Law 25 compliance,
handled quietly.
Automate your access requests and stay within the 30-day deadline, effortlessly. One line of code is all it takes.
Drops into the tools you already use
Non-compliance is the expensive option.
Three steps, then it runs on its own.
Install
Paste a single script tag. No dependencies, no framework, no build step and the widget appears on your site.
Configure
Set your privacy officer, retention rules and notifications from one dashboard.
Forget
Requests, inventory, the 30-day clock and the CAI incident register, all handled in the background.
Everything Law 25 asks of you.
Built so a small team runs it alone. No lawyer on retainer.
Access requests
Every request submitted through the widget lands in a single queue. Identity gets verified, the legal 30-day clock starts on its own, and you answer with a secure delivery. No scattered emails, no spreadsheet.
- Built-in identity verification with official ID
- 30-day countdown with alerts before any deadline
- Build the response package: select, redact, send
- Full history kept for every request
Cookie consent
A consent banner that actually blocks trackers until visitors agree. Analytics and marketing scripts stay dormant by default, every choice is logged, and the banner speaks French and English on its own.
- Scripts gated by category until consent is given
- Bilingual banner aligned with your policy
- Every choice logged with a timestamp as proof
- Granular categories visitors control themselves
Data inventory
A living register of every category of personal data you hold: why you collect it, where it lives, who can touch it and how long you keep it. The document Law 25 expects you to produce on demand.
- Three sensitivity tiers: standard, sensitive, restricted
- Purpose, storage and retention documented per category
- One-click export for audits and CAI verifications
Incident register
Law 25 requires a register of confidentiality incidents. Log what happened, assess the risk of serious injury, record the measures you took, and keep it all in a format the CAI can read.
- Risk-of-serious-injury rating: low, medium, high
- Status tracking: open, under review, closed
- Exportable register, ready on demand
Privacy policy
Answer a few questions about your business and get a Law 25-compliant policy written in both French and English. Every section stays editable, every version is kept.
- Guided five-step configurator
- Bilingual document generated as you type
- Editable sections with reset to generated text
- Export as text, Markdown or PDF
Privacy impact assessment
The EFVP that Law 25 demands before risky projects, guided end to end. The risk score recalculates as you answer, mitigations bring it down, and the full report writes itself, ready to sign.
- Live risk score with every factor itemized
- Mitigation controls that lower the residual risk
- Complete, editable report with saved versions
- Coverage checklist aligned with the CAI
Access requests
Every request submitted through the widget lands in a single queue. Identity gets verified, the legal 30-day clock starts on its own, and you answer with a secure delivery. No scattered emails, no spreadsheet.
- Built-in identity verification with official ID
- 30-day countdown with alerts before any deadline
- Build the response package: select, redact, send
- Full history kept for every request
Cookie consent
A consent banner that actually blocks trackers until visitors agree. Analytics and marketing scripts stay dormant by default, every choice is logged, and the banner speaks French and English on its own.
- Scripts gated by category until consent is given
- Bilingual banner aligned with your policy
- Every choice logged with a timestamp as proof
- Granular categories visitors control themselves
Data inventory
A living register of every category of personal data you hold: why you collect it, where it lives, who can touch it and how long you keep it. The document Law 25 expects you to produce on demand.
- Three sensitivity tiers: standard, sensitive, restricted
- Purpose, storage and retention documented per category
- One-click export for audits and CAI verifications
Incident register
Law 25 requires a register of confidentiality incidents. Log what happened, assess the risk of serious injury, record the measures you took, and keep it all in a format the CAI can read.
- Risk-of-serious-injury rating: low, medium, high
- Status tracking: open, under review, closed
- Exportable register, ready on demand
Privacy policy
Answer a few questions about your business and get a Law 25-compliant policy written in both French and English. Every section stays editable, every version is kept.
- Guided five-step configurator
- Bilingual document generated as you type
- Editable sections with reset to generated text
- Export as text, Markdown or PDF
Privacy impact assessment
The EFVP that Law 25 demands before risky projects, guided end to end. The risk score recalculates as you answer, mitigations bring it down, and the full report writes itself, ready to sign.
- Live risk score with every factor itemized
- Mitigation controls that lower the residual risk
- Complete, editable report with saved versions
- Coverage checklist aligned with the CAI
Honest pricing, no surprises.
Start free. Upgrade when you take on real requests. Cancel anytime.
- Incident register
- Data inventory
- Privacy policy generator
- Bilingual FR / EN
- Email support
- Everything in Starter
- Compliance Widget
- Unlimited requests
- Identity verification
- Priority support
- Everything in Business
- Multiple merchants
- Team roles & audit log
- Dedicated onboarding
- Data Privacy Officer as a Service