Organisation and customer data is often spread across more places than people realise. It may be in mailboxes, contact forms, spreadsheets, documents, invoices, cloud folders, website databases, CMS plugins, webshop orders, social media accounts, booking systems, analytics tools, backups and old exports that nobody remembers anymore.
The aim is to understand what data exists, where it is stored, who has access, why it is kept, how it is protected, and what should happen when it is no longer needed. That understanding is necessary before data handling can be simplified, documented, corrected or made safer.
The first step is often to make an inventory. Which systems are used? Where do contact forms send messages? Are customer details stored in a website, mailbox, spreadsheet, webshop, booking system, CRM, accounting program or cloud service? Are there old exports, backups or copies on personal computers?
Mapping this out helps make the situation understandable. It becomes clearer which data is important, which data is duplicated, which accounts control access, which systems are still needed and which old data should be cleaned up or archived more carefully.
Many data problems are access problems. A mailbox may be shared by several people. A website administrator account may still belong to a former employee, volunteer or web builder. A cloud folder may contain customer files but have unclear permissions. A form plugin may store submissions in a database without anyone realising it.
We can help review who has access to which systems, which accounts are personal or organisational, which recovery options are configured, and where two-factor authentication, password managers, administrator roles or clearer documentation are needed. The goal is to reduce accidental loss of access, unnecessary exposure and dependence on one person or one forgotten account.
Websites often collect data through contact forms, newsletter sign-ups, order forms, booking forms, account registrations, analytics tools, embedded services or chat widgets. Sometimes this is necessary. Sometimes the same result can be reached with less data, a simpler form or a clearer explanation.
Part of the work is looking at what each form asks, where the submission goes, whether it is stored, how long it is kept, who can read it, and whether visitors are told what happens with their data. This can also include reviewing CMS plugins, themes, embedded scripts, trackers, spam protection, analytics and external services that may receive visitor or customer information.
Backups are important, but they also contain data. A backup of a website, mailbox, webshop or customer file may include personal information, messages, orders, logs or form submissions. Old exports and test copies can become a privacy risk when they are forgotten or stored in the wrong place.
We can help explain which backups are needed, where they are stored, who can access them, how long they should be kept and how they can be restored. We also look at old copies, development versions, exported spreadsheets and archived files that may contain customer data without being part of the current workflow.
The AVG/GDPR is not only paperwork. It asks basic practical questions: which personal data do you collect, why do you need it, who receives it, how long do you keep it, how is it protected, and what can a person do when they want to inspect, correct or delete their data?
We help make these questions understandable. This can include reducing unnecessary data collection, improving forms, documenting retention choices, preparing privacy text, checking processor relationships, and making sure the practical workflow matches what the organisation says it does.
Business and customer data often passes through other parties: hosting providers, mail services, cloud storage, accounting software, payment providers, booking systems, newsletter platforms, analytics providers, social media platforms or webshop services. These parties may act as processors, independent controllers or something in between depending on the situation.
Where useful, we help identify which external services are involved, what role they play, what data they receive, whether agreements or settings need attention, and whether a simpler or more privacy-friendly setup is possible. The point is not to create paperwork for its own sake, but to understand the real data flow.
Good data protection starts with ordinary practical measures: strong passwords, two-factor authentication, fewer shared accounts, clear administrator roles, regular updates, careful backups, limited access, documented recovery options and avoiding unnecessary copies.
For websites and online systems, this can also include reviewing CMS versions, plugins, themes, server settings, HTTPS, security headers, mail authentication, file permissions, error messages and exposed administrative areas. Security is not a single setting; it is the result of many small choices being kept understandable and maintained.
Sometimes someone asks to inspect, correct or remove their data. Sometimes data is sent to the wrong person, an account is lost, a mailbox is compromised, a website leaks information, or an old system turns out to contain customer records. In those situations it matters that the facts are gathered carefully and that the next step is not based on guesswork.
We can help reconstruct what happened, which systems were involved, what information may be affected, who should be contacted, and what needs to be documented. Where formal legal assessment, notification or representation is needed, specialised legal advice may be appropriate. Our role is practical and educational: making the technical and organisational situation clear enough to act responsibly.
Business and customer data becomes safer when the ordinary working habits are clear. Where are files stored? Which mailbox receives which kind of message? Who updates the website? Who can access customer records? How are passwords shared or not shared? What happens when someone leaves? Where are important decisions documented?
The result does not always need to be a large manual. Sometimes a simple overview of accounts, data locations, access roles, backup locations, retention choices and recovery steps already prevents many future problems. The goal is to make the data handling understandable enough that people can keep working without losing control.
The result may be a clearer account structure, better protected mailboxes, a cleaned-up form, documented backups, a simpler data flow, updated privacy text, a list of processors, reduced data collection, improved website settings, or a better understanding of what still needs attention.
The common thread is control. People and organisations should know where their business and customer data is, why it is there, who can access it, how it is protected and how it can be maintained responsibly over time.