Business-Type Engine + GDPR Tech Demo

Leif

Map a business type. Get every process, system, data flow, and regulation it touches. Build compliance on top.

React / Vite / Tailwind Python FastAPI Gemini 2.5 Pro Playwright Supabase
01 The Product

GDPR compliance platform.

The GDPR platform is the first application built on the data layer. The audit comes pre-filled. The system already knows the tools, data, and regulations that apply to each company type. The user confirms, corrects, and fills in the gaps.

Leif landing page, Ditt favoritverktyg för GDPR with colorful compliance icons
02 Onboarding

We look up your company. You just confirm.

Enter an org number. Leif pulls the rest from Bolagsverket: company name, registered address, employee count. A three-step wizard pre-fills every field. Review, confirm, move on.

Example: Scandinavian Sportsmen AB (556273-8954). 5 employees. Klostergatan 5, Lund. Every field auto-filled.

Onboarding step 1 of 3 with pre-filled company fields for Scandinavian Sportsmen AB
03 Guided Questionnaire

AI-assisted compliance questions, not a blank form.

Questions are organized by department and topic. Each one presents visual answer cards. The website scan pre-fills suggestions. Here Leif detected Google Analytics, Google Tag Manager, and Visitor Analytics, and asks the user to confirm which tracking tools are in use.

A left sidebar shows progress through each audit section (Spårning & Samtycke, Marknadsföring & Kommunikation) at 75%. Below it, answers trigger concrete policy updates: Integritetspolicy entries, PUB-avtal requirements, Cookiepolicy changes.

Questionnaire showing tracking tool selection with Google Analytics, Meta-pixel, LinkedIn Insight Tag, and AI suggestions sidebar
04 Document Generation

Documents generated from actual answers.

Leif assembles compliance documents as the audit progresses. The Integritetspolicy shown here covers 12 data processing activities, from purchases to Stripe and Swish payments. Each activity includes its legal basis and retention period, pulled from the data layer and questionnaire answers.

Documents are presented one by one: Cookiepolicy, Integritetspolicy, and Personuppgiftsbiträdesavtal. A confirmation banner shows when generation is complete.

Integritetspolicy document 2 of 3 generated with 12 treatments and full rights sections
05 Document Review

Every section traced back to its source.

Each treatment section covers what data is collected, why, legal basis, retention period, and recipients. The sidebar shows where each came from: 10 from questionnaire answers, 2 auto-added from the website scan.

Color coding shows where each treatment came from: green for scan-detected services, blue for questionnaire answers, orange for auto-added items pending confirmation. Copy, email, or download as PDF from the toolbar.

Full Integritetspolicy document with treatment sections, legal basis, and color-coded source sidebar
06 Team Delegation

Assign questions to the people who know the answers.

Not every GDPR question falls on one person. The audit lead picks flagged questions, groups them by topic, and delegates via email. Recipients see only their questions, answer independently, and responses merge back into the main audit.

Selected questions show a "Markerad för delegering" badge. Add recipients at the bottom and hit Skicka. The colleague gets a focused view with no access to the full audit, just the questions they need to answer.

Delegation view with selected questions, email recipients, and send button