Data protection and AI rules for businesses
We set up data protection basics and AI rules before going live. Your lawyer supplies the final text.
AI-generatedData protection built in before anything goes live.
Data protection basics
Consent banner, locally hosted fonts, legal text templates and a model data processing agreement.
More details
- How it works: We check which services your website and processes use, then set up consent, fonts and templates.
- You provide: A list of your services. Your lawyer or data protection officer reviews the final legal text.
- Watch out: Mandatory details such as the controller or supervisory authority are often missing.
AI policy
An internal rule: what your team may do with AI and who is responsible.
More details
- How it works: We draw up principles and responsibilities for using AI in your business.
- You provide: Which AI tools are already in use.
- Watch out: A policy only works if your team knows it.
Risk assessment
We assess which AI applications are sensitive and name measures in advance.
More details
- How it works: We classify the system and derive measures, such as an age limit.
- You provide: What the system does and with which data.
- Watch out: Your data protection officer decides whether an impact assessment is needed.
Data protection check of your workflows
Which data goes where: from the web form to the AI service.
More details
- How it works: We map the path your data takes and check where a data processing agreement is missing.
- You provide: Access to the programs that pass data on.
- Watch out: Services added along the way don’t appear on any list.
Example: checklist before going live
- Website: Consent before analytics, fonts hosted locally.
- Form: Which data goes where?
- AI service: Does customer data leave the company? DPA in place?
- Team: Who may do what with AI?
How it works
Initial consultation
You tell us about your website, programs and AI tools. We tell you where we would look first.
Review and set up
We check data flows, set up consent and fonts, and draft the AI policy.
Handover to your lawyer
You receive templates and models. Your lawyer reviews the final text.
Quick check: where should you take a look?
Five yes/no questions. Your answers stay on this page; nothing is stored or sent.
Prefer a quick call?
Good to know
Not legal advice
We handle the technical and organisational setup. Review and approval lie with your lawyer.
You stay in control
AI gets limited permissions, a person approves critical steps, and everything is logged.
Data minimisation
We only work with what you show us.
You remain responsible.
From client projects
Data protection basics are live in three client projects, from consent to the privacy notice. One association has its internal AI policy in place.
Frequently asked questions
Will everything then be GDPR-compliant?
We set up the data protection basics properly. Whether your business meets all requirements is for your lawyer or data protection officer to check. We do not provide legal advice or guarantees.
Do you write my privacy policy?
We provide a template and match it against the services you actually use. Your lawyer or data protection officer provides the final text.
Do I need a data processing agreement for AI services?
That depends on which data goes to which service. We clarify this in the data flow check. A model agreement is available; your lawyer reviews it.
What goes into an AI policy?
Principles for using AI and who is responsible in your business. It is an internal rule for your team, not a legal opinion.
Do we stay in control of AI agents?
Yes. AI agents only get limited permissions, critical steps such as sending emails stay with a person, every action is logged and every workflow can be paused.

Let’s talk about your data protection.
Free initial consultation, no obligation. You leave with a first assessment of where to look first.
The cost depends on the number of services, systems and AI applications.
- Process Vision, Zwickau, Saxony
- Industry experience since 2015
- Focus: AI integration for SMEs