For modern SaaS teams

Keep privacy requests from becoming an internal project.

Trace is developing a managed path through product databases, billing, support and identity systems so an authorised privacy professional receives one structured case instead of a series of internal hand-offs.

Direct answer

Managed data-rights operations is the recurring work required to receive a privacy request, identify relevant systems, retrieve and structure evidence, expose exceptions and prepare a case for an authorised human decision.

When a request lands today

A rights request crosses the org chart before it reaches a decision.

The work often becomes a temporary project shared across support, engineering, operations and legal. Every hand-off introduces context loss and new follow-up.

  1. 01

    Support recognises the request

    The request may begin in a general inbox, ticket or legal queue.

  2. 02

    Legal asks where the data lives

    Engineering, billing and customer teams reconstruct the source list under time pressure.

  3. 03

    Each owner produces something different

    Exports, screenshots, queries and caveats arrive with inconsistent context.

  4. 04

    A privacy professional rebuilds the case

    Only then can an authorised person decide what is relevant, disclosable or actionable.

Likely starting stack

Begin with the structured systems that describe the customer.

These names represent research targets and proposed retrieval paths, not live one-click connectors. The first scope would normally select up to three agreed systems.

Review source-mapping readiness
01Product data

Postgres, Supabase or Firebase

Mapping candidate
02Billing

Stripe or customer-produced exports

Mapping candidate
03Support

Intercom or Zendesk

Mapping candidate
04Identity

Auth0 or Clerk

Mapping candidate
05Customer context

HubSpot or controlled files

Mapping candidate

The source map

A retrieval plan another person can follow.

The proposed source map is an operating record, not a systems diagram. It makes the evidence path and its limitations explicit before a live deadline.

01

Source

Which agreed system may contain relevant records.

02

Identifiers

How email, user ID or another stable key connects the person.

03

Retrieval path

Who can produce the evidence and by which approved method.

04

Known limit

What cannot be retrieved or interpreted without an exception.

05

Decision owner

Who is authorised to decide what happens next.

Internal ownership

Your team only handles defined exceptions.

That does not mean zero internal involvement. The controller and authorised privacy professional retain decisions, and system owners may still be needed where the agreed retrieval path cannot answer a question.

Proposed operating role

Trace is being designed to prepare

  • Intake and case structure
  • Source maps
  • Approved retrieval coordination
  • Source inventories
  • Evidence organisation
  • Draft response structure
  • Exception notes
  • Timestamped activity records
  • Closure evidence

Decision boundary

Your authorised team retains

  • Identity sufficiency and interpretation of the request
  • Disclosure, redaction, retention and exemption decisions
  • Erasure or correction authorisation
  • Legal advice and final response approval
  • Defined system exceptions and controller responsibility

Why rehearse

Synthetic data can expose a real operating gap.

A fictional request can test whether the intake owner, identifiers, retrieval paths, decision boundary and evidence record are clear without introducing live requester data.

A synthetic rehearsal does not prove production security, connector availability or readiness for every real case. Those remain separate go-live questions.

01

Intake ownership

Who receives the request, records it and owns the next hand-off.

02

Identity matching

Which identifiers connect the same person across agreed systems.

03

Source coverage

Which sources are in scope, how they are checked and where gaps remain.

04

Decision boundary

Which questions require an authorised privacy professional.

05

Evidence trail

What records the search, exceptions, decisions and closure path.

Initial fit

A deliberately bounded first environment.

Likely fit
  • Approximately 25–250 employees
  • EU or UK operations
  • Structured product and customer data
  • Approximately 3–8 primary systems
  • No dedicated privacy-operations function
  • A named privacy decision owner
Outside the initial scope
  • Employee disputes or litigation
  • Health data or children’s data
  • Broad Slack, mailbox or file-share discovery
  • Large unstructured-document volumes
  • No stable identifiers
  • Urgent live matters before capacity is confirmed

Readiness Sprint

Map up to three systems before the next request.

The proposed €2,500 fixed-scope engagement creates a source map, decision boundary, synthetic rehearsal and fictional evidence pack. Price, capacity, terms and exact scope remain under validation.

Explore the Readiness Sprint

Illustrative output

Inspect the case before discussing the service.

The sample uses fictional people, records and systems. It stops at the authorised review boundary.

Founding design partners

Show us where the request becomes an internal project.

Join the waitlist or describe the hand-offs in an email. Use workflow categories only; do not send request contents, identities, exports or credentials.