Essential Package Builder
Data Mapping
Identification and documentation of all personal data processing activities.
Record of Processing Activities (ROPA)
A detailed log of every processing activity in your business, built together — we structure it, you fill in the detail only you know.
Internal Privacy Policy
Customized privacy policy for internal data handling practices.
Data Breach Response Plan
Simple steps and templates to help you handle data breaches and notify the right people, in time.
Data Subjects Rights Procedure
Clear steps and templates to handle access, rectification, deletion, and other GDPR rights.
2-Hour GDPR Awareness Session for Managers
A focused training session to raise key staff awareness and responsibility for GDPR compliance.
3-Month Soft GDPR Audit
A preliminary audit to assess GDPR compliance readiness.
- External Policies (Website)
- DPA Agreements
- Third-Party Vendors (Non-EU) Consulting
- Eshop Policies
- CCTV DPIA and Policy
- Work from Home DPIA and Policy
AI Act & AI Governance
New to this? Our plain-English guide to the EU AI Act in Cyprus sets out what applies today, what was postponed in July 2026, and whether any of it is yours.
AI Transparency Check
Since 2 August 2026, businesses using chatbots or publishing AI-generated content must disclose it. We identify where Article 50 applies to you, and what needs to change.
AI Act Readiness Assessment
Which AI Act obligations apply to your business, where you stand against them today, and what to deal with first. The same approach as our GDPR gap assessment, applied to AI.
AI Acceptable Use Policy & AI Register
The rules for your staff: which tools are approved, what may never be entered into them, and who is accountable for the output. Plus a record of every AI system in your business.
AI Literacy Training
Article 4 of the AI Act requires you to support AI literacy among staff using these tools. Delivered as a session, built around what your team actually uses.
AI Vendor & Tool Assessment
What a tool does with your data, where it processes it, and whether its terms stand up. Reviewed before you commit, rather than after.
AI Adoption Advisory
Practical help deciding what to adopt and how to govern it — reviewing the tools you are considering, writing the rules, training your people, and assessing vendors before you sign.
Where We Stop
- We advise, we don’t implement. No installation, configuration or code — we work alongside your IT provider, not instead of them.
- We sell no software and take no vendor commissions. The recommendation is the whole product.
- Where we act as your DPO, we won’t implement systems we would then have to audit. Article 38(6) requires that independence, and we protect it.
Add-Ons
Additional Audits
- Quarterly GDPR Audit: A comprehensive review of your business's GDPR practices.
- Semi-Annual GDPR Audit: A bi-annual checkup to ensure continuous compliance.
Consent Mechanisms Consulting
- When and how to obtain valid GDPR consent across your operations.
Additional Policies
- Bring Your Own Device (BYOD) Policy
- Clean Desk Policy
- Data Retention Policy
- Data Protection Officer (DPO) Policy
- Vendor Risk Management Policy
Additional DPIAs
- General DPIA
- CCTV DPIA
- Work from Home DPIA
- Payment Processing DPIA
- Employee Monitoring DPIA
- AI/Data Analytics DPIA
- Cloud Storage DPIA
- Customer Relationship Management (CRM) DPIA
Training
- GDPR Employee Awareness Training
- Advanced GDPR Training for Managers
- Training on Data Subject Rights
DPO as a Service (Subscription Options)
Basic DPO Subscription
2 hours of consultation per Quarter, email handling, and acting as the registered DPO.
Extensive DPO Subscription
8 hours of consultation per Quarter, email handling, acting as the registered DPO, and an annual GDPR audit included.
Data Breach Response Services
- Immediate response and management of the breach.
- Incident investigation and coordination.
- Notification handling to affected parties and regulatory authorities.
Tailored Solutions
For larger corporations, multi-departmental companies, or educational institutions.
- Custom GDPR Compliance Plan for multi-entity or multinational corporations.
- Data protection policies tailored to minors’ data, data privacy and management systems.