Privacy and data control
Keep sight of purpose, retention, deletion and handover
This page describes which roles, purposes, data categories, retention, deletion, export and request handling must be established for each future customer implementation. It is not yet a legally reviewed customer data flow.
Intended delivery
Objective for each implementation: define and review ownership, purpose, location and end point before processing.
Evidence required before delivery
- Required before production: a customer- and provider-specific data table, role allocation and retention schedule.
- Required before publishing privacy claims: legal review of lawful basis, contracts and request handling.
- Current product boundary: adapter 1.1.0 is locally tested on 150 + 120 frozen records, with zero external actions.
Authority boundary
What this solution explicitly does not promise
- 01
No blanket claim that a solution is automatically GDPR compliant.
- 02
Processing roles and lawful basis are established for each customer workflow.
Next step
Start with one provable workflow.
No generic AI presentation. Bring volume, systems, exceptions and the human decision-maker.