GDPR · UK DPA 2018

Reviews that respect every subject right.

Lawful basis built in. Self-service export and erasure. EU and UK data residency. Signed DPAs available on request — no upgrade required.

Lawful basis: legitimate interest SARs answered in 30 days EU + UK residency Signed DPA on request
GDPR · UK DPA 2018 · live signal
DSAR SLA
30d
Statutory
Region
EU/UK
Primary residency
Retention
Custom
Per-tenant config
Subprocessors
12
Publicly listed
Verified & audit-logged
30d
DSAR SLA
EU/UK
Region
Custom
Retention
12
Subprocessors
Capabilities

Everything you need, animated into one workflow.

Lawful basis built in

Invitation flows scoped to legitimate interest with clear opt-outs and balancing tests on file.

Learn more

Self-service DSARs

Subjects can request export or erasure directly from their review page — no support ticket required.

Learn more

EU + UK residency

London and Dublin regions by default. US opt-in. No silent cross-border replication.

Learn more

Right to erasure

Hard delete tooling with audit trail. Anonymised reviews remain only with explicit policy approval.

Learn more

Consent management

Granular consent for invitations, follow-ups and surveys. Withdrawn instantly across channels.

Learn more

PECR-aware messaging

Email and SMS templates pre-flighted against PECR, CAN-SPAM and CASL requirements.

Learn more
Live preview

Answer subject questions before they escalate.

An always-on support layer explains verification labels, data rights and submission flow — in plain language, with a real human on standby.

New review
5.0 · Verified
Verification
Invitation Verified
10:245G
S
Sasha · Review Support
online
Message
From request to resolution

Four steps for any subject right.

1

Request

Subject submits via self-service portal, email or your support team.

2

Verify

Identity confirmed via tokenised link tied to the original engagement.

3

Action

Export, rectify, restrict or erase — logged with reason codes.

4

Confirm

Subject receives signed confirmation; you receive an audit entry.

Comparison

GDPR posture compared.

Compliance is a baseline, not a feature flag.

CapabilityScoreReviewTrustpilotYotpo
Signed DPA on every plan
Self-service DSAR portal
EU/UK data residency
Granular consent log
Subprocessor change notifications
Subject rights covered

Every right, every plan.

  • Right to access (export in JSON, CSV or PDF)
  • Right to rectification (in-line edit log)
  • Right to erasure (hard delete + anonymise)
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
GDPR FAQ

What DPOs ask before signing.

Legitimate interest, supported by documented balancing tests. Subjects can object at any point and we honour opt-outs across channels within minutes.

Ready when you are

Compliance without the friction.

Request the DPA, residency map and subprocessor list — all in one pack.

4.9 / 5 SOC 2 + GDPR 2,800+ firms