A setup that passes on nothing nobody agreed to
We deliver the technical side: local fonts, scripts only after consent, named processors. The legal review stays with your solicitor.
Privacy on websites rarely fails on intent and almost always on convenience. A typeface from someone else's CDN, an embedded video, an analytics script that loads before anyone clicks the consent button: three lines of code nobody deliberately ordered, handing your visitors' IP addresses to a third party before anyone was asked.
We deliver the technical implementation, not the legal assessment. Fonts sit locally, scripts start only after consent, and every embedded service appears on a list with its name and purpose. Whether your privacy notice is complete and correct for your business is for a solicitor to judge. That is not caution, it is a question of who is qualified.
Who this suits
A fit if
- You want a site that contacts nobody before consent is given
- You need a dependable list of which service sees which data
- You want your legal adviser reviewing facts rather than guessing
Not a fit if
- You expect legal advice or a guarantee against warning letters from us
- You want us to write the privacy notice itself
- You insist on tracking that runs before consent
What is included
- Fonts served locally, no call to a Google CDN
- A consent banner that makes declining as easy as accepting and loads scripts only afterwards
- Forms with encrypted transmission that collect only what you genuinely need
- A list of every embedded service and processor, as a basis for your record of processing activities
How we work
- 01
We look at who gets contacted
We open your site with the network log running and note every request that leaves before consent is given. On websites that have grown over years, that list is reliably longer than anyone expected.
- 02
Clean up rather than paper over
Whatever can be served locally, we serve locally. Whatever needs consent loads only after it. For anything with no leaner alternative, you make a deliberate decision instead of inheriting one unnoticed.
- 03
Handover to your legal adviser
You get the full breakdown: which service, which purpose, which data, which recipient. From that your solicitor writes the privacy notice instead of guessing at a template.
What it costs
Included in the website subscription
The GDPR-compliant setup is part of the website subscription at 349 euros net per month on a twelve-month term, then 49 euros net per month for hosting and technical maintenance. We do not sell it separately, because a website that hands over data before consent is simply not finished. Legal advice, review of your texts and the drafting of the privacy notice are not included and belong with a solicitor.
Common questions
Further reading
- A GDPR Check for Your Website: The Gaps That Are Almost Always ThereFonts from someone else's server, maps without consent, analytics before agreement: the typical gaps on SME websites, as a list you can actually check.Read the article
- GDPR in Email Marketing: What Is Actually RequiredDouble opt-in, the documentation duty, mandatory disclosures and the narrow existing-customer exception under German law - orientation, not legal advice.Read the article
- Trust Elements 2026: Which Signals Still Build ConfidenceWhy generic seals and SSL badges are now noise, which trust signals still demonstrably work, and why fewer of them, done properly, carry more weight.Read the article
- robots.txt in 2026: Why Blanket Blocking or Allowing Is Both WrongWhich AI crawlers exist, what robots.txt actually controls, and why neither blocking every bot nor allowing every bot is a considered decision.Read the article
- HTTPS Is Not Enough: HSTS, Certificate Transparency and HTTP/3Why HTTPS alone does not protect against downgrade attacks, why HSTS preload is practically irreversible, and what HTTP/3 actually delivers.Read the article
Let us talk about GDPR and privacy
A conversation where we listen first and then say honestly whether and how we can help.