Skip to content
gdpr / hipaa / data mapping

Compliance reviewed in the product, not in the policy

We map how your product collects, stores, transfers, and deletes personal and health data, compare it against GDPR and HIPAA, and hand back a prioritised gap analysis your engineers can build from.

Why a compliance review

A privacy policy is a description of a system. The gaps that matter are in the system: the analytics SDK sending identifiers off-platform, the export endpoint with no rate limit, the backup nobody set a retention on. Those are found by reading the product, not the policy.

01

Compliance is an engineering problem

Minimisation, access control, encryption, retention, audit logging, and deletion are all things the code either does or does not do. We review the code, the schema, and the infrastructure — where the answers actually are.

02

An engineering review, not legal advice

We assess your product against the requirements and give you the gap list and the fixes. We are not a law firm and not a certification body: your counsel or accredited auditor makes the legal call, and this review is built to make their job cheap rather than to replace it.

03

Both regimes in one pass

GDPR and HIPAA overlap heavily — minimisation, access control, encryption, breach notification, retention, third-party agreements. Reviewing them together costs far less than two engagements and stops one regime’s fix breaking the other’s requirement.

04

A data map you did not have

The review starts by inventorying every field of personal or health data, where it enters, where it lands, who can read it, and when it dies. Most teams have never had this written down, and it stays useful long after the audit.

05

Third parties count as you

Analytics SDKs, error trackers, hosting regions, sub-processors, and AI vendors all touch the same data, and the regulator holds you responsible for them. They are in scope, including where the data physically goes.

06

Built to be re-run

You get the checklist the review was run from, mapped to your architecture — so a new feature can be checked against it before launch instead of reopening a gap you already closed.

What we deliver

01

Data Inventory & Flow Map

Every category of personal and health data your product touches, mapped from collection through processing, storage, third parties, and deletion — with the cross-border hops named.

02

GDPR Gap Analysis

Consent and preference handling, data-subject access, export and erasure, retention, encryption, breach detection and notification readiness, sub-processor coverage, and international transfers — each reviewed as implemented, not as documented.

03

HIPAA Safeguards Review

The technical and administrative safeguards as they exist in your system: access control and unique identification, audit logging, integrity and transmission security, PHI handling and minimum necessary, plus where a Business Associate Agreement is missing.

04

Prioritised Remediation Plan

One ranked list of gaps, each with the requirement it maps to, the risk it carries, and the specific engineering change that closes it — walked through with your team, and implemented by us if you want it done.

Process

  1. 01

    Map

    We inventory the data your product handles and trace every path it takes — through your services, your vendors, and your backups.

  2. 02

    Assess

    The map is compared against the GDPR and HIPAA requirement sets, and every gap is written up with the requirement it fails and the evidence for it.

  3. 03

    Remediate

    You get the ranked plan and the reusable checklist. We implement the fixes if you want, then re-check the gaps and confirm which are closed.

Faqs

Common questions about our compliance reviews

It tells you exactly where you are not, and what to change. Compliance is a legal status, not a deliverable an engineering firm can hand over — no consultancy can certify you against GDPR, and HIPAA has no official certification at all. What we provide is the engineering gap analysis and the fixes, which is the part your counsel or auditor cannot do for you.

No. We are engineers, not lawyers. We read your system against the published requirements and report what does not meet them. Interpretation calls — lawful basis, contractual positions, regulatory correspondence — belong to your counsel, and our report is written to be handed straight to them.

Yes. A European SaaS with no health data usually needs GDPR only; a US health product often needs HIPAA first. We scope to what applies. The pages overlap enough that doing both together is normally cheaper than doing one now and one later.

Read access to the codebase and infrastructure configuration, your list of third-party services and sub-processors, and an hour with whoever knows the data model best. Everything is covered by an NDA signed before access.

Yes — they are usually where the surprises are. Any vendor that receives personal or health data is in scope, including what it retains, where it processes, and whether the agreement covering it exists.

Yes. Encryption, access control, audit logging, retention and deletion jobs, consent handling, and export and erasure endpoints are ordinary engineering work, and we build products for a living. The review and the remediation can be one engagement or two.

Let’s talk

Book a call with our CEO

Portrait of Denys Havryliak, Founder & CEO of Applefy

Denys Havryliak

Founder & CEO

  • 10+ years in software engineering
  • Master’s in cybersecurity
  • Deep, current knowledge of AI tooling

You’ll talk to the person who builds. Denys works hands-on across product, architecture, and delivery — and keeps a close watch on what today’s AI tooling can genuinely do in production, not just in a demo.