Verkta ยท GDPR

GDPR documentation that writes itself

Every company must be able to present records of its personal-data processing, and most keep them in a forgotten spreadsheet. Verkta builds the records in 10 minutes and generates the privacy policy straight from them.

No credit card required. Set up in 5 minutes.

Records and privacy policy on autopilot

1

Start from the standard activities

Payroll, customers, recruitment, one click pre-fills the records with what almost every company processes.

2

The policy generates itself

The privacy policy is written directly from the records. Change the records, and the policy follows.

3

Ready for the regulator

Print-ready records and policy, with sensitive data and third-country transfers clearly flagged.

โœ“Start from the standard activities
โœ“The policy generates itself
โœ“Ready for the regulator

Every feature, in detail

Full transparency about what the GDPR module does. Every line corresponds to something the system actually does.

The article 30 records

  • Prefilled with standard activities

    Payroll, HR, customers, marketing, bookkeeping and more, pick your activities from templates instead of starting from a blank page.

  • Every statutory column

    Purposes, categories of data subjects and data, recipients, third-country transfers and retention periods, the structure follows art. 30, not the other way round.

  • Sensitive data flagged

    Activities involving special categories (art. 9) are clearly marked, so you know where the requirements tighten.

  • Third-country transfers visible

    Transfers outside the EU/EEA appear in the records, the first thing a supervisory authority looks for.

  • Retention periods in one place

    Every activity has its retention period, the basis for documenting storage limitation.

  • Print-ready for the authority

    The entire records can be printed in one click, ready for an inspection or a board meeting.

Privacy policy and daily operations

  • Auto-generated privacy policy

    The policy is built from your actual processing activities, not from a generic template that doesn't fit.

  • Update with one click

    When an activity changes, the policy is regenerated. It is never out of step with reality.

  • Vendor and processor management

    Register your processors with DPA status, so you can document that the agreements are in place.

  • Breach log with a 72-hour clock

    Record breaches immediately. The clock counts down to the notification deadline, and the assessment is documented.

  • Data subject requests with a one-month deadline

    Every request automatically gets its one-month deadline, and the process is documented from receipt to reply.

  • The year wheel remembers the reviews

    Annual reviews of records, policy and retention periods live in the compliance year wheel with reminders.

Legal & compliance

  • Built for art. 30 and art. 28

    The records follow the regulation's structure, and the data processing agreement with Verkta is part of the terms, automatic for every customer.

  • Applies across the EU

    The GDPR is the same regulation in every member state, and the law pages cover the national supervisory authorities.

  • GDPR checklist and templates

    A free checklist and templates supplement the module, so you get all the way round.

  • Accountability documentation

    Records + policy + breach log + DSAR trail together form the accountability evidence under art. 5(2).

Security & operations

  • Encryption throughout

    All traffic is TLS-encrypted, and data at rest is encrypted in EU data centres in Frankfurt.

  • All data stays in the EU

    Operations and database are in Frankfurt, no customer data leaves the EU/EEA in normal operations.

  • Self-service data export

    Export all company data as a single JSON file, any time, no request needed.

  • Role-based access

    Administrator and user roles control who can change the records and policies.

  • Complete audit log

    Changes to records, breaches and requests are logged with timestamp and responsible person.

  • Certified infrastructure

    Verkta runs on ISO 27001 and SOC 2 certified infrastructure (Vercel, Neon). Verkta itself is not yet certified, we say so honestly until that changes.

A GDPR consultant charges thousands, for the same document

Most companies either pay a consultant for records that are outdated three months later, or cross their fingers. Verkta keeps the documentation alive: change one line in the records and the policy updates itself.

โ‚ฌ29/mo

Your Article 30 records built in 10 minutes, and the privacy policy generated straight from them. Change the records, and the policy follows.

Start free 14-day trial