About Veld

Built from inside the work.

Veld exists because its founder needed it and could not buy it. What follows is the honest version: the problem, the two decisions that shaped the product, and the things we have deliberately refused to build.

It started as one practice's problem, not a product idea.

Veld was not commissioned, funded or road-mapped. It grew out of a single data-protection practice that needed a tool no vendor was selling, and built the tool instead of waiting for one to exist.

That is still the test every feature has to pass: not would this look good in a demo, but would this have survived a Tuesday when a request landed while you were on site with someone else.

The long version

Five chapters

The problem, the two decisions that shaped the product, where it stands, and the name.

  1. A book of clients and a folder of spreadsheetsOne practitioner, many controllers, every statutory clock running at once
  2. The first decision: don’t hold the dataNever hold a key that opens anyone’s records
  3. The second decision: nothing is generatedYou make the decisions; the prose, the citations and the structure follow from them
  4. Where it stands todayWhat runs now, what opens empty, and what is still marked soon
  5. Why “Veld”Open grassland — cleared ground, with no fence yet drawn on it
CHAPTER ONE

A book of clients and a folder of spreadsheets

Veld's starting point was a practising DPO in the medical-advisory sector, doing the job the way most people doing this work still do it: a tracker per client, a folder of half-current templates, and the part of it that lived in memory rather than in any system.

None of that fails loudly. It fails on the Tuesday a request lands while you are on site with someone else, and the calendar-month deadline is worked out wrong by two days. It fails when a register that was accurate in March is quietly wrong by September. It fails when a client asks what you have actually done for them this quarter and the honest answer — a great deal, constantly — has no evidence behind it.

The tooling that existed came in two shapes. Enterprise privacy platforms, priced and scoped for a corporate programme with a budget holder, that assume one organisation and one set of records. And generic case management, which knows nothing about Article 12(3), the three-month extension, or the seventy-two hours that start when you become aware and not when you finish investigating.

Nothing was built for the shape of the job: one practitioner, many controllers, every statutory clock running at once.

CHAPTER TWO

The first decision: don't hold the data

The obvious way to build Veld was the normal way — accounts, a database, client records on our servers. We got some way down that road before the objection became impossible to ignore.

A DPO evaluating that product has to do a supplier assessment on us. A contract under Article 28. A transfer question. A due-diligence conversation with every client about a new processor holding their subject access files. We would be asking practitioners to take on exactly the work we claim to remove, in order to buy a tool that removes it.

So the rule became: never hold a key that opens anyone's records. The workspace is sealed on your own machine with a key derived from your password, and that key never leaves it. On the free version nothing is transmitted at all — no account, no server-side copy, nothing for us to hand over if anyone ever asked.

What that means in a supplier assessment. On the on-device version we are not a processor of your clients' personal data, because we receive none of it. The question that usually takes three weeks and a legal review takes one sentence.

Practitioners then asked for the obvious thing — the same workspace on the laptop and the office machine — and we had to decide whether the rule survived contact with it. It did, but not for free. Syncing means we hold your encrypted workspace, which makes us a processor with an Article 28 contract like anyone else. What it does not mean is that we can read it: the key stays derived on your device and is never transmitted, so a total breach of our infrastructure yields ciphertext and nothing else.

We are not going to pretend any of this is free of cost. Lose your password, your recovery key and every passkey, and the records are gone — nobody can recover them, including us. That is the price of the guarantee rather than a gap in it, and we would rather hand you a real trade-off than a comfortable story.

CHAPTER THREE

The second decision: nothing is generated

Every compliance tool being built right now writes your response letter for you. Veld does not, and this is the part we argue about most.

A refusal to disclose is a professional decision. It has to be defensible eighteen months later, to a client, an auditor, or the ICO, by the person who made it. "The system drafted it" is not a defence, and a paragraph that sounds authoritative while citing a provision that does not apply is worse than a blank page — because the blank page gets checked.

So the response pack composer inverts it. You make the decisions — which systems were searched, what the outcome is, which exemptions you are relying on — and the prose, the citations and the structure follow from those decisions. Every sentence is a fixed template selected by a recorded choice, which means you can point at the choice that produced each paragraph. Where a ground is relied on, the provision is quoted in full: Article 15(4) and Schedule 2 Part 3 paragraph 16, not "an exemption applies".

The same rule governs everything that carries professional weight. The statutory clocks are calendar arithmetic. The compliance health score is inspectable weighted arithmetic over record state — you can recompute it by hand and defend it line by line. Where we do use pattern matching, in the on-device scan that flags candidate personal data in a disclosure bundle, it runs in your browser, it is presented as a reviewer's assistant, and a clean scan is labelled as nothing matched these rules — never as there is nothing here.

The line we hold: software tracks, calculates, cites and reminds. A practitioner decides. Anything that blurs that boundary makes your work harder to defend, not easier to do.
CHAPTER FOUR

Where it stands today

Veld runs a practice end to end: clients, subject requests with the calendar-month clock, breaches on the seventy-two-hour Article 33 clock, the Article 30 register, DPIAs, a recurring compliance calendar, an evidence log, and document generation in PDF, Word and Excel.

Above the registers sits the part that makes it a practice rather than a filing cabinet: a workspace for each client instead of nine lists filtered nine ways, a health figure that will show you every number behind it, client reports and evidence packs ready to send, guided onboarding, the annual review, an inbox of what you are waiting on and for how long, and the figures that say how the book is actually running — deadlines met, deadlines missed, how often each client is reviewed.

It opens empty on purpose. No sample clients to unpick, no demo data to mistake for your own — and the portal coaches you the first time you open each tool, so an empty workspace is not the same as an unhelpful one.

It runs two ways, and the free way is not a trial of the paid one. Every register is free on a single device, uncapped, where nothing is transmitted and there is no account at all. What you pay for is the practice layer above the registers, and a workspace that lives somewhere other than one laptop. An existing on-device workspace can be moved onto an account without retyping anything, and the copy already on your machine is left exactly where it is.

The client portal — where a client answers the request themselves instead of it sitting in your sent items — is the next substantial piece, and it is marked coming rather than shipped because only half of it exists. The half that decides what a client would be allowed to see is built, and you can read the exact object they would receive before anyone receives it. Nothing is published anywhere, there is no link to hand out, and the rest is a decision about becoming a two-way service rather than an afternoon's work. We would rather be short a feature than accurate only in the marketing.

CHAPTER FIVE

Why "Veld"

A veld is open grassland — cleared ground, with no fence yet drawn on it. That was deliberate. Every enterprise privacy platform on the market when this one was being built assumed the fence already existed: one organisation, one budget holder, one set of records. A sole practitioner responsible for forty controllers does not fit inside that fence, and we did not want a name that implied one either.

The full stop after the name is not decoration. It sits in the same place on every page, because the sentence it closes is meant to stay short: a practice tool, not a platform with another feature to pitch you next quarter.

How we think

Four things we believe

These are not values on a wall. Each one has cost us a feature.

Judgement stays human

Software should track, calculate, cite and remind. Deciding whether an exemption applies is your job — Veld is built to protect that division of labour, even where it would demo better not to.

Records are a by-product

If keeping the register is a separate task, it won't get done. Good tooling makes the audit trail fall out of the work itself, which is why the evidence log fills as you go rather than at the end.

Your data is yours

A compliance platform that locks your records in would be a contradiction. Everything exports in open formats, on every plan, and the workspace was never ours to keep.

Say the hard part out loud

There is no password reset. The scan is not exhaustive. A feature that isn't finished is labelled unfinished. Practitioners are paid to spot the gap between a claim and reality — we would rather not be the claim.

How it stays honest

Built inside the work, checked from outside it

Veld isn't governed by a product committee. It answers to the practice that started it, and to a network that keeps testing whether it still holds up.

Built on a live caseload

Every deadline rule, template and register field exists because a real matter needed it first — not because a roadmap called for it.

Pressure-tested by specialists

A standing network of practising DPOs, information-governance leads and privacy lawyers checks the deadline logic, exemption wording and statutory citations before any of it ships.

Run as a practice, not scaled as a platform

That is the only reason the first two rules survive contact with a growth target. Veld stays small enough that no decision here is made by someone who has never done the job.

Talk to a practitioner

Questions about whether Veld fits your practice? You’ll get an answer from someone who does the work — not a sales team.