Newa supplier pack for whoever asks, and questionnaire answers drafted from your record.See it live →See the demo →
■GDPR documents for when a customer asksAnswers for when they send a questionnaireA sub-processor list for when they look firstUK & EU

A customer asked for your GDPR documents. Send them today.

Enter your website. Rowpa reads it, drafts your record, your policy and your supplier checks, and turns them into the pack a procurement team asks for or the answers to the questionnaire they sent. You review everything before it leaves. The scan takes seconds. The record is designed to take under an hour.

Check the questionnaire they sentStart your free scan

Build your whole record free. Pay only when you send something. No card.

scanning yourstore.comlive
ToolLegal entityAgreement
Google AnalyticsGoogle LLCneeds DPA
Meta PixelMeta Platforms, Inc.joint controller
StripeStripe, Inc.DPA on record
MailchimpIntuit Inc.needs DPA
HotjarHotjar LtdDPA on record
Third parties found on your site5 in 1.2s
01 / The ask

Whatever shape the ask arrives in.

02 / No login

Look before you sign up.

Three real things, no login.

Trust Center published 2 July 2026. The Trust Center and the list belong to a fictional shop, published with Rowpa.

03 / How it works

Four steps. The first three are designed to take under an hour.

01

It discovers your business

Enter your name and website. The AI scans for the tools, trackers and scripts it recognises, classifies your business, and drafts a compliance profile. You confirm what it found and add anything it missed.

02

It builds your ROPA

Your full Article 30 record, mapped from your profile. Every activity gets a legal basis, a retention period, a vendor. Where the AI is unsure, it says so plainly and flags it for you. Never a silent guess.

03

It answers the ask

A customer wants your GDPR documents: Rowpa assembles a supplier pack addressed to them, one link or a PDF. They send a spreadsheet: Rowpa drafts the data protection rows from your record and the MFA, backup and patching rows from a security profile you fill in once, with the evidence beside each answer, marks the rows only you can answer, and writes the approved answers back into their file.

04

You can see when they read it

Your Trust Center and every pack link count their readers, so you know when to stop chasing. Your privacy policy is generated from your ROPA, and flagged when your record moves on without it. Weekly monitoring of ICO guidance and vendor changes tells you when something needs your attention.

What changed on 19 June 2026

The Data (Use and Access) Act makes four things mandatory for every UK organisation: provide a complaint form completable electronically, acknowledge each complaint within 30 days, keep records of how complaints were handled, and update your privacy notice. There is no SME exemption. Rowpa drafts these materials from your business profile for you to review.

Get the free template →
04 / The demo

See it live

Rowpa itself, running on a fictional company's data: the workspace, a supplier pack ready to send, and a questionnaire half answered, with the rows only the owner can answer marked as such. Nothing there belongs to a real business, and nothing you do changes anything.

Open the demoOr scan your own site above: it names the tools you run and whether it can find your policy.
05 / One URL

One URL, and one pack, for whoever asks.

When a prospect asks “how do you handle our data?” you paste one link. Your Trust Center shows your ROPA summary, sub-processors with DPA links, security overview, privacy policy, DSR submission form, DUAA complaints intake, and breach disclosures, with a Rowpa review badge and the date it was last reviewed. Your sub-processor list gets its own address a DPA can quote, and customers can ask to be emailed when it changes. When procurement wants a document to file, you send a supplier pack instead: the same record, addressed to them, as a link you can revoke or a PDF, with your insurance certificates attached.

Think of it as a lightweight version of what Vanta charges enterprise teams thousands for.

trust.yourbusiness.com
Record of Processing Activities current
Sub-processors, with DPA links 12 listed
Security overview auto
Data subject request form live
DUAA complaints intake live
06 / Why now

Nobody starts this because of a fine.

They start because a customer asked. The numbers below are real and sourced, and they are the reason the asking keeps getting more thorough: your client has their own auditor to answer to, and increasingly a questionnaire to send you.

42%

of UK firms have been asked by a partner to prove their compliance; 36% by a customer or prospect

CyberSmart, 2025
5% to 12%

small businesses holding Cyber Essentials, up in one year, driven by requests from customers, insurers and tenders

Cyber Security Breaches Survey 2025/26
In force

The DUAA complaints-procedure requirement, in force since 19 June 2026. No SME exemption.

DUAA 2025
07 / Provenance// compliance is no place for a black box

An auditor will ask how you got here. You should have an answer.

Every record, policy, assessment and response is a draft until you approve it. Nothing is published on its own. Every AI action is logged with a timestamp, the model used, what it looked at and what it concluded. When the ICO asks how you arrived at an assessment, that is your answer, with full provenance.

01

You approve everything

The AI drafts. Where it is less certain, it tells you. Nothing is actioned without your review.

02

Every decision is logged

Timestamp, model, inputs, conclusion. Regenerate an assessment and the old version is still there.

03

Vendor data from the source

DPA links and sub-processors are sourced from vendor pages, with confidence signals, source health and review prompts.

08 / Who it is for

Built for businesses like yours

If you handle personal data but don't have a DPO or legal team, Rowpa is built for you.

Also: accountants · solicitors

08b / Try it without signing up

Six tools, free, no account.

If a customer has just asked you for something, start here. Nothing to install, nothing to sign up for.

All six at rowpa.app/tools

09 / What you get

What a privacy consultant would build for you.

What you send

Your record. What all of it is built from.

Every section of a pack and every questionnaire row Rowpa can evidence comes from here. It is free to build, Rowpa keeps it current, and you pay only when you send.

05ROPA generationYour full Article 30 record, built from your business profile and the scan of your site. The AI flags anything that needs your input, so you know where to focus.
06Living privacy policyGenerated from your ROPA, not from a template. When the record changes, Rowpa flags the policy as out of date and regenerates it with one click.
07Security posture, answered onceThirty-six plain questions about your IT, forty-one if you build software, answered once. They feed the pack, every questionnaire row about security, and the UK Cyber Essentials self-assessment.
08Vendor DPA library, 418 toolsNot just “Mailchimp” but Mailchimp by Intuit Inc., with a DPA status, transfer mechanism and plain-English risk note linked to source evidence for your review.
09A score you can act onOne number built from your real records. It fills in as your ROPA, retention and vendor DPAs fall into place, and points at the one thing still waiting on you.
10Risk radarA new tracker on your site, a vendor that changed its DPA, fresh ICO guidance. Rowpa flags it with a severity rating and tells you what to do about it.
11AI-drafted DSR responsesA subject access request arrives. Rowpa drafts the response from your record, gives the person a private page to follow it on, and tracks the calendar month.
12DUAA complaints procedureRequired of every UK organisation since June 2026. Rowpa writes the procedure, hosts the intake form, and tracks the 30-day acknowledgement on each complaint.
13Breach response plannerIf something happens, Rowpa works through severity with you, says whether the 72-hour notification applies, and keeps a record of how you decided.
10 / The founder

Why Rowpa exists

I spent years building compliance tools for enterprises with privacy teams and six-figure budgets. Then friends running a Shopify store and an eight-person SaaS asked the same quiet question: do I actually need to worry about this. The answer was yes, and I had nothing practical to point them to.

The same law applies to a five-person company as to a multinational. The tooling never should have. Rowpa supports the documentation work a privacy consultant may help with, and you review all of it.

Tomasz Smieja, founder
CIPP/E · CIPM · FIP · IAPP-certified privacy professional
What the monitor picked up, across 10 official sources
ICO · direct marketing · 27 AugustUODO · breach notification · 25 SeptemberCNIL · lawful basis · 24 SeptemberEDPB · lawful basis · 23 SeptemberAEPD · AI processing · 23 SeptemberBfDI · lawful basis · 11 SeptemberLfDI BW · lawful basis · 11 SeptemberHmbBfDI · AI processing · 10 SeptemberICO · lawful basis · 11 AugustICO · vendor management · 7 AugustICO · direct marketing · 27 AugustUODO · breach notification · 25 SeptemberCNIL · lawful basis · 24 SeptemberEDPB · lawful basis · 23 SeptemberAEPD · AI processing · 23 SeptemberBfDI · lawful basis · 11 SeptemberLfDI BW · lawful basis · 11 SeptemberHmbBfDI · AI processing · 10 SeptemberICO · lawful basis · 11 AugustICO · vendor management · 7 August
11 / Pricing

Simple, honest pricing.

Build your whole record free. Pay when you send a pack or a questionnaire: once, or on a plan. Prices ex VAT. No long-term contracts.

Pack Pass£39 once

One supplier pack for one customer. Regenerate it as often as you like for a year, share it by a link you can revoke.

Questionnaire Pass£79 once

One security questionnaire, up to 300 questions, drafted from your record and written back into the file they sent you.

No card on file, nothing to cancel. Buy a pass, subscribe within 30 days, and it comes off your first payment.

Free
£0
/month
For seeing the whole thing before you pay
  • 1 user
  • Unlimited activities
  • Unlimited vendor library
  • Preview packs and questionnaires
Start free
Business
£79
/month ex VAT
For the firm that gets asked every month
  • 5 users
  • Everything in Starter, plus:
  • Unlimited supplier packs
  • 12 questionnaires a year
  • Automated site scanner
  • DPIA tool
  • Breach response planner
  • Compliance score tracking
Get Business
Business Plus
£159
/month ex VAT
For the firm that gets asked every week
  • Unlimited users
  • Everything in Business, plus:
  • 36 questionnaires a year
  • Your own domain for published pages
  • Your logo, colours and footer line
  • Priority support
Get Business Plus
What Rowpa is
An AI-powered compliance platform that does the heavy lifting for youAI-generated ROPA, policies, and DSR responses you review, edit, and exportA sourced, AI-enriched vendor library with legal entities, DPA links, and review signalsWeekly monitoring of regulatory changes, vendor updates, and new ICO guidance
What it isn't
Legal advice, every output is a draft for your reviewA substitute for a DPO if you are legally required to appoint oneSuitable for special category data without professional oversightA replacement for qualified counsel if you are facing ICO enforcement
12 / Questions

Common questions

6 of 19
A customer sent us a security questionnaire. What does Rowpa actually do with it?
You upload the spreadsheet they sent (xlsx, xlsm or csv) or paste the questions. Rowpa shows you how it read the columns and waits for you to confirm. It then drafts every row it can evidence from your own record, with the source beside each answer, and marks the rest as rows only you can answer. In a general vendor security assessment the data protection rows are usually around a tenth of the sheet; the rest is MFA, backups, patching and the like. Those come from your security posture profile: thirty-six questions about your IT, answered once as yes, partly, no or not sure, which Rowpa drafts from and never embellishes. What is left is the specifics only you know, such as a penetration test summary or an insurance limit. You approve, edit or skip each row, and the approved answers are written back into their file in their layout.
What is in a supplier pack?
A cover addressed to whoever asked, then: how you handle personal data, what you do with it, sub-processors and suppliers with DPA status, international transfers, AI tools in use, security measures, what happens if something goes wrong, complaints, data subject rights, policies and procedures, how the record is kept current, and an attestation by a named person. Every section comes from your record; nothing is written for the pack alone. You can leave sections out. It goes out as a link you can revoke, with or without asking the reader for their email, or as a PDF.
Can I see a pack before I sign up?
Yes. The demo shows a finished pack and a questionnaire mid-review on a fictional company, and the supplier pack page walks through every section of a sample. Nothing in either belongs to a real business.
What do the passes cost, and what happens after I buy one?
A Pack Pass is 39 pounds once: one pack for one customer, regenerated as often as you like for a year, share link included. A Questionnaire Pass is 79 pounds once: one questionnaire of up to 300 questions, written back into the file they sent. No card is kept on file and there is nothing to cancel. If you subscribe within 30 days of buying a pass, the pass comes off your first payment.
How long does setup take?
Setup is designed to be completed in under an hour. The AI drafts everything from your website scan; you review each processing activity, confirm vendors, and add any tools we missed.
Does GDPR apply to my business?
If you collect or use personal data from people in the UK or EU, yes. That includes customer emails, employee records, website analytics, contact forms, and payment details. It applies to businesses of any size, not just large companies.

The hard part was never the work. It was not knowing where you stood.

Start your free scanThe record is free. No card.