Secure
GDPR compliance and health data
Getting genuinely compliant, not putting up a cookie banner and hoping.
Compliance is not decided by the cookie banner, which is the visible part and the least binding. It is decided by written answers: what data do you collect, what for, on what lawful basis, how long do you keep it, who else has access, and what happens in a breach. We keep that register for our own applications, including for health data — the most demanding regime there is, with mandatory certified hosting. That is the rigour we bring to our clients.
The method
How we work
- 01
We inventory the data actually collected
In the database, in the logs, in third-party tools, in mailboxes. The gap between what a company thinks it collects and what it collects is consistently large.
- 02
We write the processing register
Purpose, lawful basis, retention period, recipients, processors. It is the first document a regulator asks for, and the only one that proves anything.
- 03
We fix what is technically fixable
Automatic purging at expiry, consent that genuinely blocks before any cookie is set, encryption, access and deletion rights handled by tooling rather than by hand.
- 04
We write down what remains non-compliant
A known, documented gap with a resolution date is defensible. A forgotten one is not. The register is the only place where a gap genuinely exists.
What you get
Deliverables
- check_circleThe processing register, in the format regulators expect
- check_circleLegal notices and privacy policy written and current
- check_circleCompliant cookie consent: nothing is set before agreement
- check_circleAutomatic purges in place, with justified retention periods
- check_circleThe list of remaining gaps, each with its risk and its deadline
The proof
Where we have done it

STS Arbres et Jardins
Since 2026A one-year-old site built on an abandoned theme, with an American contact page still live. Full rebuild, migration off WordPress, and local pages built on verified facts.
Read the case studyarrow_forward
Gextra
Since 2010Admissions, care records, staff scheduling, billing, mobile apps. A complete business system, being migrated screen by screen to modern technology without stopping the work.
Read the case studyarrow_forward
Gextra AI
Since 2026How a stay is coded determines what the facility is paid. An AI-assisted review flags under-rated severity levels, and the doctor decides.
Read the case studyarrow_forward
HAY HuaHin
Since 2024A studio rental in Hua Hin, Thailand. Site rebuilt, hosted, deployed and optimised by us — and it is our own money going into the Google Ads campaigns.
Read the case studyarrow_forwardFrequently asked questions
- Are you lawyers?
- No, and we do not give legal advice. We handle the technical and documentary side, which is most of the work. On calls that are genuinely legal — appointing a data protection officer, a contestable lawful basis, drafting terms — we tell you to see a lawyer, and about what precisely.
- We handle health data. Can you cope with that?
- It is a significant part of our work: we build and operate applications for healthcare facilities. Be aware, though, that hosting health data in France requires the host to hold a specific certification — a point on which we will tell you what is possible and what is not, with no arrangement.
- Is a cookie banner enough?
- No, and most installed banners are non-compliant: they set trackers before the click, or make refusing harder than accepting. A site using neither advertising nor third-party analytics often needs no banner at all — which is the best answer when it is available.
Let's talk about your project
Thirty minutes is enough to tell whether we are the right fit. We reply within 48 hours, and we say no when it is not for us.
