Capability · Engineering · Automation

Sensitive registers out of Excel — GDPR as a property of the system, not something to remember

A 180-person consultancy ran its landowner process in Excel: personal IDs, addresses and bank details in the same file, GDPR masking done by hand "when it happens", and final deliveries glued together into PDFs one full working day at a time. We design platforms that own the data lifecycle register, status, delivery log, and automatic retention.

SectorInfrastructure & field-operations consultancies
01

Challenge

Challenge

The problem pattern.

A field engineer preparing landowner agreements opens an Excel file. In it: personal identity numbers, names, addresses, often bank details — all in one document. Contact details are looked up manually, one owner at a time. Before archiving, someone is supposed to strip the personal data by hand. Sometimes it's missed. When a project closes, someone spends a full working day gluing Word, Excel, map and CAD files into a 30-tab PDF binder according to the client's template — and if something's wrong, 50 of 200 documents may need redoing.

No single step is hard. It's manual, person-bound — and sensitive in exactly the wrong places. Organisations in this position also hoard sensitive documents because clients lose delivered contracts, and nobody dares delete.

02

Solution

Solution

What we build.

A platform that owns the data's lifecycle, in three parts:

  1. In — the register. Counterparties, properties, ownership relations and compensations in one system with access control. Public-records data fetched via API instead of manual lookups. Login through the customer's existing identity provider, roles per user. The data model handles the real world: multiple owners per property, properties owning properties, associations with up to 80 part-owners.
  2. During — control & status. Real-time status per counterparty and project, reminders when something stalls, a document inbox where scanned signed agreements are AI-matched to the right project, property and person (auto-approve above a confidence threshold, otherwise one-click confirm).
  3. Out — GDPR & delivery. Retention rules and masking logic per field type run automatically. A delivery log proves what was delivered and when — so the organisation finally dares to delete. The final-delivery pipeline converts and assembles building documents to the client's template with bookmarks and drag-and-drop ordering: a day of gluing becomes minutes.

When data leaves Excel, GDPR becomes a property of the system instead of something someone must remember.

03

Architecture

Architecture

How it’s put together.

Web application in the customer's own cloud tenant — no data passes through us, infrastructure billed at cost. Identity via the existing Microsoft environment; read integration against public property-data APIs; file storage tied to the register; a rules engine for retention, masking and status triggers; PDF generation and file conversion (Word/Excel/DWG/DXF). Add-ons priced separately: client delivery receipts, agreement generation, postal and digital-mailbox integrations.

04

Questions about registers

Questions about registers

How do we get personal data out of a shared Excel file?

By moving the register into a system that owns the rules instead of asking people to remember them. Access, masking, retention and the delivery log become properties of the platform. Records expire on their own schedule, deliveries are produced rather than glued together by hand, and who saw what is recorded without anyone having to note it.

Sound like your Tuesday?

Your operation is the next case.

Book a diagnostic