Enter your website. Rowpa reads it, drafts your record, your policy and your supplier checks, and turns them into the pack a procurement team asks for or the answers to the questionnaire they sent. You review everything before it leaves. The scan takes seconds. The record is designed to take under an hour.
Build your whole record free. Pay only when you send something. No card.
“Please send your data protection documentation”
Sub-processors, transfers, security posture, breach and complaints procedures, policies, your insurance certificates, a named signatory. One link you can revoke, or a PDF. You see when it was opened.
What is in the pack →“Please complete the attached questionnaire”
Upload the file they sent. Rowpa drafts every row it can evidence, from your record and a security profile you answer once, marks the rows only you can answer, and writes the approved answers back into their layout.
How the drafting works →“Where is your sub-processor list?”
One public page with your record, policy and security overview, and a sub-processor list at its own address that a DPA can quote, with an email to customers when it changes.
The published list →Three real things, no login.
Trust Center published 2 July 2026. The Trust Center and the list belong to a fictional shop, published with Rowpa.
Enter your name and website. The AI scans for the tools, trackers and scripts it recognises, classifies your business, and drafts a compliance profile. You confirm what it found and add anything it missed.
Your full Article 30 record, mapped from your profile. Every activity gets a legal basis, a retention period, a vendor. Where the AI is unsure, it says so plainly and flags it for you. Never a silent guess.
A customer wants your GDPR documents: Rowpa assembles a supplier pack addressed to them, one link or a PDF. They send a spreadsheet: Rowpa drafts the data protection rows from your record and the MFA, backup and patching rows from a security profile you fill in once, with the evidence beside each answer, marks the rows only you can answer, and writes the approved answers back into their file.
Your Trust Center and every pack link count their readers, so you know when to stop chasing. Your privacy policy is generated from your ROPA, and flagged when your record moves on without it. Weekly monitoring of ICO guidance and vendor changes tells you when something needs your attention.
What changed on 19 June 2026
The Data (Use and Access) Act makes four things mandatory for every UK organisation: provide a complaint form completable electronically, acknowledge each complaint within 30 days, keep records of how complaints were handled, and update your privacy notice. There is no SME exemption. Rowpa drafts these materials from your business profile for you to review.
Get the free template →Rowpa itself, running on a fictional company's data: the workspace, a supplier pack ready to send, and a questionnaire half answered, with the rows only the owner can answer marked as such. Nothing there belongs to a real business, and nothing you do changes anything.
When a prospect asks “how do you handle our data?” you paste one link. Your Trust Center shows your ROPA summary, sub-processors with DPA links, security overview, privacy policy, DSR submission form, DUAA complaints intake, and breach disclosures, with a Rowpa review badge and the date it was last reviewed. Your sub-processor list gets its own address a DPA can quote, and customers can ask to be emailed when it changes. When procurement wants a document to file, you send a supplier pack instead: the same record, addressed to them, as a link you can revoke or a PDF, with your insurance certificates attached.
Think of it as a lightweight version of what Vanta charges enterprise teams thousands for.
They start because a customer asked. The numbers below are real and sourced, and they are the reason the asking keeps getting more thorough: your client has their own auditor to answer to, and increasingly a questionnaire to send you.
of UK firms have been asked by a partner to prove their compliance; 36% by a customer or prospect
CyberSmart, 2025small businesses holding Cyber Essentials, up in one year, driven by requests from customers, insurers and tenders
Cyber Security Breaches Survey 2025/26The DUAA complaints-procedure requirement, in force since 19 June 2026. No SME exemption.
DUAA 2025Every record, policy, assessment and response is a draft until you approve it. Nothing is published on its own. Every AI action is logged with a timestamp, the model used, what it looked at and what it concluded. When the ICO asks how you arrived at an assessment, that is your answer, with full provenance.
The AI drafts. Where it is less certain, it tells you. Nothing is actioned without your review.
Timestamp, model, inputs, conclusion. Regenerate an assessment and the old version is still there.
DPA links and sub-processors are sourced from vendor pages, with confidence signals, source health and review prompts.
If you handle personal data but don't have a DPO or legal team, Rowpa is built for you.
Also: accountants · solicitors
If a customer has just asked you for something, start here. Nothing to install, nothing to sign up for.
All six at rowpa.app/tools
Every section of a pack and every questionnaire row Rowpa can evidence comes from here. It is free to build, Rowpa keeps it current, and you pay only when you send.
I spent years building compliance tools for enterprises with privacy teams and six-figure budgets. Then friends running a Shopify store and an eight-person SaaS asked the same quiet question: do I actually need to worry about this. The answer was yes, and I had nothing practical to point them to.
The same law applies to a five-person company as to a multinational. The tooling never should have. Rowpa supports the documentation work a privacy consultant may help with, and you review all of it.
Build your whole record free. Pay when you send a pack or a questionnaire: once, or on a plan. Prices ex VAT. No long-term contracts.
One supplier pack for one customer. Regenerate it as often as you like for a year, share it by a link you can revoke.
One security questionnaire, up to 300 questions, drafted from your record and written back into the file they sent you.
No card on file, nothing to cancel. Buy a pass, subscribe within 30 days, and it comes off your first payment.
Nothing matches. Ask us instead: Get in touch