Who gets in, what they touch, what stays on record.
The platform helps you apply your policies and document processes. It doesn't replace legal review or good internal organization.
Access
Roles, proportionate permissions, session control and data separated per organization.
Record
Relevant actions are noted with person, moment and context.
Data
Export, correction, retention and deletion prepared from day one.
Operations
Providers, backups and responsibilities get documented as the service is defined.
What the platform covers and what stays with you
The regulation places obligations on your organization, not on our software. This is what the platform handles on its side, article by article.
Data subject rightsArts. 15-22 GDPR
Access, rectification, erasure, restriction, objection and portability are executed from the person's record, with export in an open format.
Technical and organisational measuresArt. 32 GDPR
Access control by role and module, data separated per organization, session management and least privilege applied by default.
Record of processing activitiesArt. 30 GDPR
The configuration of modules, fields, permissions and retention is documented and exportable to feed your own record.
Processing agreementArt. 28 GDPR
We sign the data processing agreement: instructions, purposes, sub-processors, measures and return or deletion at the end.
Personal data breachesArt. 33 GDPR
A notification procedure to the controller so your organization can report to the authority within 72 hours.
Minimisation and retentionArt. 5 GDPR
Only the fields you configure are collected, with retention periods agreed by data type and deletion once they expire.
What stays yours: defining purposes and legal bases, informing data subjects, maintaining the record of processing, appointing a data protection officer where required and running impact assessments when the regulation demands it. We support you there, we don't replace you.
Organitz.art does not on its own guarantee GDPR or LOPDGDD compliance. The organization remains the data controller: purposes, legal bases, retention and recipients are defined by you.
Tell us how your organization runs and we'll show you what it would look like set up. Half an hour, no slides.