The register
Service, country, purposes served, data categories, agreement status and expiry, security review date, risk score.
- Expiring agreements flagged
- Appears in the data-flow map and access bundles
- Processor register report
Register each processor with its agreement and review status. Connect the ones that hold personal data and every withdrawal and erasure is delivered to them, with a log of what was sent and whether it was accepted.

Section 8(1) is clear: the Data Fiduciary is responsible for compliance even when a processor does the processing. A withdrawal that reaches you but not your email tool is a breach waiting to be noticed.
Most processor registers are spreadsheets. This one is wired to the systems it lists.
Service, country, purposes served, data categories, agreement status and expiry, security review date, risk score.
CRM, engagement, email marketing, WhatsApp, support desk, payments and advertising, plus a signed webhook for your own systems.
A transactional outbox queues each instruction; the sync log shows every attempt, response and retry.
Connector credentials are encrypted in the vault and write-only; saving tests the connection.
Every module writes to the same registers and the same hash-chained evidence, so nothing is re-keyed and nothing is lost between teams.
A withdrawal in the ledger becomes an instruction to the processors on that purpose.
See notice & consent →Erasure reaches a processor once every purpose it serves has expired.
See retention & erasure →A connected CRM is also a discovery source for the inventory.
See data discovery →On withdrawal it sets the processor's own opt-out or unsubscribe state for the person; on erasure it deletes or anonymises the contact where the processor's API allows, and sends a formal erasure request by email where it does not (payment processors, for example). We list what each one does during onboarding.
Use the signed webhook. Nyvika posts each withdrawal and erasure to your endpoint with an HMAC signature you verify, and retries until you acknowledge.
Against stand-ins that follow each vendor's published API, in our automated tests. Live-account verification is done during your onboarding with your own sandbox or trial accounts.
Still have a question? Write to us.
Bring API keys for your CRM and your engagement tool; a withdrawal will reach both before the demo ends.