Accountability by design
Versioned RoPA, DPIA, provider, transfer, retention, rights-request, incident and control records create an auditable operating history.
This page describes Collty's implemented technical and operational data-protection controls, the evidence maintained for review, and the legal or contractual facts that remain subject to verification.
Versioned RoPA, DPIA, provider, transfer, retention, rights-request, incident and control records create an auditable operating history.
Authenticated users can submit and track privacy requests. Deadlines, responses and state changes are recorded without storing requester email in the case table.
Contracts, processing regions, transfer safeguards, DPO status and EU-representative status remain pending until supporting evidence and legal review are complete.
Collty uses this page as a public summary, not as a substitute for the Privacy Policy, a data processing agreement, regulator guidance or legal advice. The underlying protected registers contain more detail than is published here.
Collty is building GDPR accountability into the product and its operating records. The platform distinguishes technical implementation, operational verification and legal determination. A control is not described internally as verified merely because a table, interface or policy exists.
| Status | Meaning |
|---|---|
| Implemented | The technical control and its protected evidence path exist and can be operated. |
| Partially implemented | The control exists but an enforcement, automation or evidence step remains. |
| Pending verification | A legal, organizational, contractual, regional or supplier fact still requires evidence. |
| Not required | A documented assessment concluded that the control is not applicable in the reviewed context. |
Encryption complements rather than replaces authorization, secure transport, key management, audit logging, minimization, retention and incident response. No security system can eliminate every risk.
The versioned processing register records each identified processing purpose, controller or processor role, data-subject groups, personal-data categories, sources, recipients, legal-basis assessment, retention references, expected international transfers, accountable role and review state.
The register is an operating dataset rather than a static document. New processing must be added and reviewed before it is treated as part of the approved inventory.
Technical DPIA records currently cover Team Assembly, Signals applicant ranking, Team Intelligence and task allocation. Each assessment identifies intended processing, necessity, proportionality, data flows, risks to people, mitigations, residual risk, linked AI-system records and review dates.
Technical assessment completion is not recorded as legal approval. Any requirement for supervisory consultation remains a separate status and decision.
An authenticated user can submit access, portability, rectification, erasure, restriction or objection requests in My Account. A protected case is created with the request type, authenticated user ID, encrypted details, status, one-month due date and audit history.
The retention matrix separates the trigger, active-system rule, backup rule, legal-hold rule, deletion method, accountable role and enforcement status for each data category.
| Layer | Control |
|---|---|
| Active systems | Delete, de-identify, restrict or retain according to the documented purpose and trigger. |
| Shared workspaces | Protect the rights and records of other authorized participants when one account is removed. |
| Financial and dispute records | Retain only where tax, accounting, fraud, claim or legal-hold requirements apply. |
| Backups | Remove through controlled backup rotation unless a documented legal hold requires preservation. |
| Derived analytics | Retain only in de-identified form when the data can no longer reasonably be linked to an individual. |
The register explicitly identifies which policies are automatic, manual, hybrid or still pending verification. This prevents a written target from being mistaken for enforced deletion.
The provider register covers infrastructure, database, AI, vector search, email, research, identity, analytics and optional communication integrations actually referenced by Collty. Current records include Supabase, Render, OpenAI, Jina AI, Qdrant, Resend, Exa, optional Anthropic shadow evaluation, Google services and optional Zoom integration.
Collty does not publicly assert that a DPA is executed, a particular region is guaranteed or a transfer safeguard applies until the applicable account, contract and deployment evidence has been reviewed.
A suspected privacy incident creates an encrypted record containing severity, source, affected data categories, estimated people affected, confidentiality, integrity and availability impact, containment, corrective action and rights-risk assessment.
Each processing, DPIA, retention and accountability record identifies an accountable role and review state. Privacy case and incident transitions create durable database audit entries. Admin reporting reads the protected registers on demand and does not run a background AI review or scan user content.