CHAPTER ONE
A book of clients and a folder of spreadsheets
Veld's starting point was a practising DPO in the medical-advisory sector, doing the job
the way most people doing this work still do it: a tracker per client, a folder of
half-current templates, and the part of it that lived in memory rather than in any system.
None of that fails loudly. It fails on the Tuesday a request lands while you are on site
with someone else, and the calendar-month deadline is worked out wrong by two days. It fails
when a register that was accurate in March is quietly wrong by September. It fails when a
client asks what you have actually done for them this quarter and the honest answer —
a great deal, constantly — has no evidence behind it.
The tooling that existed came in two shapes. Enterprise privacy platforms, priced and
scoped for a corporate programme with a budget holder, that assume one organisation and one
set of records. And generic case management, which knows nothing about Article 12(3), the
three-month extension, or the seventy-two hours that start when you become aware and not
when you finish investigating.
Nothing was built for the shape of the job: one practitioner, many controllers, every
statutory clock running at once.
CHAPTER TWO
The first decision: don't hold the data
The obvious way to build Veld was the normal way — accounts, a database, client records on
our servers. We got some way down that road before the objection became impossible to ignore.
A DPO evaluating that product has to do a supplier assessment on us. A contract under
Article 28. A transfer question. A due-diligence conversation with every client about a new
processor holding their subject access files. We would be asking practitioners to take on
exactly the work we claim to remove, in order to buy a tool that removes it.
So the rule became: never hold a key that opens anyone's records. The workspace is sealed
on your own machine with a key derived from your password, and that key never leaves it. On
the free version nothing is transmitted at all — no account, no server-side copy, nothing for
us to hand over if anyone ever asked.
What that means in a supplier assessment. On the on-device version we are not a
processor of your clients' personal data, because we receive none of it. The question that
usually takes three weeks and a legal review takes one sentence.
Practitioners then asked for the obvious thing — the same workspace on the laptop and the
office machine — and we had to decide whether the rule survived contact with it. It did, but
not for free. Syncing means we hold your encrypted workspace, which makes us a processor with
an Article 28 contract like anyone else. What it does not mean is that we can read it: the
key stays derived on your device and is never transmitted, so a total breach of our
infrastructure yields ciphertext and nothing else.
We are not going to pretend any of this is free of cost. Lose your password, your recovery
key and every passkey, and the records are gone — nobody can recover them, including us. That
is the price of the guarantee rather than a gap in it, and we would rather hand you a real
trade-off than a comfortable story.
CHAPTER THREE
The second decision: nothing is generated
Every compliance tool being built right now writes your response letter for you. Veld does
not, and this is the part we argue about most.
A refusal to disclose is a professional decision. It has to be defensible eighteen months
later, to a client, an auditor, or the ICO, by the person who made it. "The system drafted it"
is not a defence, and a paragraph that sounds authoritative while citing a provision that does
not apply is worse than a blank page — because the blank page gets checked.
So the response pack composer inverts it. You make the decisions — which systems were
searched, what the outcome is, which exemptions you are relying on — and the prose, the
citations and the structure follow from those decisions. Every sentence is a fixed template
selected by a recorded choice, which means you can point at the choice that produced each
paragraph. Where a ground is relied on, the provision is quoted in full: Article 15(4) and
Schedule 2 Part 3 paragraph 16, not "an exemption applies".
The same rule governs everything that carries professional weight. The statutory clocks are
calendar arithmetic. The compliance health score is inspectable weighted arithmetic over record
state — you can recompute it by hand and defend it line by line. Where we do use pattern
matching, in the on-device scan that flags candidate personal data in a disclosure bundle, it
runs in your browser, it is presented as a reviewer's assistant, and a clean scan is labelled
as nothing matched these rules — never as there is nothing here.
The line we hold: software tracks, calculates, cites and reminds. A practitioner
decides. Anything that blurs that boundary makes your work harder to defend, not easier
to do.
CHAPTER FOUR
Where it stands today
Veld runs a practice end to end: clients, subject requests with the calendar-month clock,
breaches on the seventy-two-hour Article 33 clock, the Article 30 register, DPIAs, a recurring
compliance calendar, an evidence log, and document generation in PDF, Word and Excel.
Above the registers sits the part that makes it a practice rather than a filing cabinet:
a workspace for each client instead of nine lists filtered nine ways, a health figure that
will show you every number behind it, client reports and evidence packs ready to send,
guided onboarding, the annual review, an inbox of what you are waiting on and for how long,
and the figures that say how the book is actually running — deadlines met, deadlines
missed, how often each client is reviewed.
It opens empty on purpose. No sample clients to unpick, no demo data to mistake for your
own — and the portal coaches you the first time you open each tool, so an empty workspace is
not the same as an unhelpful one.
It runs two ways, and the free way is not a trial of the paid one. Every register is free
on a single device, uncapped, where nothing is transmitted and there is no account at all.
What you pay for is the practice layer above the registers, and a workspace that lives
somewhere other than one laptop. An existing on-device workspace can be moved onto an
account without retyping anything, and the copy already on your machine is left exactly
where it is.
The client portal — where a client answers the request themselves instead of it sitting
in your sent items — is the next substantial piece, and it is marked coming rather
than shipped because only half of it exists. The half that decides what a client would be
allowed to see is built, and you can read the exact object they would receive before anyone
receives it. Nothing is published anywhere, there is no link to hand out, and the rest is a
decision about becoming a two-way service rather than an afternoon's work. We would rather
be short a feature than accurate only in the marketing.
CHAPTER FIVE
Why "Veld"
A veld is open grassland — cleared ground, with no fence yet drawn on it. That was
deliberate. Every enterprise privacy platform on the market when this one was being built
assumed the fence already existed: one organisation, one budget holder, one set of records.
A sole practitioner responsible for forty controllers does not fit inside that fence, and we
did not want a name that implied one either.
The full stop after the name is not decoration. It sits in the same place on every page,
because the sentence it closes is meant to stay short: a practice tool, not a platform with
another feature to pitch you next quarter.