Data Protection (RGPD): Turn Your Legal Obligation into a Competitive Advantage

In a digital world, your customers' trust is your most valuable asset. We help you adapt your company to the General Data Protection Regulation (RGPD) and LOPDGDD, not only to avoid sanctions, but to build a reputation for security and transparency.

Cristina Contero

Cristina Contero · Head of Privacy

LLM MSc · EU Legal Tech Woman 2020 Nominee

Adrián Becerra

Adrián Becerra · CTO

Forbes 30 Under 30 Nominee · InfoSecurity Expert

We help companies of any size and sector implement or strengthen their privacy and compliance program. We work with clients who need an initial audit and full privacy regulation implementation, as well as those who are already compliant but need to raise the bar to win large clients or enter regulated markets.

We treat privacy and security as essential requirements: from the way we work internally to how we design, deploy, and operate our IT products and software solutions. All our solutions, software, and services maintain strict regulatory compliance in privacy and security.

Our goal is for clients, users, and partners to trust that data is handled with rigor, minimization, and control, in compliance with the applicable regulatory framework and applying technical and organizational measures proportionate to the level of risk.

Our Working Method

An 8-phase methodological process to bring your company to full compliance, from initial diagnosis to ongoing support.

  1. 1

    Initial diagnosis (gap analysis) and real data map

    Inventory of processing activities and data flows (what comes in, where it goes, where it's stored, who has access).

    Identification of risks and critical points (prioritization by impact and probability).

    Phased plan with quick wins and measurable objectives.

  2. 2

    Governance and compliance (accountability)

    Definition of roles and responsibilities (who approves, who executes, who validates).

    Internal policies and operational procedures.

    Preparation for third-party audits and reviews (clients, investors, insurers).

  3. 3

    Essential RGPD documentation

    Record of Processing Activities (ROPA).

    Privacy texts and clauses (data subject information, legal bases, purposes, retention periods).

    Data Processing Agreements (DPA), annexes, and sub-processor oversight.

    Review of legal basis for marketing, sales, support, and analytics.

  4. 4

    Risk assessments and DPIA where applicable

    Impact assessments for higher-risk processing (e.g., sensitive data, monitoring, large volumes, profiling).

    Definition of technical and organizational measures and implementation plan.

  5. 5

    Cookies and digital environment

    Cookie audit and tracking technologies.

    Review of tags, analytics, and marketing tools.

    Consent, transparency, and proper configuration.

  6. 6

    Data subject rights

    Procedures for access, rectification, erasure, objection, portability, and restriction.

    Request traceability, response times, and internal coordination.

  7. 7

    International transfers and vendors

    Identification of data flows outside the EEA.

    Review of mechanisms and safeguards per scenario (especially in cloud and SaaS tools).

    Documentary and evidentiary support.

  8. 8

    Ongoing support (privacy "as a service")

    Review of new projects, campaigns, or products before launch.

    Support for client inquiries and audits.

    Continuous maturity reinforcement: training, controls, procedures, and evidence.

Protect Your Business and Achieve RGPD Compliance Without the Hassle

We identify risks, implement measures for ongoing regulatory compliance — efficiently and without unnecessary red tape.

Contact us

Frequently Asked Questions

Yes, if you process personal data of EU citizens, regardless of your company's size. This includes client, employee, supplier and contact data. Penalties for non-compliance can reach EUR 20 million or 4% of global turnover.