Your vendors handle your customers' data. The responsibility stays yours.
DataCycles finds out what your software vendors are actually doing with personal data and gives you the evidence to answer for it.
It's your responsibility. Yet you can't answer for it.
Not jointly. Not partially. If a tool you pay for mishandles your customers' information, the obligation is yours — you chose the vendor, and the law treats that choice as yours to answer for.
It isn't negligence — it's paperwork that never kept up
Not through negligence: the privacy policy was written by someone who never saw the systems, the vendor list is whatever accumulated on the company card, and nobody has checked in two years whether what those vendors do matches what was agreed.
AI widened the gap faster than anyone tracked
Tools you already pay for switched on AI features and began sending customer data somewhere new — without a decision, a contract review, or a notification. Your team started using assistants that were never assessed. The stack changed underneath the paperwork.
The law turned this into an obligation, not a risk
The gap didn't grow because anyone was careless. It grew because software changed faster than the documents describing it. The question worth asking: if a customer, an insurer, or the regulator asked where your customers' data goes — could you answer, with evidence?
What We Do
Three stages. You can stop after the first.
- 01
Assess
A fixed-scope, fixed-fee engagement, two to four weeks. We map where personal data lives and moves, check what your vendors are actually configured to do with it, and identify what's exposed and what it would take to close.
- 02
Foundation
Where you'd rather not run the remediation yourself, we do it: the vendor agreements that are missing, the settings that are wrong, the consent mechanism that isn't working, the notices and internal procedures that don't match the systems. Scoped from the assessment, so you know what it covers before it starts.
- 03
Run
Compliance isn't a project that finishes. An ongoing arrangement keeps the picture current: periodic re-checks, review of new vendors before they're onboarded, handling of data subject requests and regulator correspondence, and a named person who already knows your systems when something happens.
How the assessment works
Most assessments work by asking. Your team is interviewed, vendors get questionnaires, the answers go into a table. It's a reasonable method and it produces a real document — it just can't tell you whether the answers are true. We check.
What we check
- Your vendor accounts, as configured — not as described
- Where personal data reaches a model, and under what retention terms
- What's in your retrieval index, and whether deletion actually reaches it
- Where the data physically goes — regions, subprocessors, transfer basis
- Contractual coverage — signed DPAs, click-through terms, and the gaps between them
- Data mapping and security-tier classification under the Data Security Regulations
The three ways AI touches personal data
- Model usage (API and direct) — reversible: contract and configuration
- RAG — data held in a retrieval index, reversible in principle, rarely in practice
- Fine-tuning — data absorbed into the model's weights, not reversible
What you receive
- A written report of every data flow found
- Evidence behind every finding
- Findings ranked by exposure rather than by regulation
- A remediation list ordered by what closes the most risk for the least work
Who it's for
This is for you if:
You hold data that matters
You hold personal data about customers, patients, employees or applicants, and it matters to them that you hold it well.
Vendors run your operation, largely unmonitored
Software vendors run most of your operation, and you have no straightforward way to know what they do with that data. Your team has adopted AI tools — or your existing vendors have added AI features — faster than anyone reviewed them.
Someone's already asking
Someone has started asking — a customer's procurement questionnaire, an insurer at renewal, a partner's due diligence, a letter you weren't expecting. You have no privacy function in-house, and hiring one isn't proportionate to your size.
About
I'm Meir. I've spent most of my career building software — recently AI systems and data platforms — and I moved into data protection because of one problem that kept following me: data is trivially easy to collect and remarkably hard to follow.
Alongside DataCycles I build AI systems for health and finance companies, including the privacy engineering — consent flows, data minimisation, retention, the deletion paths that have to reach every copy. It's why I know where the gaps are. I've had to close them in production, on a real system, with real constraints and a deadline.
That's what I bring that a privacy consultant usually can't: I can open the systems and check. When I tell you what a vendor does with your data, it's because I read the configuration, not because they answered a questionnaire.
When you engage me, I become one of your processors. So I come with my own DPA, my own security declaration, and answers to the questions you'd put to any supplier. I've published all of it — it only seems fair to hold myself to the standard I'll be asking your vendors to meet.
Data has a life cycle, and most of it happens where nobody's looking. That's the part I find interesting.
What we publish about ourselves
Assessing a company means asking hard questions of its suppliers. It would be strange to ask them without answering the same questions first. Our privacy notice and our security declaration are both current, and both public.