Use Case
GDPR-Compliant, Zero-Knowledge Data Collection
Collect personal data through a zero-knowledge intake — encrypted in the browser so even we can't read it — with an audit trail, right-to-erasure by crypto-shredding, and EU data residency. Built for GDPR, UK GDPR, PIPEDA, and CCPA/CPRA.
Handle Personal Data ResponsiblyThe Problem
Personal data sits in inboxes anyone can read
Email and generic forms leave personal data readable by your provider, your staff, and anyone who breaches the mailbox — with no record of how it arrived.
A breach means notifying regulators and data subjects
When you hold readable personal data, a leak can trigger breach-notification duties. Data you can't read yourself is a smaller, different risk.
Data leaves your jurisdiction the moment you use a cloud form
International-transfer rules and data-residency requirements are hard to meet when the tool decides where personal data lives.
You can't show how data was collected, or delete it cleanly
Answering access and erasure requests from scattered email threads is slow and incomplete, and proving how data was handled is nearly impossible.
How it works
Collect through a zero-knowledge request
Personal data is encrypted in the data subject's browser before it reaches **doconvoy**. We store ciphertext we can't read; you hold the keys and decrypt when you need it.
Keep the data in the EU
**doconvoy** hosts application data with AWS in the EU, so personal data stays in a known region, not wherever a vendor happens to put it. A self-hosted option for stricter residency needs is on our roadmap.
Track each data subject with an audit trail
Every submission is logged against a data subject: when the request was sent, opened, and submitted. Access requests are answered from one place, precisely.
Honor deletion with crypto-shredding
When an erasure request arrives, delete the submissions or forget the person — doconvoy destroys the keys, so the content becomes unrecoverable at once. The log keeps proof the deletion happened, without the content.
Benefits
- —Encrypted in the data subject's browser — doconvoy stores ciphertext it can't read
- —Data you can't read is a smaller breach-notification risk
- —EU data residency (hosted with AWS in the EU); self-hosting on the roadmap
- —Full audit trail of how and when each record was collected
- —Access, portability, and right-to-erasure answered from one place
- —Data minimization by design: scoped requests with automatic expiry
The hard part of privacy law is proving how you collected the data — and not being able to leak it
GDPR in the EU, UK GDPR and the Data Protection Act, PIPEDA in Canada, CCPA and CPRA in the US: the specifics differ, but they share a spine. Collect lawfully and minimally, document how you did it, honor data-subject rights, and answer for a breach. The keyword changes by jurisdiction; the obligations rhyme.
If your collection process is "we emailed them and they replied with their details," you have almost nothing to show. The data exists, readable, in an inbox. You can't prove how it arrived or what protected it, and if that inbox is breached, so is the data.
Collect what you can't read
A doconvoy request encrypts personal data in the data subject's browser before it reaches our servers. We store ciphertext, not readable data, and you hold the keys. That changes your exposure: there is no readable copy sitting on a vendor's server to leak or to be compelled to produce, and strongly encrypted data you can't read is treated differently under most breach-notification rules than plaintext in an inbox.
It is the difference between "we hold everyone's personal data in the clear" and "we hold data only the client and we can unlock."
Keep personal data in the EU
Cross-border transfer is one of the hardest parts of modern privacy law. doconvoy hosts application data with AWS in the EU, so personal data stays in a known region rather than wherever a SaaS vendor happens to put it. And because what you collect is encrypted before it reaches us, we only ever hold the scrambled result. For teams with stricter residency requirements, a self-hosted option is on our roadmap — it isn't available today.
Prove how it was collected
Every intake creates a verifiable record from the moment data arrives: when the request was created and sent, when the data subject opened it, when they submitted, and how their identity was confirmed. You have evidence of the collection event itself, which is exactly what the accountability principle asks for and what an email thread can't give you.
Answer access and erasure requests cleanly
Each submission is tied to the submitter's identity, creating a data-subject record in your workspace. When someone asks what you hold on them (a subject access request, GDPR Article 15), you query that identity, answer precisely, and can export the data for a portability request. When they ask you to delete it (the right to erasure, Article 17), you remove their submissions or forget the person — doconvoy destroys the keys (crypto-shredding), so the content becomes unrecoverable immediately, backups included. The audit log keeps a record that a deletion occurred, without the content.
Data minimization by design
Requests are scoped to exactly what you need, and you can set an expiry date after which a submission is automatically invalidated. Collection that doesn't accumulate data beyond its purpose is data minimization in practice, not only on paper.
What doconvoy doesn't replace
We provide the encryption, the audit trail, EU hosting, and a Data Processing Agreement you can sign. We don't provide legal advice or compliance certifications, and no tool makes an organization compliant on its own. How doconvoy fits your posture under GDPR, UK GDPR, PIPEDA, CCPA, or any other regime is a question for your context and your counsel. What we can say is that the data is encrypted before it reaches us, the audit trail is yours, and the data is hosted in the EU.
For a related workflow, see KYC & Identity Document Collection, or explore Secure Requests and the Audit Trail.
Handle sensitive client information securely — from onboarding to handoff. Try any workspace free for 3 days — no credit card required.
Handle Personal Data Responsibly