Products · DMS · GDPR, security & audit

GDPR as a feature,
not a worry.

Subject access requests with tracked deadlines, permissions that change automatically when someone’s role does, safeguarding records sealed from everyone outside the team — and an audit trail that shows every decision, ready for inspection.

DSR
Requests as workflows
Field
Level permissions
Full
Audit trail, every action
Sealed
Safeguarding records
Trust, by design

Three things the DPO stops chasing.

The obligations become workflows, the access model becomes policy, and the evidence writes itself.

Data subject requests, managed.

Subject access, right-to-erasure and right-to-correction requests logged, typed and tracked to completion — each with its statutory deadline visible, not remembered.

Permissions follow the job.

Route, resource, dashboard, report and field-level permissions, managed in a visual matrix editor. Because access is tied to job categories, it changes automatically the day someone’s role does.

The audit trail is the answer.

User actions, role transitions and system events recorded throughout. “Who changed this, and when?” is a lookup — not an investigation.

In the detail

Defence in depth, by design.

The controls an ICO auditor would ask about, built into the same system the teams work in every day.

Retention policies

Configurable rules for how long each kind of data is kept — policy-driven deletion instead of “we’ve always kept everything”.

Access review campaigns

Periodic recertification of who can see what, with sign-off recorded — the access model stays deliberate as staff and roles change.

Team visibility, deliberately

Engagement records scoped by team, with a purposeful cross-team summary layer — colleagues see that contact happened without seeing what shouldn’t travel.

Safeguarding sealing

The allegations register and CDM casework are invisible outside the safeguarding team — in the same platform, behind a hard wall. See safeguarding →

Email governance

Bulk-email permissions and rate limiting — nobody accidentally emails every contact in the diocese on a Friday afternoon.

PII never reaches the AI

Phone numbers, NI numbers, postcodes and emails are redacted before any AI call, and the assistant only sees what the logged-in user can. How the privacy guard works →

An inspection-ready system isn’t one with a policy folder — it’s one where the policy is how the software behaves.
— See also: the GDPR answer in the DMS FAQ · our data processing statement
Next step

Bring your DPO’s
hardest question.