Skip to content
Apply
Privacy packIn build

The DPIA your client's lawyers will ask for.

Agencies get asked the same question: where does our customers' data go? The privacy pack answers it from the client's real setup, not a template. Generated, not written by hand, so it can't drift from what the system does.

What's in it

Six answers, from the live configuration.

01Every table, named

The tables that exist for that client, what each holds, and which hold nothing identifying.

02The three columns

What is counted without consent, what is observed after a yes, and what is inferred and labelled.

03Where data goes

Each ad platform switched on, what is sent, and the gate it passes first. Declined or modelled data is never sent.

04Where data lives

On the client’s own subdomain, in databases located in the EU, under UK data law.

05How long it’s kept

The retention for each kind of data, as configured.

06How a person is erased

The erasure route, from the button in the hub to every platform the person’s data reached.

Sample pagesIllustrative

What a client's legal team reads.

Made-up client, made-up setup. The real pack is built from yours.

Data protection impact assessment

North Pier Digital · client: Harbour Goods

Illustrative
Counted without consent
Page views, referrer host, campaign tags, country, device type. No IP, no user agent, no raw identifier.
Observed after a yes
Journeys and replay, for 13 months, then deleted.
Sent to platforms
Meta: purchases, hashed email, consented only.
Location
EU databases. UK data law.
Audit · tables in use

What each table holds

Illustrative
TableIdentifying?
daily_metricsNo
consent_logPseudonymous
customersEmail encrypted
ordersLinked to a customer

Founding clients get the first packs.

The pack is in build. It ships to founding clients first, generated from their own setup.

Apply for a founding slot

This explains the law in plain English. It isn't legal advice.