For bootstrapped and indie SaaS founders

GDPR for indie SaaS. Built by someone who would rather code.

Vanta is £8,000 a year and built for a Series A. Rowpa is £34 a month and built for the founder who knows GDPR is real, doesn't have a compliance budget, and would rather not lose a weekend to ICO docs every time a customer asks a question.

The honest truth

If you've started a SaaS in the last two years and you have EU or UK users, you have GDPR exposure. You also know that the moment a customer asks "are you GDPR compliant?", the answer "we have a cookie banner and a privacy policy from a template" stops working.

Rowpa is the working tool for that exact moment.

What you actually get

01
When the enterprise customer's security team sends a spreadsheet
Upload it. Rowpa drafts the data protection rows from your record with the evidence beside each, marks the rows only you can answer (MFA, backups, patching, pen tests), and writes the approved answers back into their file. For the ones who just want documents, a supplier pack addressed to them: one link, or a PDF.
02
ROPA built from your real stack
Paste your URL. AI scans for trackers, identifies the SaaS vendors you use (Stripe, Supabase, Vercel, Resend, OpenAI, Anthropic, Loops, Cal.com, Cloudflare, GitHub, Linear), and produces an Article 30 record. You review, you ship.
03
Vendor DPA register with source links
400+ vendor records with source URLs, sub-processor information and transfer fields to check. Add anything we don't have and the AI proposes details for your review.
04
Privacy policy generated from your ROPA
Not a template. Reflects what you actually do. When you add a vendor, the policy moves with it.
05
Trust Center URL
One link you can paste into a customer email instead of writing a 40-question vendor security questionnaire response. ROPA summary, sub-processors, security overview, privacy policy, DSR form, complaints intake.
06
Public DSR intake form
Customers who want to access or delete their data have a form, and then a private page where they can see where the request has got to instead of emailing to ask. AI drafts the response with legal reasoning from your ROPA.
07
DUAA complaints procedure
Required for every UK organisation since 19 June 2026. If you have any UK users, you need it. Five minutes to publish.

Pricing

Free - 1 user, unlimited activities and vendors. Build the whole record and preview a pack; you pay when you send one. Starter £34/mo - unlimited ROPA, full 400+ vendor library, living privacy policy, DSR workflow, risk radar, audit-ready PDF export, Trust Center URL. Most indie founders live happily on Starter. Business (£79) when you start running ads and need the site scanner.

Start free See all plans

Common questions

I'm bootstrapped and pre-revenue. Do I need this?
If you have users in the UK or EU, yes. GDPR applies to anyone processing their data. Free tier covers the basics; Starter covers everything when you have paying customers.
Will Rowpa get me through a vendor security questionnaire?
It will draft the data protection rows from your record, with the evidence beside each, and show you exactly which rows only you can answer. In a general security assessment those data protection rows are usually around a tenth of the sheet; the rest is MFA, backups, patching and pen tests, which Rowpa does not record and will not guess. Your own answers to those go into an answer library, so the second questionnaire is faster than the first. For a customer who only wants documents, a supplier pack does the whole job.
Do you compete with ComplyDog?
Partly. ComplyDog is a DSR portal, DPA signing and a sub-processor list, priced in dollars from $49 a month. Rowpa builds the record from a scan, keeps it in several languages, and turns it into supplier packs and questionnaire answers, which ComplyDog does not do. If you are a UK or EU indie SaaS we will generally fit better.
Will Rowpa scale with me?
To about 30 staff or your first SOC 2 audit prep. At that point Vanta or Drata are the right tools and we'll say so honestly. You take your data with you on export.
What about EU AI Act?
GDPR is what we do. AI Act compliance for AI-feature SaaS is on our long-term roadmap. We'll flag where it intersects with GDPR.
I run a side project, not my main job. Does this still make sense?
Yes. The free tier is forever free. If your side project starts taking PII (signups with email is enough), Starter is £34.
GDPR done. Go back to building.

Build the record free. Pay only when you send something. No credit card.

Start free