GDPR compliance software · made in Italy
Your company's privacy, finally under control.
PrivacyGate brings together, in a single dashboard, everything the GDPR requires: data subject rights, the processing register, data breaches, risk assessments, consents, privacy notices and supplier agreements. No more scattered spreadsheets: a register that's always ready for an inspection.
In short: PrivacyGate is a multi-tenant Italian software platform that helps controllers, DPOs and privacy managers handle GDPR and Italian Privacy Code obligations — data subject rights, processing register, data breaches, DPIA/LIA, consents, privacy notices, DPA agreements, authorized personnel, training and company documents — with data hosted in Italy, a tamper-evident event log and an art. 28 agreement already in place for the client. It does not provide legal advice and does not replace the DPO.
Why it matters to whoever runs the company
Non-compliance costs more than the software
The GDPR (art. 83) provides for fines of up to €20 million or 4% of global annual turnover, on top of reputational damage and the time lost reconstructing, too late, what should have been documented from the start. PrivacyGate turns a regulatory obligation into an ordinary, verifiable process.
How it works
From activation to the first audit, in four steps
Activation
The company's tenant is created with the base registers, with Innhova already set up as processor for the platform, DPA included.
Setup
The controller, DPO and privacy manager record processing activities, departments, authorized personnel and suppliers: each with their own role and permissions.
Day-to-day management
Data subject requests, consents, breaches and deadlines are all handled from the same dashboard, with automatic reminders.
Evidence at any time
Every event stays on record with its own fingerprint: in case of a check, the documentation is already ready to export.
The whole GDPR, one module at a time
One platform, every obligation
Each module covers a specific obligation of Regulation (EU) 2016/679 and the Italian Privacy Code, with the reference articles always cited in the interface.
Rights and transparency towards data subjects
Data subject rights (art. 15-22)
Intake, handling, deadlines and responses for access, rectification, erasure, portability and objection requests, with automatic reminders and a dedicated portal for the requester.
Consents and acknowledgements (art. 7)
Tamper-evident register with a chain of fingerprints, the exact text of the notice shown, the collection method, double opt-in and an API for collecting consents from external sites and apps. For consent-based purposes, the data subject can consent directly from the public page of the privacy notice, confirming by email.
Privacy notices (art. 13-14)
A single template for one or more categories of data subjects and processing activities, published in HTML from a dedicated link, downloadable as PDF, with an immutable version history. Also available in English, French, German and Spanish, with an AI-proposed translation reviewed by the DPO before publication.
Risk, security and assessments
Data breach register (art. 33-34)
Logging, risk assessment and notification to the supervisory authority with the 72-hour timer, communication to data subjects when required and documented reasoning when it is not.
DPIA and LIA (art. 35 and 6.1.f)
Data protection impact assessments with the WP29 checklist, risk analysis and an action plan, plus legitimate interest balancing tests with the DPO's opinion.
Processing register (art. 30)
Purposes, legal bases, categories of data and data subjects involved, use of AI systems and automated decision-making, security measures: all linked to privacy notices and consents.
People, suppliers and evidence
Relations and DPA register (art. 26 and 28)
Review queue for forms submitted by suppliers, generation of the appointment agreement and electronic signature with OTP verification by email, signature certificate included.
Authorized personnel (art. 29)
Named designations by department and role (manager, coordinator, staff member), with the processing activities allowed for each role and an electronically signable appointment.
Training and company documents
A register of courses with enrollees and completions, and a register of versioned procedures, guidelines and policies, with staff acknowledgement via OTP signature.
Additional obligations and documentary evidence
Cookies and tracking (art. 122 Italian Privacy Code)
Automatic site scanning, recognition of the most common trackers, an embeddable consent banner and a cookie register confirmed by the DPO, with the panel reopenable for visitors.
Video surveillance (art. 4 Workers' Statute)
Register of installations with purposes, areas covered, retention periods, signage and extended notice generated automatically, and a register of access to footage.
Systems, measures and retention (art. 32)
A security profile for each system, a catalogue of measures with their status, retention periods by data category and automatically calculated deviations.
Accountability and audits (art. 5.2 and 24)
Internal and external audits with checklists, corrective actions with effectiveness checks, DPO appointment and review, certifications, and a dashboard that flags deviations across the other registers on its own.
Document archive
Every document produced by the platform lands automatically in organized folders, with SHA-256 fingerprinted versions and controlled sharing with identified individuals.
A plan for every stage of growth
Three plans, one tool
Annual price, excluding VAT. Each plan includes a set of modules; you can upgrade to a higher plan at any time, and modules no longer included remain viewable without losing any data.
Loading plans…
Security and infrastructure
Built to protect the data it handles
A compliance platform must, first of all, be secure: here are the technical and organizational measures in place.
- Encryption of sensitive fields and uploaded files, with keys kept separate from the database.
- Append-only event log, with a verifiable chain of cryptographic fingerprints.
- An isolated database for each client company: no data shared between tenants.
- Encrypted daily backups, with an off-site copy and periodic restore verification.
- Automated weekly security check (dependencies, updates, reboot).
- Strong password authentication and OTP, with distinct roles for the controller, DPO and departments.
Who it's built for
One tool, three points of view
Controller / CEO
Visibility, not detail
A dashboard that shows the company's real compliance status, without having to get into the technical detail of every case.
DPO / Privacy Manager
The register you actually need
All obligations in one place, with deadlines, checklists and documentary evidence ready in case of an inspection by the supervisory authority.
Professional firms
More clients, one tool
Multi-tenant architecture: each client has its own isolated environment, manageable from a single consulting firm.
Frequently asked questions
What people ask us most
What is PrivacyGate?
PrivacyGate is a software platform that brings together, in a single dashboard, all the obligations required by the GDPR and the Italian Privacy Code: handling data subject requests, the processing register, the data breach register, data protection impact assessments (DPIA) and legitimate interest assessments (LIA), consents, privacy notices, agreements with processors (DPA) and staff training.
Does PrivacyGate replace the Data Protection Officer (DPO)?
No. PrivacyGate is the operational tool that the DPO, the controller or the processor use to keep registers up to date, meet deadlines and preserve evidence; it does not provide legal advice and does not replace the role of the DPO under articles 37-39 of the GDPR.
Where is the data stored?
Data is stored on servers in Italy (Aruba S.p.A.), with a dedicated database for each client company, encryption of the most sensitive fields and files, encrypted daily backups with an off-site copy, and an automated weekly security check.
Does PrivacyGate provide an art. 28 agreement (DPA)?
Yes. Innhova acts as processor for the delivery of the platform and makes available a data processing agreement (DPA) under art. 28 of the GDPR, publicly available.
How are consents collected and proven?
Every consent or acknowledgement is logged in a tamper-evident register, with a chain of cryptographic fingerprints, the exact text of the notice that was shown, the collection method and, where applicable, double opt-in confirmation: the goal is to produce, at any time, the evidence required by art. 7 of the GDPR.
How much does PrivacyGate cost?
Three annual plans, excluding VAT: Silver (€1,490) for the base modules, Gold (€2,990) which adds suppliers, DPIA/LIA, training and cookies, and Premium (€5,490) with the entire platform, including the AI features. You can upgrade to a higher plan at any time, and modules no longer included after a downgrade remain viewable without losing any data.
Is PrivacyGate suitable for multiple companies or just one?
PrivacyGate is multi-tenant: each client company has its own isolated environment and database, which makes it suitable both for a single SME and for a professional firm handling compliance for several clients.
Take your company's privacy out of spreadsheets
Get in touch for a demo of the platform or to receive the data processing agreement (DPA) to submit to your DPO.