  • Access, deletion, correction, portability
  • Identity verification before the clock burns
  • System-by-system location checklists
  • Deadline clocks per statute, tracked to the day

Request queue

REQ-4192D. FontaineDeletion29d left
REQ-4191J. OkaforAccess10d left
REQ-4190L. NovakPortability20d left
REQ-4189M. ChenVerifying33d left

Evidence

Policies, training logs, approvals, and audit artifacts in one governed library — collected and reviewed on a cadence, so nothing expires quietly and nothing has to be hunted down under audit pressure.

  • One governed library, tagged to obligations
  • Review cadences with owners and due dates
  • Expiry warnings before artifacts go stale
  • Exportable audit packages on demand

Evidence library

Privacy policy v4.2Current
Incident response planReview due
Q3 training logCurrent
SCC Module 2 annexIn review
// Trust & security

Built to hold your most sensitive records.

A privacy platform has to clear its own bar. Security posture summary — full documentation available under NDA to early-access teams.

Encryption

Data encrypted in transit (TLS 1.2+) and at rest. Keys managed and rotated on a defined schedule.

Access control

Role-based access with least-privilege defaults, SSO/SAML support, and full administrative audit logs.

Compliance roadmap

SOC 2 program underway with early-access customers as design partners; BAAs available for health-tech deployments.

// Early access

Be first on the console.

PrivacyPoint is onboarding a limited group of early-access teams. Leave your email and we'll reach out with a working demo.