Where personal data really sits
We trace it through Comarch Optima, the CRM, Outlook mailboxes, shared drives and web forms. That inventory becomes the raw material for the record of processing activities your DPO keeps.
Six pieces that tie documents to configuration. Your DPO settles lawful bases and wording; we bring hard facts about the systems and switch on the safeguards.
We trace it through Comarch Optima, the CRM, Outlook mailboxes, shared drives and web forms. That inventory becomes the raw material for the record of processing activities your DPO keeps.
Every outside service touching data goes on the list: the accounting office, newsletter tool, shop hosting, e-signature app. Each entry notes where processing happens, so your lawyer knows which contracts to check.
An honest look at likely failures: a stolen laptop with an unencrypted disk, one shared password for the shop admin panel, backups nobody has ever restored. The findings also feed a DPIA if your DPO decides one is needed.
MFA on every account, BitLocker enforced through Intune, proper Entra ID roles instead of one shared “admin”, sensitivity labels and DLP rules in Microsoft 365, and access logs kept for as long as your policy says.
A runbook naming who alerts whom, and in what order, when the payroll file lands in the wrong inbox. Plus a technical routine for finding and erasing one person’s records across every system within the deadline the GDPR sets.
One hour online, built on examples from your own business: spotting a fake invoice from a “supplier”, what never to paste into an AI chat, and the first few minutes after a file goes to the wrong person.
Facts first, purchases later. Plenty of companies buy expensive tools before noticing that their biggest gap is a former employee’s account that still signs in.
A call with whoever owns GDPR internally, then a remote pass over tenants, servers and laptops: permissions, encryption, backups, dormant accounts.
The data map, the vendor list and a ranked list of gaps. It is written so your DPO or lawyer can drop it straight into the record and the risk analysis.
We configure the fixes in the agreed order and timeframe. The work is remote, and any change that needs a pause is scheduled outside your team’s working hours.
You keep configuration snapshots, restore-test reports and a permissions list. It is worth refreshing the whole set once a year and whenever a new system arrives.
GDPR trouble often starts with an incident rather than with the policy. For example: a customer complaint, a lost phone, a mailing sent to a hundred people in “To” rather than “Bcc”. What matters then is whether, within 72 hours, you can work out which data leaked and to whom. That is a technical question, and it is the one we prepare you for.
The technical chapters, yes: passwords, encryption, backups, granting access and incident handling. The legal content, such as lawful bases, privacy notices and retention periods, belongs to your DPO or lawyer. If you have neither, we will say so plainly and suggest handing that part to a law firm.
Not every company is required to appoint one, and whether yours is should be answered by a lawyer. The GDPR duties apply either way. In that case we simply work with the person who looks after data in practice, typically the owner, the office manager or whoever runs HR.
Yes, because remote administration gives us access to systems holding personal data. We can use your template or offer ours. It sets out our level of access, the sub-processors we rely on and how fast we tell you about an incident, so your 72 hours are not spent waiting on us.
Email office@apply.pl straight away with “Support” in the subject line. On the technical side we can attempt a recall in Microsoft 365, kill the shared link and check the logs to see who opened the file and when. Whether to notify UODO or the people affected is a call for the controller and the DPO, but they make it using our findings.
The length of the review depends on headcount and the number of systems, and we agree the scope before starting. It is billed at PLN 190/hour excl. VAT or covered by an ongoing support plan. The cost of the safeguards depends on your starting point: some tools may already be included in the Microsoft 365 licences you pay for, so before suggesting any purchase we check what can simply be switched on.
Tell us what personal data you handle, which software you use and who looks after GDPR today. We will reply with a proposed review and a few questions worth putting to your DPO first.
Your enquiry has reached us
You will hear back within one working day, and if you have reported an outage that is holding up work, it goes to the front of the queue.
No match for that name. Try a different spelling or pick a bigger town nearby - all our support is delivered online, so your choice has no effect on the service.