Javascript is required
logo-dastralogo-dastra

A modular offer, simple and constraint-free

STARTER

Starter

199 €

/ month

Start your GDPR compliance project with peace of mind

ENTERPRISE

Entreprise

Custom price

An advanced privacy center for all your organisation

All features from Pro, plus

Can't find what you're looking for?

publicServicePlan plan icon

Public sector, SMBs, non-profit

Public sector, SMBs with fewer than 50 employees, non-profit associations, students

Contact us
externalDPOPlan plan icon

External DPO

External DPO, consulting firms, resellers and partners

Contact us
customPlan plan icon

Customizable

Select the features that interest you

Contact us

Starter

Try for free

Pro

Ask for a demo

Entreprise

Contact us
General

Number of legal entities

505050

Number of users

150150150

Dashboard

Organisational chart (multi-entity)

Multi-client/workspace management

Design customisation

Customisable expert watch

Integrated information resources

Advanced classification (tags)

Log history and notification center

Integrated discussions

Advanced filters and search engine

Import and export of data

Batch edit

Customisation of workflow steps

Restrict access to workflow steps

Automated workflows

1 /workspace25 / workspace100 /workspace

Custom fields

1 /workspace25 / workspace100 /workspace
Record of data processing activities (ROPA)

Consolidated record of data processing activities, both controller and processor

Creation and editing of processing records

Processing models

Generation of processing from assets (software, database...)

IA generated data processing activities

Guided tutorials, filling assistance and intelligent suggestions

Collaborative updating of personal data processing

Progress and quality indicators

Automated data processing sensitivity indicator

Processing freshness

Workflow for validation of processings

Processing sharing links

Processing relationships

Export of the record (article 30 format, complete)

Generation of information notices from processings

Automated collection of data processing by e-mail

World map of non-EU transfers

Data mapping

Asset repository and models

Stakeholder repository and models

Repository & dataset library (including customised retention periods)

Data glossary

Repository & library of security measures

Repository & data subject library

Duplication detection and merge tool

Create asset from AI

Automatic generation of Data Processing Agreement (DPA)

Sync your register with your repositories

Inter-object relationships

Visual representation of your data mapping

Project management

Creating and editing tasks and subtasks

Visualisation of tasks in Kanban mode

Project management and iterations

Statistics and monitoring indicators

Privacy by design/default

AIPD and questionnaires

Questionnaires template library

Privacy Impact Assessment (DPIA)

Creation of audit questionnaires

Advanced customisation of audit questionnaires

Planning an audit and invitation manager

Bulk import of respondents

Validation of audit campaigns

Access to Privacy Hub

Customize logo in external audits

Managing data subject requests

Creating and editing requests to data subject requests

No-code integration of collection forms

Automated collection of data subject requests from emails

Library of response templates

Pre-checking the identity of the applicant

Identification and processing of the data sets concerned by the requests

Secure instant messaging platform with the applicant

Customisation and translation of notification emails

Data breaches

Creation and editing of data breaches

Risk analysis during a security incident

Notifications to supervisory authorities

Communication to the data subjects

Contracts management

Contracts record

Secure document storage, filing and versioning

Signature management

Sharing links with operational staff

Liaison with repository stakeholders and assets

Automated fields and workflows

Managing risks

Risk edition & risk types

Repository of dreaded events

Threats repository

Control points repository

Event log

Customisation of risk scales

Risk assessment

Integrated risk models

Risk summary and statistics

Privacy and security

Customisation of roles and permissions

Team management

Secure hosting (encryption in transport and at rest)

Security logs (connections, role changes)

Custom SMTP

Email domain filtering

IP Filtering

Multi-factor authentication

SSO (Saml2, OpenID)

OptionalOptional

SCIM

Automatic signout in case of inactivity

Sandbox area (1 dedicated workspace)

Customisation of log retention periods

Customisation of the password renewal

File integration (FTPS, AWS S3, Azure Blob Storage)

Automations and integrations

Automated e-mail collection

Open & documented API (REST)

Webhooks

Calendar synchronization

Zapier integratrions

Google drive integration

OneDrive integration

Support and services

9 languages

Telephone support or instant chat 5/7

Integrated ticketing tool

Online help center

Training Webinars

User community (forum)

SLA 99.9%

Optional

Integration of your existing records

OptionalOptionalOptional

Onboarding program and support

OptionalOptionalOptional

What are the prohibitions of the general data protection regulation?

The GDPR prohibits the collection and use of data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, as well as the processing of genetic data, biometric data allowing for the unique identification of a person, health information, or data related to an individual's sexual life or sexual orientation.

However, there are exceptions to this prohibition, including:

  • If the data subject has given explicit consent, which must be free, specific, informed, and preferably in writing.
  • If the information has been manifestly made public by the data subject.
  • If this data is necessary for the protection of human life.
  • If its use is justified by a public interest and authorized by the CNIL.
  • If it concerns members or affiliates of an association or political, religious, philosophical, or trade union organization.

What are the main obligations of the GDPR?

  • Inform the data subjects clearly and accessibly about the use of their data (purpose, retention period, rights, etc.).
  • Justify a legal basis for each processing (consent, contract, legitimate interest, etc.).
  • Respect the rights of data subjects (access, rectification, erasure, objection, etc.).
  • Ensure the security of personal data: appropriate technical and organizational measures must be implemented to protect data against risks of loss, unauthorized access, or disclosure.
  • Document all processing activities in a record, especially starting from 250 employees or in the case of sensitive or non-occasional processing.
  • Notify data breaches to the CNIL (or other competent authority) within 72 hours, and sometimes, to the affected data subjects.
  • Frame relationships with subcontractors through formalized contracts, to ensure their compliance with GDPR requirements and clarify each party's responsibilities.

What are the 3 principles of the GDPR?

The three main principles of the general data protection regulation are:

  1. Transparency, fairness, and legality: Personal data must be collected and processed in a transparent, lawful, and fair manner. This involves informing the data subjects about how their data will be used and ensuring that they provide informed consent.
  2. Data minimization: Only the data necessary for the specific purpose should be collected. This principle encourages companies to limit the amount of personal data they process, thereby reducing risks to individuals' privacy.
  3. Security and confidentiality: Personal data must be protected against unauthorized access, processing, or disclosure. Companies must implement technical and organizational measures to ensure the security of the personal data they process.

In which Dastra subscription plan can I benefit from the Cookie consent module?

The consent management platform is marketed as a dedicated module. Depending on the number of visitors to your website, the subscription fee will vary. See our pricing page or contact us for more information.

Is a cookie banner mandatory?

A cookie banner is essential as soon as you store or access information on a user's device, regardless of the technology used. As soon as non-essential trackers are used — such as those for targeted advertising, audience measurement with identifiable data, or personalization — you must inform the user and obtain their prior consent.

What are the 3 types of cookies?

Cookies can be classified into several categories:

  1. strictly necessary cookies
  2. performance cookies
  3. functionality cookies

What is the ePrivacy Directive?

The ePrivacy Directive 2002/58/EC, amended in 2009, often referred to as the "Privacy and Electronic Communications Directive", is an initiative of the European Commission aimed at ensuring the confidentiality of communications and protecting users against certain intrusive practices in the digital realm. It is transposed differently in each Member State (in France, through the Data Protection Act, particularly regarding cookies and direct marketing).

In which Dastra subscription plan can I benefit from the AI Act?

The AI Act is marketed in a dedicated or complementary module of the Privacy offerings. Depending on the number of employees in your company, the subscription amount will vary. Please consult our pricing page or contact us to learn more.

What are the forms of risks?

The approach to AI systems is based on a risk assessment. The regulatory framework defines four categories of risk for artificial intelligence systems (AIS), with varying levels of regulation depending on the different levels of the pyramid.

  • Unacceptable risks
  • High risks
  • Limited/Moderate risks
  • Minimal or no risks

What is the purpose of the AI Act?

The AI Act aims to create a harmonized legal framework in the EU to ensure that artificial intelligence systems are safe, transparent, ethical, and respect fundamental rights. More specifically, it has the following objectives:

  • Protect citizens against the use of AI deemed dangerous or intrusive (e.g., mass surveillance, behavioral manipulation)
  • Regulate high-risk systems with strict obligations for transparency, human oversight, data quality, and documentation
  • Promote trustworthy innovation by providing a clear framework for AI developers and companies
  • Enhance public and professional user trust in AI

What is the EU regulation on AI?

The AI Act, or Regulation on Artificial Intelligence, is a regulation developed to regulate and encourage the development as well as the marketing of artificial intelligence systems within the European Union. Proposed by the European Commission in April 2021, the AI Act came into effect on July 12, 2024, after three years of negotiations.

How do I cancel my subscription?

In order to cancel your subscription, please contact us adding any information that can help us identify your subscription (company name, etc).

How quickly can the work environment be deployed?

The Dastra work environment is deployed immediately after the creation of the entity.

I work in a large company, is DASTRA adapted to our size?

Yes, we offer subscriptions dedicated to large structures (large and medium-sized companies) composed of several legal entities.

Dastra is particularly well suited for corporate groups, either centralized with a single location for entity management and shared repositories, or decentralized.

Please contact us if you would like to know more information on how Dastra can help your specific organization.

How long does my trial offer last?

The trial offer is for a period of one (1) month. After that, you can contact us directly to extend it if you need it.

Can I host the files in my own environment?

Yes!

With DASTRA, you can connect yourself your own data hosting solution to host the documents stored in the application. This includes all documents stored in the document management system and documents stored in the rights management system.

You have control over the security of this hosting. The files remain under your control.

Today, we can connect Amazon S3 and Azure Blob Storage. Other services can be developed on demand, please contact us if you have a question regarding this topic.

Does Dastra comply with the government's General Accessibility Guidelines for French administrations (RGAA)?

Yes, in part !

We have completed a compliance audit of the General Accessibility Guidelines for the Administration (RGAA).

Our cookie choice management widget is fully compliant with the RGAA.

We have made the necessary changes to the source code to comply with accessibility standards.

Thus, the use of the widget and its appropriate configuration will maintain compliance with the standard for the site that hosts the widget.

More information about this standard: https://www.numerique.gouv.fr/publications/rgaa-accessibilite/

What happens when my subscription expires?

When your subscription expires and without renewing your contract, you will no longer be able to access or modify the information contained in your space. The information is deleted within a reasonable time (maximum 2 months).

Is the data secure with Dastra?

We apply strict security measures to our environment, both at the application and development levels.

We maintain a technical watch and have our solution regularly audited in order to provide the maximum guarantees on the security of the data you entrust to us.

You can find out more on our page dedicated to security.

What features are included in the trial offer?

You have access to all of Dastra's features in the trial package, except for audit and data processing activities exports.

If you want to have a view of the exports, contact us !

Subscribe to our newsletter

We'll send you occasional emails to keep you informed about our latest news and updates to our solution

* You can unsubscribe at any time using the link provided in each newsletter.