Privacy automation

End-to-end privacy automation

Relyance builds your ROPA, subject requests, assessments, consent records and data map from how data really moves, and keeps them current when anything changes.

ROPADSRAssessmentsConsentData Map
activities
35
no legal basis
3
filled in for you
92%
activityMarketing AnalyticsGoogle Marketing Platform · 46 subprocessorsnew
activityCustomer support assistantZendesk · Consumersbasis set
activityApplication DevelopmentAnthropic · Account balance and 24 moreno basis
activityData StoragePostgreSQL · Database credentialssensitive
activityBusiness IntelligenceAmazon Web Services · Engineeringup to date
A new activity is added the day a new tool starts getting data.
Purpose and legal basis are filled in from how the data is used.
An activity with no legal basis is flagged for the privacy team.
Sensitive data in an activity is marked for a closer look.
Records stay current as systems change. No spreadsheet to update.
open requests
41
need attention
6
average time
4 days
deleteKeri SutherlandCustomer · Waiting on a manual stepmanual task
accessBrenda SimsCustomer · Data found in 4 systemsneeds approval
accessFernando ColemanCustomer · Report sentcompleted
accessJessica PateCustomer · Duplicate requestcanceled
deleted***@northline.coCustomer · Running in 4 systemsin progress
Requests come in through one form and are checked before work starts.
Access requests pause for a person to approve before data is sent.
Data is collected from every system and sent back with a full log.
Duplicate requests are closed with the reason on file.
Deletion runs in every system that holds the person's data.
in progress
5
need review
2
filled in for you
80%
dpiaAmplitudeAnalytics integration · 22 data typespre-filled
dpiaAdobeUsing Adobe · Started May 28in progress
vendorClearwater AnalyticsVendor review · 3 questions leftneeds review
vendor&WalshVendor review · Signed by legalcomplete
templateAI vendor privacy & securityMade from an uploaded PDFnew
Answers come from the data map, so the form starts mostly done.
Each assessment is linked to the project or vendor it covers.
Questions only a person can answer go to the right owner.
Finished reviews are signed and saved as proof.
Upload a policy or questionnaire and get a template from it.
trackers found
20
not approved
2
purposes
5
cookie_gaGoogle Analytics · Analyticsapproved
scriptfacebookFacebook · Marketingneeds consent
storagecheckout_flow_stateShopify · Needed for checkoutalways on
beaconhotjarHotjar · Added without approvalblocked
signalGlobal Privacy ControlBrowser opt-out · All purposeshonored
Every cookie and tracker on your site is found and sorted by purpose.
Marketing trackers wait until the visitor says yes.
Trackers the site needs to work stay on, with the reason recorded.
A tracker added without approval is held back until reviewed.
Opt-out signals from the browser are respected and logged.
assets
1,746
unprotected
56
data classes
60
tableBOUTIQUE_CUSTOMERSCard numberEmail+8unmasked
tableBOUTIQUE_FINANCEBank accountEmail+7protected
flowStripecheckout_serviceAPI keysBilling+7new flow
flowGoogle BigQueryhris pipelineBank accountSalary+9exposed
bucketAmazon S3Full nameAddress+12Germanyin region
Personal data is found and labeled in every database and app.
Protected data, like tokenized fields, is recorded as safe.
A new flow between two systems shows up the day it starts.
Sensitive data that outsiders can reach is flagged.
The country where data is stored is shown for every asset.
Every record above is built from our
Discovery & classification
Live data map
Policy center

What you get

A ROPA that matches how you really use data.

Records are built from your live systems and update when they change. No interviews and no spreadsheets that go out of date.

Answer subject requests in days, not weeks.

Relyance knows every system that holds a person's data, so access and deletion run across all of them with a log attached.

Launch new features without waiting on privacy.

New data use is caught early and opens an assessment that is mostly filled in, so reviews take minutes.

CAPABILITIES

Build every record from real data

Relyance reads your code, cloud and apps to learn where personal data lives and where it goes. Your records start from that, not from interviews.

Found automatically

Databases, apps, vendors, cookies and data flows are found without anyone filling in a form.

Always current

When a system changes, the records that depend on it change too.

Linked to the source

Every entry points to the system or code it came from.

ropa · processing activityrelyance · live
A record written from how the data is really used, not from a form someone filled in.
activityMarketing Analytics
purposeMeasure campaign resultsfound in code
processorGoogle Marketing Platform
dataemail, device ID, location
peopleConsumers in the EU and US
basisLegitimate interestssuggested
shared with46 subprocessorsfound in traffic
Built from 3 live systemsupdated today
dsr · access requestrelyance · live
A request comes in. Each step runs on its own until a person needs to approve.
Brenda Sims asks for a copy of her data.
Send "request received" emailautomaticchecking…sent
Check identityemail and account matchchecking…verified
Collect datafrom 4 systemschecking…collected
Approval stepprivacy teamchecking…waiting
Day 1 of 45request · access data
assessments · new templaterelyance · live
Upload a policy or vendor questionnaire. A ready-to-use template is made from it.
AI vendor policy.pdfuploaded by the privacy teamreading…read
34 questions writtensorted into 6 sectionschecking…done
Linked to vendorssent when a vendor is addedchecking…linked
Answers filled infrom the data mapchecking…80% done
AI vendor privacy & securityready to send
consent · site scanrelyance · live
Every cookie and tracker on the site is found and sorted by what it is used for.
20
trackers found
2
not approved
5
purposes
_gaGoogle Analytics · cookiechecking…analytics
facebookFacebook · fingerprinting scriptchecking…marketing
checkout_flow_stateShopify · session storagechecking…necessary
hotjarHotjar · beaconchecking…not approved
relyanceconsent.comscanned today
data map · assetsrelyance · live
Personal data is found and labeled in every database, bucket and app.
1,746
assets
60
data classes
56
unprotected
BOUTIQUE_CUSTOMERSSnowflake · 500 rowschecking…card numbers
BOUTIQUE_FINANCESnowflake · 447 rowschecking…tokenized
Communication siteSharePoint · 9.8 MBchecking…bank accounts
DemoSiteSharePoint · 1 KBchecking…date of birth
7 clouds and apps connectedupdated hourly
ropa · missing legal basisrelyance · live
An activity with no legal basis goes to its owner, with an answer already suggested.
Application Development sends account balances to Anthropic with no legal basis on file.
Suggested basiscontract, based on how the data is usedchecking…suggested
Sent to ownerEngineering · Nishant Shahchecking…sent
Owner confirmsone clickwaiting…confirmed
Record updated2 of 35 left
dsr · review before sendingrelyance · live
Before data goes back to the person, sensitive fields are hidden and a reviewer signs off.
first_nameBrenda
last_nameSims
dateofbirth1942-03-29
driverslicensehiddenredacted
passporthiddenredacted
emailbrenda.sims@relyance.org
ReviewerJessica Patewaiting…approved
2 fields hiddensent to Brenda
dpia · amplituderelyance · live
Most questions are answered from the data map. People only confirm or fill the gaps.
Will personal data be used?answer: yeschecking…filled in
Which data types?22 found: email, IP address, location…checking…filled in
Does data leave the EU?needs a personchecking…assigned
Sign-offprivacy teamchecking…waiting
18 of 24 answers filled instatus · in progress
consent · rules by regionrelyance · live
Each region gets the consent rules its law asks for.
United Statesopt-out · banner shownchecking…set
European Unionopt-in · wait for a yeschecking…set
Global Privacy Controltreat as opt-out for every purposechecking…on
hotjarno approval yetchecking…blocked
Tested before going livepublished to site
data map · unprotected datarelyance · live
Sensitive data stored in plain text is flagged with who can read it and who owns it.
BOUTIQUE_CUSTOMERS holds card numbers in plain text. 16 people can read it.
Owner founddata platform teamchecking…assigned
Fix suggestedmask the card number columnchecking…suggested
Checked againafter the changewaiting…masked
55 left to fixBOUTIQUE_CUSTOMERS

Fix gaps before they become findings

When something is missing or risky, the right person is asked to fix it, with most of the answer already filled in.

Flagged with a reason

Each gap says what is wrong and which law it affects.

Sent to the right owner

The person who owns the system gets the task, not a shared inbox.

Checked after the fix

Relyance confirms the change actually happened.

Show proof whenever you are asked

Every action is saved with who did it and when, so audits and regulator questions take minutes instead of weeks.

Full history

Every change, request, review and consent choice is on record.

Ready to export

Download reports as PDF or CSV, or send them to your own tools.

Mapped to the law

Records line up with GDPR, CCPA and the other laws you follow.

ropa · change historyrelyance · live
Every change to a record is saved with who made it and why.
Legal basis addedNishant Shah · today, 9:14checking…saved
New subprocessor foundautomatic · yesterdaychecking…saved
Retention set to 90 daysread from config · Sep 12checking…saved
GDPR Article 30 exportPDF and CSVbuilding…ready
35 activities, full historyready for audit
dsr · audit logrelyance · live
Each request keeps a full record of what happened, step by step.
Data received from product APIresponse 200 · 9:11 AMchecking…saved
Access data step completedautomatic · 9:12 AMchecking…saved
2 fields hidden in the replyJessica Pate · 9:13 AMchecking…saved
Report sent to requestersecure linksending…sent
Done in 4 dayslegal limit is 45 days
assessments · signed reviewsrelyance · live
Signed reviews are saved as proof, with the answers that were true on the day.
&Walshvendor review · signed by legalchecking…complete
Calibre Analyticsvendor review · signedchecking…complete
AmplitudeDPIA · 18 of 24 answeredchecking…in progress
AdobeDPIA · a new data type was foundchecking…reopened
8 assessments this quarterexport as PDF
consent · consent logrelyance · live
Every consent choice is stored as proof, the way GDPR and CCPA expect.
IP addresslast part removedchecking…stored
Date and time of the choiceper visitorchecking…stored
Choice for each purposeanalytics, marketing, functionalchecking…stored
Banner versionand browser typechecking…stored
Published by Jessica Pate · Aug 14export the log
policy center · laws that applyrelyance · live
Your data map is checked against the privacy laws you choose to follow.
GDPRregulation · European Unionchecking…on
CCPAregulation · Californiachecking…on
LGPDregulation · Brazilchecking…on
ISO/IEC 27701framework · privacychecking…off
42 laws and frameworksturn on the ones you need
HOW IT WORKS

Live data in. Records out.

Relyance reads your code, cloud and apps once, then keeps watching. Each flow of personal data is matched to a purpose, a legal basis and the laws that apply. Your records are built from that.

1
Find where personal data lives and where it goes
2
Suggest a purpose and legal basis, confirmed once by the owner
3
Match each flow to the laws that apply, like GDPR and CCPA
4
Keep records, assessments and proof current on every change
ropa entry · refund-handling · generated 09:14:22
activityRefund handling
purposeprocess customer refunds
basiscontract · Art. 6(1)(b)
dataemail, card_last4, order_history
subjectscustomers (EU, US)
recipientsStripe (processor) · OpenAI (processor)
retention90 days ← source: refunds/config.py:12
transferEU → US · SCCs on file
sourcerefunds/handler.py:41 · commit 3f9c2a1
owner@payments-team · confirmed 2026-09-02
Deployment options
Where records live

Export records, assessments and proof as CSV or JSON, or send them to the tools you already use.

Who uses it

Privacy and security teams work from the same map. Privacy sees purposes and laws. Security sees access and risk.

How it stays current

When a system changes, only the affected records update. Reviewers see what changed, not the whole list again.

Bring your current ROPA. We'll show you what it missed.

In the demo we connect one system, build its record of processing from live data, and compare it with the one you keep today.

30-minute demo
One system, one generated ROPA
Gap list against your current record
Privacy and security leads welcome together
Get a Demo