Privacy & Compliance (GRC)

Most privacy risk sits in your marketing tags, not your policy page. We map what you actually collect, where it goes, and what to fix first.

Almost every privacy policy we read describes a company that doesn't exist.

It says data is collected with consent. Meanwhile the pixel fires before the banner loads. It says data isn't shared with third parties. Meanwhile eleven scripts on the checkout page are sending events to ad platforms. It says data is kept only as long as necessary. Nobody has ever deleted a row.

The gap between the policy and the tag manager is where enforcement actually happens.

Where We Start: The Data Map

Not a questionnaire. An inventory of what your systems are genuinely doing.

  • What personal data you collect, at which touchpoints, in which fields
  • Where it lands — CRM, analytics, ad platforms, email tool, helpdesk, spreadsheets, someone's inbox
  • Which third parties receive it, and whether they were ever supposed to
  • Who internally can reach it, and whether that's still appropriate
  • How long it's kept, and whether anything ever deletes it
  • Where it crosses a border, and under what mechanism

Most findings come out of this stage. It's unglamorous, and it's the whole engagement.

The Tracking Layer

This is the part general privacy consultants skip, and the part that gets companies fined.

  • Consent mechanics: whether tags respect the banner, or just wait politely and fire anyway
  • Consent Mode, server-side tagging and Conversions API setups, reviewed for what they actually transmit
  • Identifiers and hashed data sent to ad platforms, and whether your legal basis covers it
  • Form fields and URL parameters leaking sensitive values into analytics
  • Healthcare specifically: tracking technology on booking, symptom and portal pages — the single most enforced area in US health privacy right now

We've built HIPAA-conscious tracking infrastructure for live healthcare clients. This isn't theory for us.

Vendors, Policies and Evidence

  • Processor and sub-processor review, and whether your agreements match what those vendors are doing
  • Records of processing, retention schedules, and a data subject request process that works when the request arrives
  • Incident response and breach notification procedures, tested rather than filed
  • A policy set written to your operations, not copied from a template naming a company you're not
  • Gap assessment against the frameworks you're actually held to: GDPR, CCPA/CPRA, HIPAA, ISO 27001, SOC 2, PCI DSS scoping

What You Get

A prioritised remediation plan. Every finding rated by regulatory exposure and effort, with the fixes that take an afternoon separated from the ones that take a quarter — so it becomes a list you work through, not a document you file.

Readiness, Not Certification

We get you audit-ready. We are not an accredited certification body and won't pretend otherwise. For ISO 27001 or SOC 2, an independent auditor issues the certificate. Our job is making sure you walk into that engagement without surprises.

Questions We Get Asked

We're a small company. Does GDPR really apply to us?
Company size isn't the test — whose data you process is. If you have EU visitors and you run analytics or ads, you're in scope. Enforcement against small companies is less common, but the exposure is real and the fixes at your size are usually cheap.

How long does an assessment take?
Two to four weeks for most mid-sized companies, depending on how many systems touch personal data and how fast we get access.

Can you just write us a privacy policy?
We can, but a policy that doesn't describe your real data flows is worse than no policy — it's a written admission. We map first.

Ready to take the first step?