Privacy built into the software itself
We turn your company's privacy rules into software behaviour: less personal data, retention periods, access logs and handling of data subjects' requests.

Who it's for
For companies with a privacy policy on paper that the system does not yet follow.
What it solves
- A data subject asks for their data under the LGPD, and nobody knows where it is.
- The system has always stored personal data that no process uses.
- A deletion request removes the account, but copies remain in logs, reports and spreadsheets.
- There is no record of who looked at a person's data.
What we do
- Data inventory
- Which personal data exists, where it lives, what it is for and who accesses each item.
- Less data
- Collection limited to what each purpose needs; sensitive fields masked or encrypted.
- Retention periods
- How long each piece of data is kept, enforced by automatic deletion or anonymisation jobs.
- Access log
- Who viewed or changed personal data, when, and through which screen or API.
- Data subject requests
- Functions to find, export, correct and delete a person's data, with the request recorded.
- Retention exceptions
- Data that a legal obligation requires you to keep is protected from deletion, as your legal team defines.
What you get
- An inventory of the system's personal data, with purpose and access
- Deletion and anonymisation jobs running to the defined periods
- A log of access to personal data that your team can query
- Functions for handling data subject requests, documented and tested
- Technical input for the RIPD (data protection impact report) and your data protection officer
How we do it
Inventory
Personal data in the code, the database, the logs and the data pipelines.
Rules with legal
Purposes, periods and exceptions set by your legal team and turned into technical rules.
Implementation
Masking, deletion jobs, access logging and functions for data subjects.
Testing
Every data subject request and every deletion job tested with fictitious data.
Documentation
Technical material for the data protection officer and future reviews of the system.
Technology examples
- PostgreSQL
- Row-Level Security
- pgcrypto
- HashiCorp Vault
- OpenAPI
In Brazil, we handle
- LGPD
- Brazil's General Personal Data Protection Law (Law 13,709/2018).
Related services
FAQ
Will this make our company meet the LGPD?
That cannot be promised. Meeting the LGPD involves legal and process decisions that go beyond software. We handle the technical side, based on the rules your legal team sets.
Who decides the retention periods?
Your company, with its legal team or data protection officer. We show where each piece of data is and implement the rule; interpreting the law is not our role.
Do you produce the RIPD?
No. The data protection impact report is your company's responsibility. We supply the technical part: what data the system processes, where it flows, who accesses it and which controls exist.
Can test data be a copy of production?
We would rather it were not. Test environments get fictitious or anonymised data, so real people's data does not circulate outside production.
Write to Balkan
Talk to us about your project