FRIDGARD

Guide

GDPR-compliant custom software, done properly

What actually matters — beyond the word “GDPR-compliant” in the brochure.

The uncomfortable truth first: GDPR compliance is not a checkbox a piece of software ships with — responsible for the data is whoever processes it: you. Good software makes that responsibility bearable, bad software turns it into a permanent risk. This page shows how to tell the difference before you commission.

Aligned concrete thresholds one behind another with a bright passage at the end — a chain of checkpoints

What actually matters

Four things decide whether a custom application carries its data-protection duties — or leaves you chasing them.

Privacy by design

Data protection belongs in the design, not in the retrofit: collect only what the task needs, fix the purposes, default to the sparing setting. What is never stored never has to be secured, disclosed or erased.

Server location and third countries

It is not only about WHERE data sits, but who can access it. A server in Frankfurt helps little if its operator is subject to a third country's law. Location AND operator belong in the answer.

Data processing agreements

Whoever processes data on your behalf — host, operator, embedded services — needs a contract under Art. 28 GDPR. The list of sub-processors in it is the part you actually have to read.

Data-subject rights and erasure

Access, rectification and erasure must be FEASIBLE in the software. An application without a delete function turns Art. 17 into manual labour — for every single request, forever.

Four questions to ask every provider

Ask these before you commission — literally. The answers tell you whether data protection is built in or written on.

Where do operation and storage run?

Question 01 · Location

A solid answer names the country, the data centre and the operator — and who has administrative access. “In the cloud” is not an answer; it is the start of the next question.

Where does data flow during build and operation?

Question 02 · Third countries

AI services, analytics, fonts, embedded components: every silent inclusion is a transfer. Even loading fonts from a US provider has triggered waves of cease-and-desist letters — ask for the complete list.

How do I fulfil access and erasure requests?

Question 03 · Data-subject rights

Have them show you how an access request and an erasure actually run — as a function of the software, not as a promise in the brochure.

What happens in case of a breach?

Question 04 · Notification

A data breach must be reported to the supervisory authority within 72 hours. That presumes someone NOTICES it: logs, monitoring and a reachable person in charge belong in the answer.

GDPR is operations, not acceptance

Compliance is not a state you establish once — it is work that recurs every year. A quote that leaves it out has only postponed it.

State of the art

Art. 32 demands security in line with the state of the art — and that moves. Security updates and maintained dependencies are a data-protection duty, not a convenience.

Being able to prove it

Records of processing, technical and organisational measures, accountability: when it matters, what counts is not what was done but what can be demonstrated.

Every change inherits the duty

A new feature, a new service, a new form field — legally, every change is a new case. The review path has to be as routine as the change itself.

How FRIDGARD is built and operated

The platform is designed against exactly these questions: operation and hosting on our own hardware in Germany, AI from Europe — as of July 2026 the platform works exclusively with European AI, without transfers to third countries. Fonts and components of the built applications are self-hosted instead of loaded from US services, and the source code belongs to the customers.

FRIDGARD opens in waves. On the waitlist you hear first when your application is up — and you are welcome to put every question on this page to noalen itself.

Join the waitlist

Frequently asked questions on data protection

Is custom software automatically GDPR-compliant?

No. Responsible for the processing is whoever processes the data — not the developer and not the host. Custom software does have a structural advantage: it can be designed from the start so that the duties — data minimisation, access, erasure — are built in as functions rather than retrofitted as exceptions.

Why does a server location in Germany matter?

Within the EU, one data-protection law applies; a location in Germany simplifies supervision, contracts and the answer to your own customers' location question. Location alone is not enough, though: it also matters who operates the server and whose law that operator is subject to.

What is a data processing agreement and when do I need one?

A contract under Art. 28 GDPR, required as soon as someone processes personal data on your behalf — the host of your application as much as an embedded service. It governs instructions, security, sub-processors and what happens to the data when the contract ends.

May AI services process personal data?

Yes — under the same rules as any other processing: legal basis, a processing agreement, and for providers outside the EU additionally the rules for third-country transfers. What matters is where and by whom the AI computes. That is why FRIDGARD works with European AI (exclusively, as of July 2026).

Is a cookie banner enough?

No. A banner manages consent for one sub-area — it replaces neither the privacy policy nor processing agreements, erasure concepts or safe defaults. A site that needs no banner at all, because it runs without consent-requiring services, is usually the better sign.

Does this page replace legal advice?

No. It is orientation from the practice of building software — which questions to ask and how to recognise solid answers. For your specific case, your contracts and your sector, proper data-protection counsel remains the right path.

Your line of work in detail

What the duties mean in practice depends on your work. These pages go into detail — each with a live, usable example.

And the question that usually comes first: What does custom software cost? — the honest guide with the market's figures.

Five identical steel doors in a row in a concrete wall

The waitlist

FRIDGARD opens in waves.

Sign up — you will hear from us as soon as your wave is up.

Used for the invitation only; unsubscribe anytime — privacy.