Back to Rowpa

Trust & Transparency

Last updated: 29 April 2026

Rowpa uses AI to generate drafts, not to make compliance decisions for you. You maintain full control over all outputs. Your data is never used to train models or develop our product. We are transparent about what we do, what we do not do, and where AI can fail.

Our Principles

AI generates drafts, not decisions

We use Anthropic's Claude API to accelerate your compliance work by generating draft documentation, policies, and assessments. You maintain full control and make all final decisions. AI is a tool to reduce manual effort, not to make autonomous choices about your compliance posture.

Your data is yours

We do not use your data to train AI models, build competitive intelligence, or improve Rowpa. We treat your organization and its data as confidential. What you upload stays yours, and your workspace data does not inform model training or product development.

We say what we do not do

Rowpa does not offer legal advice. We do not guarantee regulatory approval or audit outcomes. We do not make binding compliance determinations. Rowpa assists with compliance work, reduces manual effort, and organizes your controls, but does not replace qualified legal or compliance counsel.

What Rowpa does

Rowpa integrates Anthropic's Claude AI to help you with six core compliance functions:

1. Site scanning

Rowpa scans your website to detect technology, cookies, trackers, and third-party tools in use, then maps these to compliance risks and privacy implications.

2. ROPA generation

Rowpa generates Records of Processing Activities by ingesting your business description, business type, scale, and existing processing activities, then producing a draft ROPA in Rowpa format or for export.

3. Compliance resolution

Rowpa generates privacy policies, cookie policies, and terms of service tailored to your business, technology, and regulatory scope. All outputs are drafts for your review.

4. Vendor enrichment

Rowpa maintains a library of 300+ verified vendors and tools, enriched with AI-generated summaries of their privacy practices and compliance features. Rows are updated regularly and marked with confidence signals.

5. DSR drafting

Rowpa generates templates and workflows for Data Subject Requests, helping you map requests to your systems, generate response letters, and track timelines.

6. Regulatory monitoring

Rowpa helps you stay aware of upcoming regulatory changes and vendor announcements relevant to your industry and compliance scope.

Data flow and AI processing

When you use Rowpa's AI features, the following data is sent to Anthropic's Claude API:

  • Your business name, website, and description
  • Your business type and employee count
  • Your ROPA entries (processing activity descriptions, vendors, legal bases)
  • Your stated compliance scope (GDPR, SOC 2, ISO 27001, etc.)
  • Publicly available information from your website (technology stack, trackers detected)
  • Prompts and context you provide within the app

Anthropic does not use data sent via their API to train models. Their API data usage policy confirms that inputs and outputs from the API are not used for model training. Data is processed on Anthropic's infrastructure in the United States. Your workspace data and AI requests do not inform Rowpa's product development.

We do not use automated decision-making that produces legal effects concerning you. AI outputs are drafts for your review, and you control what is published, exported, or deployed.

Confidence and accuracy

AI can hallucinate, misinterpret regulations, or produce incomplete or incorrect guidance. Rowpa surfaces confidence signals in the interface to help you identify where output should be treated as a first draft and sent to subject matter experts for validation.

Always validate AI-generated compliance materials against current regulatory text, your legal counsel, and domain experts before deployment. Rowpa reduces manual effort and organizes your thinking, but does not replace expert review.

Vendor library accuracy

Rowpa maintains a curated library of 300+ compliance frameworks, standards, and vendor security profiles. These rows are AI-enriched with summaries of privacy practices, but are marked with confidence signals and updated regularly. They may lag regulatory changes or vendor announcements.

Use Rowpa's vendor library as a starting point, then verify critical information against authoritative sources (regulator websites, vendor security pages, updated standards documents).

Related pages

Security and infrastructure
Privacy policy
Cookie policy
Contact compliance team
TeZe Ltd
Company number 17137231
Brighton and Hove, England

For questions about this page or Rowpa's trust practices:
compliance@rowpa.app