Alapan
Privacy Infrastructure

Privacy controls built into the system that stores the data.

We build consent, data requests, erasure, retention, and audit workflows into custom websites, CRMs, analytics, chatbots, forms, and agentic systems.

privacy.infrastructureactive
Consent
versioned
Requests
tracked
Retention
scheduled
Live audit trail
consent.updatedanalytics grantedsubject
dsar.createdaccess request assignedadmin
retention.queuedchat records near thresholdsystem
erasure.plannedRelationship Intelligence delete + analytics anonymizeadmin
Beyond the banner

A consent banner cannot see where personal data actually goes.

The real privacy work starts after a visitor makes a choice. Requests, deletion, retention, access, and audit records need to understand the collections and workflows behind the interface.

One person, five data locations
01

Website

forms + accounts

02

Relationship Intelligence

contacts + deals

03

Analytics

sessions + events

04

Chatbot

messages + intent

05

Agents

actions + tool calls

What Alapan builds

Privacy workflows that understand the data model.

Tej provides reusable privacy primitives. We configure and extend them around the client's website, Relationship Intelligence, analytics, chatbot, forms, vendors, and operating process.

01

Consent records

Purpose, source, notice version, status, expiry, and withdrawal history.

capture + version
02

Tracking controls

Separate aggregate measurement from behavioural tracking that requires consent.

gate + enforce
03

Data requests

Turn access, portability, correction, restriction, and deletion into assigned workflows.

verify + fulfil
04

Collection-aware erasure

Delete, anonymize, redact, or unlink records according to the data model.

plan + execute
05

Retention schedules

Surface records for review and run configured anonymization or purge jobs.

schedule + log
06

Operational audit

Record consent changes, access, exports, erasure, purges, and admin actions.

observe + prove

Privacy Infrastructure is a technical layer, not a legal guarantee. Legal basis, notices, regulatory interpretation, and retention policy should be reviewed with the client's privacy advisor.

Tracking and consent architecture

Aggregate insight first. Behavioural tracking only when allowed.

The code can separate low-risk aggregate measurement from personal tracking, then apply each consent choice across analytics, Relationship Intelligence enrichment, chatbot behaviour, and personalisation.

Before consentaggregate

Measure the system without building a personal history.

Page totals
Referral source
Device class
Country-level region
After consentpurpose gated

Connect behaviour only to the purposes the visitor accepted.

Visitor history
Relationship Intelligence attribution
Lead scoring
Chat engagement
Requests, erasure, and retention

A request becomes an operational workflow, not a search across vendors.

Access and erasure requests can move through verification, data discovery, policy review, collection-level actions, fulfilment, and audit inside one controlled process.

01

Receive

Capture request type and subject details.

02

Verify

Confirm identity before exposing or changing records.

03

Map

Find records across configured collections and integrations.

04

Review

Apply deletion, anonymization, retention, and legal-hold rules.

05

Fulfil

Export or execute the approved collection-level plan.

06

Audit

Record the actions and preserve the required proof.

Erasure plan · req-1842reviewed
ris-contactsdeleterelationship record
analytics-eventsanonymizekeep aggregate trend
chatbot-messagesdeleteremove conversation
form-submissionsredactretain workflow state
consent-recordsclear PIIpreserve event proof
5
collections
3
strategies
1
audit record
Agentic privacy

When agents process personal data, the system needs accountable records.

An AI agent may create a contact, book a meeting, or invoke another approved action. The privacy layer can record which agent acted, what data was used, the purpose, and the authority for that action.

Agent action receiptsigned
agentbooking-agent
actionris-contact.create
purposemeeting-booking
categoriesname, email, company
authorityvisitor confirmed
timestamprecorded server-side
Privacy operations

One operator view for consent, requests, retention, and audit.

The team can review privacy work inside the admin system it already uses, with queues, deadlines, forecasts, purge history, and recent activity in one place.

Privacy dashboardlive
Consent health
92%
active and current
Open requests
03
all within SLA
Retention review
148
records approaching
Last purge
42
records processed
Request queue
Access requestverified2d left
Erasure requestin review8d left
Portability exportcompiling12d left
Recent activity
consent withdrawnanalytics4m
record accessedRelationship Intelligence contact18m
retention purge42 records1h
Build with Alapan

Build privacy infrastructure into your platform. Not around it.

Bring us your data model, consent needs, vendors, retention rules, and operational workflows. We will map the technical privacy architecture and build the controls into the system.