See it in action.

Nine real screens from the product — what privacy operations look like when AI drafts the routine work, your team signs off, and every step lands in an append-only trail with proof a regulator can check for themselves.

1. Home dashboard

The whole privacy program, on one screen.

Open the app and immediately see what needs attention: open DSARs ticking down to their deadline, escalations waiting for review, vendor reviews coming due, and the month's Q&A volume.

  • Color-coded DSAR tile turns red when something is ≤ 7 days from deadline.
  • Latest three escalations preview right on the home screen.
  • Trial banner + onboarding checklist for fresh workspaces.
app.privacyautomated.ai
Q&A this month
142
125 answered with citations
Inbox
7
awaiting review
Open DSARs
4
1 overdue
Vendors
23
3 review due

Latest escalations

Can we send customer emails to MailBlast? jane@acme · 2h
Does GDPR require encryption at rest? sales@acme · 5h
Are we allowed to use OpenAI for support chat? eng@acme · yesterday
2. AI Q&A

Grounded answers, with receipts.

Type a privacy question. The assistant retrieves the relevant paragraphs from your uploaded policies and approved-vendor inventory, drafts an answer, and shows you exactly which sources it leaned on.

  • Composite confidence (retrieval × LLM self-confidence × citation validity).
  • Low-confidence or out-of-policy questions escalate to your privacy team automatically.
  • Built-in prompt-injection and conflicting-intent detection.
app.privacyautomated.ai/ask
Ask →
Answered 3 citations · Confidence 87%

Drew on: 4 chunks from your documents · 3 cited

Yes, with the existing DPA on file. Acme Analytics is listed as an approved processor for product-usage telemetry under your Vendor Privacy Policy (last reviewed Jan 2026).

  • Data residency: EU only. Confirm your Acme tenant is in the eu-central-1 region.
  • Retention: 13 months, per your retention schedule.
  • Special categories: not permitted.
Sources: Vendor Privacy Policy §3.2 · Approved-Vendor Inventory (Acme Analytics) · Retention Schedule v2
3. Escalation inbox

Review, edit, approve — one click.

When the AI isn’t confident or detects a conflicting intent, the question lands in your inbox with a draft answer pre-written. Review the source citations, edit if needed, and approve.

  • Intent chips flag prompt-injection, conflicting requests, hard-blocks.
  • Independent judge model verifies every draft — its note appears below.
  • Markdown-rendered draft so structured AI output reads cleanly.
app.privacyautomated.ai/inbox
Conflicting intent Confidence · 42% (Medium) From sales@acme · 1h ago
"We want to delete a customer's record but also keep their order history for tax purposes. Can we?"

AI draft answer

You have two conflicting requirements here — the right of erasure (GDPR Art. 17) and a statutory retention obligation (typically 6–7 years for tax records). Both can co-exist:

  • Erase personal identifiers (name, email, address) from the customer record.
  • Retain the order history with the personal identifiers redacted (a pseudonymous customer ID is fine).
  • Document the legal basis for retention in your Records of Processing under "tax compliance".
Judge: ✓ Verified. Cites correct article and identifies both lawful bases.
3 citations · Markdown rendered
Reject Edit Approve →
4. DPIA & risk register

Article 35 in ten minutes, not ten hours.

Describe a new processing activity in plain language. The AI drafts an Article 35-defensible DPIA with screening, scored risks, and mitigations. You review and approve.

  • 3×3 likelihood × severity heatmap with numbered chips that jump to the matching risk row.
  • Inline editing on every field.
  • Approved DPIAs sync into your RoPA (Records of Processing) automatically.
app.privacyautomated.ai/assessments/42

Customer support AI assistant — DPIA

DPIA required: Yes · Residual risk: Medium · Status: Approved

Risk heatmap

1
3
5
24
# Risk L S Status
1 Stored chat logs include incidental PII Low Low Mitigated
2 LLM provider data residency outside EU Med Med Owner
5 Prompt injection extracts other tenants' data High High Active
5. Vendor management

Onboard a vendor by URL. Score the risk. Keep it current.

Paste a vendor’s website and the AI reads their public privacy, trust, and DPA pages, then pre-fills the record with quoted, sourced suggestions — you review every one before it saves. Each vendor lands with an explainable risk tier and a review date that nudges you when it comes due.

  • Deterministic High / Medium / Low score with a “why” breakdown — no black box.
  • Review reminders feed the weekly digest and the home dashboard automatically.
  • Send a hosted due-diligence questionnaire; concerning answers get flagged for you.
app.privacyautomated.ai/vendors

Approved-vendor inventory

23 vendors · 3 reviews due · 1 questionnaire awaiting response

Vendor Risk DPA Review
Acme Analytics
sensitive data · sub-processors
Medium · 53 Signed Due 14d
MailBlast
EU transfer · no DPA on file
High · 78 Missing
Databricks
SOC 2 · EU region
Low · 8 Signed Apr 2027
✨ Auto-fill from website

“Cloudflare processes personal information on behalf of its customers under a Data Processing Addendum.”

Source: cloudflare.com/dpa · processing role → Processor

Applied 2 suggestions from 4 pages. Review before saving.

6. DSAR routing

From inbound email to closed request, with the regulatory deadline enforced.

The AI classifies an inbound email as a deletion / access / portability / opt-out request and starts the verification flow. Once you verify the requester’s identity, every department that holds their data gets a tokenized link to confirm what they hold and take action.

  • Five-step lifecycle stepper across every DSAR.
  • Per-DSAR fan-out to your configured department contacts.
  • Aggregate completion email back to the requester when every team has responded.
app.privacyautomated.ai/dsars/91

Deletion request — Sarah Kim

sarah.k@example.com · Received 2026-05-19
4 days left
Received
Verified
3
Routed
4
Responses
5
Closed

Department fan-out · 2 of 5 responded

Sales
sales-ops@acme.com
✓ No data held
Engineering
eng@acme.com
✓ Deleted
Marketing
marketing@acme.com
Emailed · 1d ago
Finance
finance@acme.com
Reminded ×1
HR
people@acme.com
Pending
7. Conflict flag & sign-off

The AI surfaces the tension. You sign it off.

When a DSAR has cross-jurisdictional friction — a deletion request meeting a litigation hold, a portability request running against an IRS retention rule — the AI drafts a flag: the relevant statutory texts, the customer-authored facts, and a verbatim line that the obligations interact and resolution is the human’s. It cites only from a closed, curated corpus of statutory text we maintain, scoped to your jurisdiction — the AI can pull references from it but cannot invent them — and a qualified human signs off before anyone acts on it.

  • Schema-level guarantee: no signed-off determination can land without an authenticated user id and a non-empty citations array.
  • Closed citation menu — the AI cannot invent a statute reference; the validator rejects any id not in the corpus.
  • Every draft requires a qualified human’s sign-off (Invariant 12) before it can be acted on — it describes, it never concludes.
  • Audit chain records the signing user, the draft it came from, and the prompt+hash that produced it.
app.privacyautomated.ai/determinations/drafts/…
Draft — awaiting sign-off

Cross-jurisdictional conflict flag

DSAR · open the source record →
AI-authored draft. Generated from a closed, curated corpus of statutory texts. Cannot be acted on until you sign off (Invariant 12).

Controlling texts

  • GDPR Art. 17(3)(e) names a carve-out from the deletion right for legal claims.
  • FRCP 37(e) creates preservation duties once litigation is reasonably anticipated.

Observed facts

  • A litigation-hold marker is set on this subject (set 2026-04-12).
  • Your retention policy cites IRS §6001 for related business records.
Interaction statement
These obligations interact; resolution is yours.
Proposed citations
GDPR Art. 17(3)(e) EU-DE FRCP 37(e) US-FED IRS §6001 US-FED
Promote — I sign off Reject…
8. AI Governance

Classify your AI under the EU AI Act — and draft the paperwork.

Add an AI system you build or use. The AI classifies it against the EU AI Act, names the obligations that follow, and drafts the documents they require — seeded from your existing DPIAs, RoPA, and vendors, and editable in-app to a final version.

  • Risk tier and triggered obligations, each cited to the Act — a human signs off before the classification counts.
  • One click drafts Annex IV technical docs, Article 50 transparency notices, and Article 27 FRIAs.
  • Record the models behind each system; if a model version or a vendor’s terms change, the classification is flagged for re-review.
app.privacyautomated.ai/ai-systems/…

Résumé screening assistant

Role: Deployer · Risk tier: High-risk (Annex III) · Signed off

Triggered obligations

  • Annex IV technical documentation Drafted
  • Article 50 transparency notice Draft
  • Article 27 FRIA Drafted

Models

claude-opus-4-8 · Anthropic · v4.8

🔐 Evidence packet Re-classify
9. Evidence a regulator can verify

One click. A regulator can verify it without an account.

Close a DSAR — or approve a DPIA, seal a RoPA snapshot, or sign off an AI-system classification — and produce a sealed evidence record. Hand it to a regulator or auditor and they confirm it’s authentic and unaltered themselves, no account required. The same record prints to PDF for the binder.

  • Public verifier — the regulator pastes the file in and gets a plain-language verdict: authentic, sealed on this date, for this controller.
  • Tamper-evident: change one character and verification fails, so “this is the record we gave you” isn’t a matter of trust.
  • Works for DSARs, DPIAs, RoPA snapshots, AI-system classifications, and point-in-time posture seals.
  • Want the cryptographic details? They’re all on the engineering trust page.
app.privacyautomated.ai/dsars/…

Signed evidence packet

Sealed

A regulator-facing record of this DSAR — every step, the verification trace, and the completion proof. Verifiable by anyone you hand it to, no account needed.

📄 Open printable evidence (PDF via Cmd+P) ⬇ Download record
Paste it into the public verifier →
“This record is authentic, sealed on 21 Jun 2026 for Acme Ltd.”

See it on your own data.

Sign up free, upload one privacy policy, ask the AI a question about your actual workflow. Takes about three minutes.

Start free 14-day trial

No credit card required · Drops to Free after, your data stays