Controls for GDPR, CCPA and KVKK
Set consent, PII and regional deployment controls against the obligations your programme already works to.
For legal teams
Consent state travels with the event, PII rules run before export, and the deployment region is yours to choose.
Consent state and event fields
Receive the event with the choices made at collection.
PII and regional policy rules
Mask, hash, redact or block the fields you name.
Configured data recipients
Send only the fields permitted for each destination.
Collection, policy, and delivery rules sit in one event path, so legal teams can see what happens before data leaves.
Set consent, PII and regional deployment controls against the obligations your programme already works to.
The consent state collected at the source decides what the pipeline does next, before anything is processed or exported.
Mask, hash or redact named fields before events reach downstream platforms.
Run in an EU region or inside your own environment where policy requires it. Destination settings are reviewed separately.
Trust Center policies and certificate scope, for security and vendor review.
Tie a consent choice to what the pipeline actually did.
Document which fields reach which destination.
Pick a deployment model that fits regional policy.
Hardal uses encrypted transport and managed access controls. Its security programme includes ISO 27001, ISO 27701, and ISO 9001:2015 certifications. Check the Trust Center for scope and certificate details.
Send your consent, PII and residency requirements. We will walk the configuration point by point.