Prudence, by Runciter

Compliant on day one.

Compliance here means adherence to the obligations set out in Regulation (EU) 2016/679, as tracked in the compliance guide and evidenced by your own register. Prudence is not a certification and does not issue one.

Your first day starts with every process written and every template ready. You answer ordinary questions about how the business runs. Prudence turns the answers into evidence an authority, an auditor or a customer will praise.

Compliant with
GDPRISO/IEC 27701HIPAAGxP Validated
  • The demo opens without a signup
  • Every document included, yours to keep
  • All the help you will ever need

Everything an authority asks for, ready and available in one click.

The Record of Processing Activities, kept for you

Article 30(1) requires the record in writing. Prudence asks ordinary questions about how the business runs and produces it, complete with purposes, lawful bases, categories, recipients, transfers and retention. It is the first document an authority asks for, and it exports in one action.

The document set, already drafted

Privacy notice, data protection policy, Article 28 processor terms, breach procedure, request procedure, Data Protection Impact Assessment and Transfer Impact Assessment templates. Put your name on them, approve them, and they are your own documents, yours to keep.

The clocks the regulation runs

Seventy-two hours to notify a breach under Article 33(1). One month to answer a request under Article 12(3). A processor with no contract signed. A notice untouched for two years. Prudence counts each one down, names an owner and holds the date.

A worked example

What follows is an illustration, not a customer. Northbrook Clinic is an invented company, used here to show how Prudence reads an ordinary set of answers.

In this example, a small clinic answers eight questions. Two breaches surface.

The clinic is invented, the situation is not. Patient notes are health data under Article 9(1), so the processing needs a condition in Article 9(2) and, here, a Data Protection Impact Assessment under Article 35(3)(b). One processor types up dictated notes in the United States, so Chapter V applies. Nobody set out to break a rule. Prudence names each problem, cites the article behind it, and puts an owner and a date against it.

Gaps identified · 2

  • The transcription service sends data to the United States

    Transfer agreement

    Add a transfer agreement before this activity can be approved.

    Open the record ↗
  • No signed contract with the practice system supplier

    Contract

    A supplier that handles patient data requires a written agreement.

    Open the record ↗
Follow the whole example ↗

The documents

The documents become yours, not borrowed.

Put your logo on them, approve them, and run the business on them. Show them to a customer, an insurer, an auditor or a supervisory authority as your own. The licence over every document you have already adopted survives the end of the subscription.

Each document is linked to the records it covers. Change a processor, a transfer or a purpose and Prudence names the documents that now need another look, before an inspection does.

Look inside before you decide.

Fourteen days trial, no card required