Limit collection
Connect authorized sources and configure the collection scope supported by each connection.
Understand what enters the workspace, what is retained, and how privacy controls apply to the intelligence extracted from connected sources.
The GDPR addresses how personal data is collected, used, protected, and retained. Extracting intelligence does not make personal data anonymous or remove those obligations. Scope, lawful basis, transparency, and the rights of affected people remain part of the review.
Connected documents and messages are processed temporarily by default. Extracted facts, summaries, citations, and provenance remain subject to access and lifecycle controls.
Explore trust and securityConnect authorized sources and configure the collection scope supported by each connection.
Retain the meaning and provenance needed for the record, with raw source content temporary by default.
Apply the relevant retention, correction, restriction, and deletion workflows to the data that remains.
These are privacy-design topics. The current receipt catalog does not provide a GDPR article crosswalk or a legal assessment of compliance.
Product evidenceConnection scope and temporary raw-source processing reduce the material retained from connected systems.
Review limitsThe organization must determine lawful purpose, necessity, and the data it is entitled to process.
Product evidencePrivate member-vault data requires an explicit contribution before entering shared intelligence.
Review limitsContribution is a product authorization step, not automatically a GDPR consent or other lawful basis.
Product evidenceConfigured lifecycle and privacy workflows support review of eligible data and its downstream effects.
Review limitsLegal holds and required history affect removal. Disconnecting a source does not erase every derived record.
Product evidenceA deployment review can identify data flows, configured AI services, and infrastructure requirements.
Review limitsController/processor roles, contracts, transfers, and provider terms must be agreed and assessed separately.
Architecture alignment describes relevant product mechanisms. It does not establish a framework mapping, audit opinion, or legal compliance.
Use the architecture and records alongside the legal and operational work your processing requires.
Lawful basis, notices, and controller/processor responsibilities
Data-subject requests, retention schedules, and any required impact assessment
Subprocessor terms, international transfers, and deployment location
No. Extracted facts, summaries, and references can still contain or identify personal information. They remain subject to appropriate access, retention, and privacy controls.
No. Disconnection and removal stop or change collection access, while derived intelligence and required history have separate lifecycles. Assess correction, restriction, unlearning, and deletion requirements for the affected data.
No. The controls support privacy work, but compliance depends on the processing, lawful basis, organizational practices, contracts, transfers, and other applicable obligations.
Framework requirements and their interpretation should be checked against the authoritative source.
Walk through the scope, available evidence, and remaining requirements with our team.