+33 (0)1 87 66 00 65 · Monday to Friday, 9am–6pm Free audit (15 min)
This agent is priced on quotation. This agent is available, and its capabilities really are the ones described below. Its price depends on your estate: how many systems are covered, the volume handled, the connections to open and the service level expected. We therefore price it on quotation, after scoping your need — and the quotation commits the scope. If you already run an agent covering part of this scope, that part is not charged again: only the real extension is priced. Request a quote
● B2B offer — GDPR rights & breaches

Subject requests and breaches: the complete file, before the deadline

An access request lands on a Friday evening; one month starts running from the moment it was received. A supplier reports an incident on a Saturday morning; seventy-two hours start running from the moment you become aware of it. In between, you have to establish an identity without collecting too much, query eight systems, find what belongs to a third party, separate established facts from unknowns, and produce a file an inspection can read back. <strong>The agent does that work in full and hands you the file in minutes</strong>: complete, quantified, sourced, with the dated rule that produced it. You keep the signature — the one that binds you, and the one that, on that day, is worth more than anything else.

One month and 72 hours shown Partitioned by entity Every source returns its result The DPO signs

Updated on

Deployed in a few weeks
GDPR rights & breaches · hosted in France
An access request came in last night. Where do we stand?
File opened, deadline shown, six systems already queried. The deadline is one month from receipt: Article 12(3) GDPR reads “without undue delay and in any event within one month of receipt of the request”, and adds that it “may be extended by two further months where necessary, taking into account the complexity and number of the requests”. I dated receipt from the portal timestamp, not from when you read it.
What I have already done: identity established from the two items the person already had on file with you, six sources queried, six replies obtained, 214 occurrences deduplicated down to 61, and the extract is assembled.
What is waiting for you: four items contain exchanges in which a third party appears. I have redacted them reversibly, each with its reason — you lift or you confirm, in four clicks.
⛓ Sourced · privacy portal, CRM, HRIS, DMS, mail, warehouse
Send it to them right now, we have waited long enough.
I will do it the moment you give me the mandate — and the file is ready to go: recipient verified, secure channel set, extract paginated, remedies notice included.
What I need from you is one signature, and it is not a formality: sending personal data to the wrong recipient is itself a breach. The mandate you write sets who validates, within what limits, and it is withdrawn with a word.
Want the shortcut? Give me a standing mandate on access requests where identity is established and no third-party data is involved: those will go on their own, and you will only review the rest. Over your last twelve months, that would have covered 31 files out of 47.
✎ Framework · written mandate, capped, dated, revocable
Our payroll provider has just reported a leak. How long do we have?
72 hours, and the clock starts from your awareness — that is, this morning at 9:14, not from the date of the events. Article 33(1) GDPR requires notification “without undue delay and, where feasible, not later than 72 hours after having become aware of it”; the CNIL states that the starting point is the moment you have “a reasonable degree of certainty that an incident has occurred and has affected personal data” (our translation of the CNIL’s French guidance).
Established facts: one payslip export, 3 systems, a 41-hour window. Unknowns, and I am leaving them unknown: the exact number of people affected — the investigation is open, and I am not writing zero in its place.
What I am putting on your table: the draft initial notification is written from the settled facts, and Article 33(4) expressly allows information to be provided “in phases”. You do not wait until you know everything to notify — you notify what you know, and I prepare the follow-up.
⛓ Sourced · processor report, application logs, ITSM
Local inference · no data outside the EU
Files and evidence hosted in France
Sovereign by designLocal inference or hosting in France
RecomputableSame inputs, same file, versions shown
TurnkeyDesigned, installed and operated for you
The decision stays with the clientReturned in minutes, quantified and reasoned
✦ In brief

A Blue Lemon Agent specialised in operational files: it opens every data subject request and every breach with its enforceable date of receipt, verifies identity and mandate without collecting more than necessary (Article 12(6)), queries the systems in scope while recording failures and non-responses, prepares reversible redactions, assembles the response file, documents the breach by separating established facts, estimates and unknowns, and drafts the notifications. The one-month (Art. 12(3)) and 72-hour (Art. 33(1)) deadlines are shown with their starting point. You keep your hand on what binds you: the notification goes out under your signature, and the agent has already drafted, dated and sourced what you will send.

12
core modules, none sold separately
12
business checks run on every file
0
notification sent without a human decision
13
file states, with guarded transitions

Reference points describing how our offer is built, not results measured at a client. Case volume, source coverage and time returned are confirmed by a pilot on your own scope.

The context

Two clocks that do not stop, and work that cannot be delegated

A subject request and a breach have almost nothing in common, except this: they arrive when nobody expects them, and a deadline starts immediately. The rest of the work — establishing an identity, bounding a scope, getting a reply from eight systems, two of which are run by a provider, finding what belongs to a third party — is done by hand, under pressure, by the person with the least time.

! What is at stake

The breaking point is almost never the law: it is documentary. Nobody can say, at the end of a search, whether all eight systems answered or whether two stayed silent. A silent source looks like an empty source, and an absence of results in a system ends up being read as an absence of data in the organisation. That confusion is what loses inspections.

On breaches the difficulty is the mirror image: the organisation waits to know everything before notifying, and the clock runs. Yet Article 33(4) GDPR provides for exactly the opposite — where the information cannot be provided at the same time, it “may be provided in phases without undue further delay”.

Our answer

The agent holds both clocks from a proven starting point, bounds the search to the authorised scope, and keeps for each source its result, its failure, its freshness and its coverage. A source that did not answer produces an unknown state, never a void. On a breach, it separates what is established from what is estimated and what remains unknown, and proposes the initial notification that Article 33(4) allows to be completed later.

The four decisions that bind you — notifying the authority, communicating to data subjects, refusing a request, lifting a redaction — reach you instructed rather than open. Each comes with its facts, its unknowns, its grounds and its draft text: what used to take you half a day of preparation is settled in a few minutes of reading. Articles 33 and 34 assign those acts to a named person; the agent does everything that precedes them, and hands you the decision while it still counts.

The decisive point

A rights tool handles, by design, the data of your data subjects

A rights file contains everything the organisation holds about a person. A breach file contains the anatomy of its incident. Here is how the architecture keeps them separate and protected.

Local inference

The agent can run on a machine inside the company: neither the extracts nor the incident files leave the network.

Hosted in France

Otherwise, a dedicated and isolated resource hosted in France under French law, with processing and access operated within the European Union as the deployment objective.

Partitioned by entity

A file belongs to a tenant and an entity. No role, not even the connector administrator, crosses that boundary — refusal is the default.

Reduced extraterritorial exposure

Architecture designed to reduce exposure to extraterritorial legislation, location alone not guaranteeing immunity.

What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.

  • The applicable location is that of the architecture set out in the quotation and verified before commissioning.
  • Local execution is announced only for the configuration explicitly described and accepted in the quotation.
  • The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
  • The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
Identity documents collected to verify a request are minimised and kept for a short period: they serve to lift a doubt within the meaning of Article 12(6) GDPR, not to build a file. Our reading of the law applicable to AI agents is set out on AI agents and personal data.
Demonstration

See the agent at work

4 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.

A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.

The company in this demonstration

Fictional company

Maison Aurore — a homeware retail chain, 22 stores and an online shop

Sector
Specialist retail: household linen, tableware, small furniture
Headcount
480 staff, including a privacy officer at half time and an incident manager in the IT department
People served
Consumers in France — 840,000 active loyalty accounts
Order of magnitude
47 rights requests received last year, 6 systems in the search scope, 2 breaches reported
Tools in place
Privacy portal, loyalty CRM, HRIS, document management system, corporate mail, data warehouse
Who decides
The privacy officer validates the redactions and the replies; the managing director, as controller, signs every notification
Room for improvement
16 of the 47 requests were closed beyond one month, and none of them says how many systems actually answered

Maison Aurore handles its rights requests by hand from the privacy portal: the officer writes to six departments, waits, chases, and assembles whatever comes back. At the end, nobody can say whether all six answered. The agent is connected to those six systems and works continuously; redacting an item, replying to the requester and signing a notification remain human acts.

This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.

GDPR rights & breaches · hosted in France
Access request received yesterday at 19:06 through the portal. File opened, deadline 6 October. I dated receipt from the portal timestamp — not from your reading it this morning: Article 12(3) GDPR runs the deadline “within one month of receipt of the request”, and that nuance was costing you an average of eleven hours on every file last year.
Identity: established. The requester gave their loyalty card number and the address declared when the account was opened; the two match. I asked for no identity document — Article 12(6) allows one only where there are “reasonable doubts”, and there were none.
Search run on the six systems in scope, six replies obtained. 214 occurrences found, brought down to 61 after deduplication: the same checkout transaction appeared up to four times across the CRM, the warehouse and the DMS.
The extract is assembled and waiting for you. source-coverage_six-out-of-six-file-AUR-2026-041.pdf6 sources queried, 6 replies, 214 occurrences brought down to 61
⛓ Sourced · privacy portal, loyalty CRM, HRIS, DMS, corporate mail, warehouse
Six out of six — does that mean we have everything?
It means the six systems in YOUR scope answered — and the scope is the one you settled. The distinction is not caution, it is what an inspection comes to check: an absence of results in a system is not an absence of data in the organisation.
What I can tell you with certainty: each of the six systems recorded in the scope returned a dated result, and I keep the query, the time and the volume returned for every one of them.
What I am proposing, and this is where you gain: I compared your scope with your signed processing contracts. Two services handle customer data without appearing among your six — the online review tool and the in-store returns platform. Add them to the scope and the same request becomes eight out of eight. I query them as soon as you record them.
✎ Framework · scope settled from your contracts, not guessed
Add them. And the extract — is it ready to go?
Both sources are recorded, and the follow-up query goes out tonight. The extract is ready to review — not yet ready to send, and for a precise reason.
Four items out of 61 contain a third party: three after-sales exchanges in which another customer is named, and one complaint in which a sales assistant's name appears. I have redacted them reversibly, each with its written reason, and I present them side by side: original version on the left, redacted version on the right.
You lift or you confirm, in four clicks. I never remove an item on my own: a redaction applied silently would be undetectable on review, and that is exactly what an inspection looks at. The work is done; the act that remains is yours, and it takes two minutes. reasoned-redactions_four-items-file-AUR-2026-041.pdf4 reversible redactions, a reason per item, before/after access-extract_file-AUR-2026-041.pdf61 occurrences, 6 dated sources, remedies included
⛓ Sourced · 61 items analysed, 4 carrying an identified third party
Local inference · no data outside the EU

Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit

What the agent actually does

Twelve modules in the core, and the extensions quoted separately

The twelve core modules cover the whole chain, from the receipt of a request to the retention of its evidence. Security, traceability, human validation and the demonstrators never leave the core to become options. The three extensions below widen the scope, the volume or the connectivity: they are quoted, and nothing else is added to them.

Included in your agent The 12 capabilities essential to this promise are included, at no extra cost.

Receipt and enforceable clock

Opens every request or incident from the portal, email, post, an API or a ticket, and keeps the channel, the date of receipt, the time zone, the acknowledgement and the computed deadline.

Identity, mandate and safe channel

Verifies identity, representation, contact details and reply channel through a proportionate procedure, without collecting more than necessary (GDPR Art. 12(6)).

Qualifying the right invoked

Distinguishes access, copy, rectification, erasure, restriction, objection and portability (Art. 15 to 21), and keeps composite requests, ambiguities and language.

Mapping and scope

Links the request to the record of processing, controllers, processors, applications, archives, backups and retention periods, with visible coverage.

Federated search and collection

Runs bounded searches, deduplicates occurrences, and records queries, sources, dates, failures and partial results.

Review, third parties and redaction

Spots third-party data, secrets and sensitive items, and prepares reversible redactions with their reason, subject to validation.

Response dossier

Assembles the reply, the copy, the portable format, explanations, remedies, items and log, and checks legibility, integrity and recipient.

Personal data breach reporting

Centralises facts, systems, categories, people, volumes, measures and unknowns, without concluding prematurely.

Risk assessment

Applies a versioned likelihood and severity grid, distinguishes risk from high risk, and documents factors, disagreements and unknowns.

Prepared notifications

Timeline, initial or follow-up notification (Art. 33(4)), communication to data subjects and internal register (Art. 33(5)): drafted, dated, sourced, ready to go under your signature.

Deadlines, escalations and acknowledgements

Tracks milestones, reasoned extensions, reminders, approvals, dispatches and acknowledgements, and refuses any closure on a mere send click.

Evidence, quality and steering

Versions sources, rules, decisions, exports, accesses and deletions, and measures coverage, turnaround, reworks, errors and human workload.

Controls and safeguards These 6 controls are built into the agent: they frame what it does, whatever plan you pick. They are not chosen and are not added to your order.
Human validation, exceptions and escalation Status, safe closure and audit trail Sources, access rights and handling of questions with no answer Manage deadlines, versions, evidence and human validation Preserve confidentiality, compartmentalisation and access logging Flag uncertainties and reserve characterisation, notification and signature for the controller
The gain

Where the time of a file goes, and where it goes back

The effort moves from collection to judgement. The proportions below illustrate that shift; they do not represent any client measurement.

Querying the systems and gathering occurrences
Today · done by hand
Sources queried, coverage shown
Spotting third-party data and preparing redactions
Today · done by hand
Redactions proposed, reasoned, reversible
Reconstructing the timeline of a breach
Today · done by hand
Facts, estimates and unknowns separated
Drafting the notification and its follow-up
Today · done by hand
Draft written, to review and sign
Qualitative, non-contractual comparison: the proportions illustrate the shift of work towards review, they do not represent any measurement. Assessing a breach, deciding on a notification, communicating to data subjects and refusing a request remain acts of the controller and the DPO.
How it works

The stages of your AI agent project

1

Audit & scoping

15 minutes to target the use case with the best return.

2

Quote or direct sign-up

A catalogue offer is bought online; a specific need gets a costed quote.

3

Design

We design the agent and its guardrails.

4

Integration & testing

We connect your tools to the agent, which is itself hosted in France.

5

Rollout

Going live and training your team.

6

Operation

Continuous supervision and improvement.

Quotation

This agent is quoted against your own scope

It cannot be ordered online, and that is deliberate: the real work depends on three things only your organisation knows — how many systems have to be queried, how many entities have to be kept apart, which intake channels have to be connected. The twelve modules and the twelve checks are in the core. The thirty-eight sector variants share this identifier and change the content, never the scope. And if you already run our DPO support agent, say so up front: data subject requests and breaches are covered there and are not billed again here — only a genuine extension of scope, volume, connectivity or service enters the quotation.

This agent is priced on quotation. This agent is available, and its capabilities really are the ones described below. Its price depends on your estate: how many systems are covered, the volume handled, the connections to open and the service level expected. We therefore price it on quotation, after scoping your need — and the quotation commits the scope. Request a quote
Our commitment

Four guarantees that matter on a rights file

A dated clock, not an inferred oneThe deadline is computed from a proven receipt and an awareness date set by you, with the rule and its version shown next to the result.
A silent source stays unknownNo coverage is declared complete while a system has not answered, and no unknown is replaced by a zero.
The decision stays with the clientRisk assessment, notification, communication to data subjects, redaction, refusal: the agent prepares and hands you the file in minutes; you sign.
Nothing leaves without an acknowledgementAn attempted send is not a received send. Without a verifiable acknowledgement the file stays open and refuses to close.
Frequently asked questions

Your questions, our answers

Can the agent refuse a request on its own?
It brings you the refusal ready-made: the request qualified, the elements gathered, the contemplated reason drafted with its grounds, and the letter to send. What used to take half a day of preparation becomes a few minutes of reading. The signature is yours — a refusal is a decision the data subject can challenge, and it binds you. The engine even refuses to record a rejection as long as no reason has been written: your file cannot become indefensible by inadvertence.
How does it prove identity without collecting too much data?
It starts from the items the person ALREADY has on file with you: a contract number, a declared address, an account identifier. Article 12(6) GDPR allows further information to be requested where there are “reasonable doubts” — so an identity document is a last resort only, and the agent flags it as such. What is collected for that purpose is kept for a short period, separate from the file itself.
How does it know that every application has answered?
Because it counts. The scope is set from the record of processing before the search starts, and every source then returns one of three states: a result, a failure, or a non-response. Coverage is shown in plain words — “five sources out of six”. A silent source never becomes an empty source: that confusion is what costs the most in an inspection, and the engine refuses to make it.
Does it handle third-party data and redactions?
It spots them and prepares the redaction, reversibly, with the reason that justifies it — then it waits for your validation. It never removes an item on its own: a redaction applied silently would be undetectable on review, and that is precisely what an inspection comes to check. You lift or you confirm, and every action is logged.
Can it notify the supervisory authority automatically?
You keep your hand on the notification, and that is what you want: it is you that it binds. What the agent takes off your hands is the work that makes it possible within the deadline — the timeline reconstructed, the facts separated from the unknowns, the initial notification drafted and, as soon as the investigation closes, the follow-up allowed by Article 33(4). The text is on your screen a few hours after awareness, not the day before the deadline. You review, you sign, you send.
How does it compute the one-month and 72-hour deadlines?
The month runs from proven receipt of the request (Art. 12(3)), and the text provides that it “may be extended by two further months where necessary, taking into account the complexity and number of the requests”: the extension exists, but it is reasoned, and the agent refuses to apply it without a written reason. The 72 hours run from awareness (Art. 33(1)) — the CNIL places it at the point where you have “a reasonable degree of certainty” (our translation) that an incident has affected personal data. That date is set by you, never guessed by the agent.
What happens when a processor does not reply?
The file stays in search, the non-response is visible in the coverage, and the reminder is recorded with its timestamp. That silence is never converted into “nothing to report”: it is presented for what it is, an uncovered area, both in the reply and in the evidence file. It is also what gives you, when the time comes, the material to document the controller / processor chain.
How does it keep proof of the dispatch and of the decision?
Every file carries the rule versions that produced it, the observed values, the unknowns, the twelve checks with their result, the human decisions and their author, the dispatch and its acknowledgement. An attempted send without a verifiable acknowledgement does not close the file — the transition to closure is refused. A file handled six months ago is therefore read back with the rule of that time, and that is what makes it contestable.
Let's talk

Let us measure your real turnaround on your last twelve files

15 minutes to map your intake channels, your systems and your deadlines — hosted in France, supervised, no commitment.