Skip to content

Your vendors handle your customers' data. The responsibility stays yours.

DataCycles finds out what your software vendors are actually doing with personal data and gives you the evidence to answer for it.

It's your responsibility. Yet you can't answer for it.

Not jointly. Not partially. If a tool you pay for mishandles your customers' information, the obligation is yours — you chose the vendor, and the law treats that choice as yours to answer for.

It isn't negligence — it's paperwork that never kept up

Not through negligence: the privacy policy was written by someone who never saw the systems, the vendor list is whatever accumulated on the company card, and nobody has checked in two years whether what those vendors do matches what was agreed.

AI widened the gap faster than anyone tracked

Tools you already pay for switched on AI features and began sending customer data somewhere new — without a decision, a contract review, or a notification. Your team started using assistants that were never assessed. The stack changed underneath the paperwork.

The law turned this into an obligation, not a risk

The gap didn't grow because anyone was careless. It grew because software changed faster than the documents describing it. The question worth asking: if a customer, an insurer, or the regulator asked where your customers' data goes — could you answer, with evidence?

What We Do

Three stages. You can stop after the first.

  1. 01

    Assess

    A fixed-scope, fixed-fee engagement, two to four weeks. We map where personal data lives and moves, check what your vendors are actually configured to do with it, and identify what's exposed and what it would take to close.

  2. 02

    Foundation

    Where you'd rather not run the remediation yourself, we do it: the vendor agreements that are missing, the settings that are wrong, the consent mechanism that isn't working, the notices and internal procedures that don't match the systems. Scoped from the assessment, so you know what it covers before it starts.

  3. 03

    Run

    Compliance isn't a project that finishes. An ongoing arrangement keeps the picture current: periodic re-checks, review of new vendors before they're onboarded, handling of data subject requests and regulator correspondence, and a named person who already knows your systems when something happens.

How the assessment works

Most assessments work by asking. Your team is interviewed, vendors get questionnaires, the answers go into a table. It's a reasonable method and it produces a real document — it just can't tell you whether the answers are true. We check.

What we check

  • Your vendor accounts, as configured — not as described
  • Where personal data reaches a model, and under what retention terms
  • What's in your retrieval index, and whether deletion actually reaches it
  • Where the data physically goes — regions, subprocessors, transfer basis
  • Contractual coverage — signed DPAs, click-through terms, and the gaps between them
  • Data mapping and security-tier classification under the Data Security Regulations

The three ways AI touches personal data

  • Model usage (API and direct) — reversible: contract and configuration
  • RAG — data held in a retrieval index, reversible in principle, rarely in practice
  • Fine-tuning — data absorbed into the model's weights, not reversible

What you receive

  • A written report of every data flow found
  • Evidence behind every finding
  • Findings ranked by exposure rather than by regulation
  • A remediation list ordered by what closes the most risk for the least work

Who it's for

This is for you if:

You hold data that matters

You hold personal data about customers, patients, employees or applicants, and it matters to them that you hold it well.

Vendors run your operation, largely unmonitored

Software vendors run most of your operation, and you have no straightforward way to know what they do with that data. Your team has adopted AI tools — or your existing vendors have added AI features — faster than anyone reviewed them.

Someone's already asking

Someone has started asking — a customer's procurement questionnaire, an insurer at renewal, a partner's due diligence, a letter you weren't expecting. You have no privacy function in-house, and hiring one isn't proportionate to your size.

About

I'm Meir. I've spent most of my career building software — recently AI systems and data platforms — and I moved into data protection because of one problem that kept following me: data is trivially easy to collect and remarkably hard to follow.

Alongside DataCycles I build AI systems for health and finance companies, including the privacy engineering — consent flows, data minimisation, retention, the deletion paths that have to reach every copy. It's why I know where the gaps are. I've had to close them in production, on a real system, with real constraints and a deadline.

That's what I bring that a privacy consultant usually can't: I can open the systems and check. When I tell you what a vendor does with your data, it's because I read the configuration, not because they answered a questionnaire.

When you engage me, I become one of your processors. So I come with my own DPA, my own security declaration, and answers to the questions you'd put to any supplier. I've published all of it — it only seems fair to hold myself to the standard I'll be asking your vendors to meet.

Data has a life cycle, and most of it happens where nobody's looking. That's the part I find interesting.

What we publish about ourselves

Assessing a company means asking hard questions of its suppliers. It would be strange to ask them without answering the same questions first. Our privacy notice and our security declaration are both current, and both public.

Contact

Get in touch to scope an assessment.

Email: contact@datacycles.co

DataCycles is the controller for the information you submit here, used only to respond to your message.

We keep it only as long as needed for that. Privacy notice

We reply within one business day.