Compliance & recordsv4.1.0

Privara

GDPR and CCPA / CPRA data requests, each on its own deadline, with every system checked and recorded.

For teams that answer data subject requests. Often replaces Termly, Enzuzo or Osano.

Single license $79 · Extended license $179 · paid once, yours for good

Try the live demoNo sign-up. The demo resets itself, so click anything.

What it does

A deadline on every request

The dashboard flags overdue and due-soon requests, with Article 12(3) deadline maths, month-end clamping included.

A checklist for every request

Load your list of systems onto a request. Each gets an owner and a done mark with who, when and a note.

California requests too

Each request runs on its own clock: GDPR's one month or the CCPA / CPRA's 45 days, extendable once.

Reply from your templates

Write to the requester from a template with the reference, name and deadline filled in. What you sent stays in the timeline.

Identity checks you can show

Record each check beyond the email link, with who and when. Set a minimum before any request is answered.

Public submission form

A public form that confirms the requester controls the email address they gave.

In your requesters' languages

The form, status page and verification email in English, German, French, Spanish, Italian, Dutch and Polish.

On your own website

Put the request form on your privacy page with one snippet. Only the sites you list can show it.

Correspondence on the record

The identity document, the reply letter and the export you sent, filed on the request. Only a signed-in controller can open them.

A response record

One page per request: answered on time or late, and every system checked, with who and when.

Owners chased for you

Switched on in Settings, each owner of an open system gets one email a day. References and deadlines only.

Six request types

Access, deletion, rectification, portability, objection and restriction of processing, each shown throughout.

Also: an audit trail on every change, CSV and JSON export, reusable templates and an installable phone app.

Is it right for you?

What Privara deliberately doesn’t do.

  • No automated data-discovery across systems — it tracks requests, it does not scan your databases for personal data
  • Not a full GRC suite: no policies, DPIAs, breach management, or staff training records
  • Not built for multi-tenant SaaS platforms needing isolated per-customer workspaces
  • Using Privara doesn't itself make you GDPR-compliant — legal sufficiency of your responses is your responsibility

What renting costs instead

TermlyStarter $10 per website/month billed annually, $14 billed monthly; Pro+ $15 annually, $20 monthly; Free $0; Agency custom. Pro+ bulk calculator (annual): $12.00 per license at 2, $10.50 at 5, $9.00 at 10. A live promo ('Extra 20% OFF using code FALL2026') sat over the prices

6 months of Termly costs what Privara costs once.

Read Sep 26, 2026 · source
Enzuzo$9 / month (Starter, monthly billing; $7/month billed annually; includes 10 DSARs/month). Growth $29/$22, Pro $79/$59, plus a free tier

9 months of Enzuzo costs what Privara costs once.

Read Sep 3, 2026 · source

The full comparison: every rival, what each does better, and who should stay with them →

Replacing one of these? Termly alternative · Enzuzo alternative · Osano alternative

Release history

Own It 4.1Client installations and your other toolsOct 4, 2026

For Privara, 4.1 makes two changes that every app gets. What’s new in 4.1 →

Own It 4.0It updates and backs itself upSep 29, 2026

For Privara, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and… What’s new in 4.0 →

Own It 3.3Replies from your templatesSep 27, 2026

Privara 3.3 turns your response templates into replies: write to the requester from one, with the reference, name, request type and deadline filled in, send it through… What’s new in 3.3 →

Own It 3.2Every system, every clockSep 26, 2026

The 3.2 wave gave Privara a checklist of the systems to search, correct or erase on each request, with an owner and a done mark per system, and California's CCPA /…

Own It 3.1It writes to the people you serveAug 20, 2026

The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar…

Own It 3.0Works for your AI, not just for youAug 9, 2026

An AI assistant can read the register, log a request that arrived by post and move requests through the workflow over MCP — writing through the same transition…

Own It 2.0API, 2FA, backups, dark modeAug 6, 2026

Privara 2.0 adds the 2.0 owner layer.

What’s in the zip

The tree as the zip ships it — the working leftovers the packager deletes are not listed

  • .htaccess
  • API.md
  • Dockerfile
  • QUICKSTART.txt
  • assets/
  • bin/
  • config.sample.php
  • controllers/
  • deploy/
  • index.php
  • install/
  • lang/
  • manifest.json
  • offline.html
  • router.php
  • src/
  • sw.js
  • tests/
  • views/
src/Dsar.php: a real module, the first 24 of 307 lines

Chosen as the largest module in src/ that is not one of the shared cores — this product's own logic, not a file every product carries.

<?php
/**
 * Dsar.php — THE core: GDPR DSAR lifecycle management (fully covered by tests/run.php, offline).
 *
 * 1. DEADLINE MATH (GDPR Art 12(3)), counted per Reg. (EEC, Euratom) No 1182/71 — the EU's
 *    own period-counting rules, which the EDPB's guidance follows:
 *      - Art. 3(1): the day of receipt does NOT count; the period starts the following day.
 *      - Art. 3(2)(c): a month-period ends on the same-numbered day of the last month, clamped
 *        to month-end when that day does not exist (Jan 31 + 1 month = Feb 28/29).
 *      - Art. 3(4): if the last day is a Saturday, Sunday or public holiday, the period runs to
 *        the end of the next working day.
 *    Extension to 3 calendar months is available for complex requests.
 *    (counting from the received date without Art. 3(1)/3(4) marked requests overdue up to
 *    3 days EARLY — conservative, but wrong in the register a controller shows a regulator.)
 *
 * 2. DERIVED STATUS. The stored status is one of: new / verifying / in_progress / completed /
 *    refused. deriveStatus() maps these to a display status by injecting 'overdue' when the
 *    effective deadline is past and the request is not closed.
 *    Precedence: refused -> completed -> overdue -> in_progress -> verifying -> new
 *
 * 3. REFERENCE CODES. Public ref: 8 chars from no-lookalike alphabet (no 0/O/1/I).
 *    Verify token: 32 random hex bytes (unguessable).
 *
 * 4. EXPORT. CSV/JSON of the request register.

Runs on: 2-minute web installer, plain PHP 8.1+ with MySQL or SQLite (WAL mode), no Composer or build step — Dockerfile included. Tested on PHP 8.3. Or run it in Docker: the Dockerfile is in the zip.

Technical owners can install it with one line and their license key: curl -fsSL https://ownware.io/install.sh | sh -s -- privara <your license key>

Nothing is obfuscated or encoded; what you read is what runs. Manual · API · the test run

Which license do I need?

It comes down to how many installations you need. Running your own business on one site is the Single license. A second domain of your own, or sites you build or run for other people, is the Extended license.

Single license$79
One (1) domain or subdomain · One business, running it on one site.
  • Install it on one domain or subdomain you own or operate
  • Change the source however you like for that installation
  • Run your own business on it commercially, client work included
  • Re-download the current build any time from your buyer portal
  • A second site, or an installation you hand to a client as theirs, needs the Extended license
  • No reselling, redistributing or sublicensing the source
  • Not for offering it to other people as a hosted service
Buy the Single license, $79
Extended license$179
Unlimited sites you own or operate, plus up to 10 client installations (white-label included) · Agencies, and anyone running it on more than one site.
  • Everything the Single license grants
  • Install it on as many domains as you own or operate — no cap on the number
  • Up to ten client installations, one per client project, handed over or hosted for each client; for more, buy another Extended license
  • White-label: remove or replace the product name and logo in the screens of client installations
  • Still no reselling or redistributing the source itself
  • Running it as a multi-tenant service others sign up for needs a SaaS agreement
Buy the Extended license, $179

Every download carries the full terms as LICENSE.txt. The complete wording is on the terms page.

After you buy

Updates

The app’s Updates page installs a new release with your license key, with the release’s signature checked and a backup taken first. Your download link always serves the current build. Download again any time from your order page or the buyer portal; there is no renewal fee.

Help

Email support for installation and for defects in the code as delivered: a person reads and answers every message. It does not cover custom development or server administration. What support covers

If it isn’t right

Refunds are handled by Lemon Squeezy as merchant of record, case by case. EU consumers keep the statutory 14-day right until delivery starts. Refund terms

If we disappear

It keeps running: your server, the full PHP source, no license check that can fail. If no stable release is published for 365 days, the domain limit lifts; after three such years your copy becomes MIT-licensed. The terms have the exact wording: continuity.

Questions

Does this make me GDPR-compliant?
No — it helps you meet the deadline and maintain an auditable record of every request; whether your responses are legally sufficient is your responsibility and depends on your jurisdiction and the specifics of each request.
Does it actually send emails?
Yes. Once you enter your SMTP server in Settings, every email goes through it: the requester's verification link, staff notifications and, if you switch it on, the daily deadline digest. Without SMTP, only the verification link is attempted, through the server's own mail(), and a send that fails is recorded on the request.
What request types are supported?
Six: access, deletion, rectification, portability, objection and restriction of processing (Article 18).
What if the developer disappears?
It's a self-contained PHP script you own and run — no SaaS dependency, no license server, no phoning home.
Will it run on my shared host?
Yes — plain PHP 8.1+ with MySQL or SQLite; no Composer and no Node. The deadline digest goes out with the first dashboard visit of the day, so no cron job is needed; one is optional, for scheduled backups and for a digest on days nobody signs in. If your host offers PHP 8.1 or later with MySQL or SQLite, it can run Privara.
Can I attach files to a request?
Yes — correspondence and evidence attach to the request record (checked by content, not filename, and served only to signed-in staff), so the deadline, the log and the paperwork live in one place. What it deliberately does not do is crawl your other systems: data discovery stays yours.
Is Privara a subscription?
You buy it once and own that copy. There is no subscription, no per-user fee and nothing that renews — the license tier decides how many sites you may run it on, not how many people use it. A request portal is infrastructure; it should not stop working because an invoice lapsed.
What exactly do I get for the money?
The download is the complete PHP source with the database schema. Read it, change it, keep it. If we vanished tomorrow the copy on your server keeps working, because nothing in it phones home to us. For a portal that handles subject requests, being able to read what it stores before you trust it is the point.
Can I get the request records out?
Yes, as CSV or JSON, with the dates each request was received and answered.
Does it decide whether a request is valid?
No. It tracks each request against the one-month period and shows where every one stands. Whether a request is in scope, and what must be disclosed, is a decision it records rather than makes.
Some tools have a free plan. Why pay for Privara?
Free plans count requests. Privara keeps the record: the clock, every step in the timeline, and which systems were checked by whom, on your own server, for a one-time price.
Better together
Compliance Suite: Privara, Confida, Complia, Packora and Cyresora
Five registers that record GDPR requests, whistleblowing reports, NIS2 and CRA reporting deadlines, complaints and packaging data, on your own server.
5 tools for$299
$435 separatelySave $136

Covered in these guides

Also covered in: From spreadsheet to system: when a business tool pays for itself.

More about Privara

A self-hosted register for GDPR and CCPA / CPRA data requests, each tracked against its own deadline.

The problem it solves

DSARs arrive by email and the clock starts immediately, but most organizations have nothing tracking them — no deadline dashboard, no audit trail, just a shared inbox. Enterprise GRC platforms cover far more than DSAR tracking and are usually priced by quote; Privara is for a team that just needs to log requests and see, at a glance, how many days each one has left in the one-month period.

  • Requests tracked in an inbox with no deadline visibility
  • No audit trail of who did what and when
  • Enterprise GRC suites priced and scoped for far more than DSAR tracking

Every feature

  • Correspondence attachments per request. The identity document, the reply letter, the export you sent — filed on the request record itself, byte-sniffed on upload and served only through a signed-in controller. The paper trail lives where the deadline does.
  • Deadline tracking against Article 12(3). The dashboard flags overdue and due-soon requests, with deadline math that follows Article 12(3) as the product implements it, month-end clamping included.
  • Public submission form. A public form that confirms the requester controls the email address they gave. Any further identity checks are yours to run and record.
  • Append-only audit log. Every status change, internal note and extension grant is timestamped in the request's history.
  • Six request types. Captures access, deletion, rectification, portability, objection and restriction-of-processing requests, shown throughout the admin interface.
  • Reusable response templates. Save canned acknowledgment, completion, and refusal text for reuse across requests.
  • CSV/JSON export. Export request data for reporting or record-keeping.
  • Installable mobile app (PWA). Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is not stored offline on the device; what you see is read live.
  • A checklist for every request. Keep a list of the systems that hold personal data (CRM, mailing tool, accounts, backups) and load it onto a request in one click. Each system gets an owner and a done mark with who, when and a note, so your register shows which systems were searched, corrected or erased, and by whom. Privara records the work; it never connects to those systems.
  • California requests too. Each request runs on its own clock: GDPR's one month or the CCPA / CPRA's 45 days, extendable once. Your form can ask which law applies.
  • Identity checks you can show. Record each check beyond the email link, with who and when, and set a minimum before any request is answered.
  • In your requesters' languages. The form, status page and verification email in English, German, French, Spanish, Italian, Dutch and Polish.
  • On your own website. Put the request form on your privacy page with one snippet; only the sites you list can show it.
  • Reply from your templates. Write to the requester from one of your templates, with the reference, name, request type and deadline already filled in. Send it through your own mail server; the message you sent stays in the request's timeline.
  • Updates from inside the app. The Updates page installs a new release with your license key: Ownware's signature is checked, a backup is taken first, and the app puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. It never checks by itself.
  • Backups by themselves. Automatic backups, an optional copy to S3-compatible storage you own, and a weekly check that the latest backup reads back. The Health page names anything that needs attention.
  • Own It 4.0.1 — fixes and an up-to-date manual. For Privara, 4.0.1 fixes an installer and its invite page that had lost their styling, a rollback that a page opened during an update could stop and a command-line update that ended in an error after putting the previous version back. Its manual, FAQ and QUICKSTART now cover everything 4.0 added, including two Nginx rules that keep the data folder private. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
  • Own It 4.0.2 — the installer opens on every host. For Privara, 4.0.2 fixes a fresh install on an Apache host: the one-page setup at /install/ looped back to itself and never opened, and now it opens. Privara's Docker image also gives the web server the whole app folder, so a Docker install can finish and update itself. Your license covers it: press Check for updates on the Updates page, or download it from your order page.

Release notes in full

  • Own It 4.1: client installations and your other tools. For Privara, 4.1 makes two changes that every app gets. An Extended license bought from October 4, 2026 covers up to ten client installations, one per client project: hand each one over to the client or host it for them, with the client's logo and colors from the app's branding settings. The API reference now shows how to connect Privara to Zapier, Make or n8n, using its own webhooks and API key. Your license covers the update: press Check for updates on the Updates page, or download it from your order page.
  • Own It 4.0: it updates and backs itself up. For Privara, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. A new install can start with a sample business and remove it in one click; backups run by themselves, with an optional offsite copy and a weekly check that the latest one reads back; and the Health page says whether the install is looking after itself.
  • Own It 3.3: replies from your templates. Privara 3.3 turns your response templates into replies: write to the requester from one, with the reference, name, request type and deadline filled in, send it through your own mail server, and keep what you sent in the request's timeline. The template import's dry run now also shows a row with an unknown request type as skipped before you confirm.
  • Own It 3.2: every system, every clock. The 3.2 wave gave Privara a checklist of the systems to search, correct or erase on each request, with an owner and a done mark per system, and California's CCPA / CPRA clock beside GDPR's month. It also records the identity checks you made, puts the request form on your own website and in your requesters' languages, and prints a one-page response record that says whether a request was answered on time.
  • Own It 3.1: it writes to the people you serve. The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Each outbound feature ships switched off and runs on your own credentials; a failed send is recorded, and the action that triggered it stands. What this app gained is listed at the top of this section.
  • Own It 3.0: works for your AI, not just for you. An AI assistant can read the register, log a request that arrived by post and move requests through the workflow over MCP — writing through the same transition function the browser uses, so it cannot set a status the screen would refuse. Overdue is computed from the Article 12(3) deadline and cannot be set by anyone.
  • Own It 2.0: API, 2FA, backups, dark mode. Privara 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase.

Browse self-hosted: Compliance software · Software for builders & agencies · Accountancy & bookkeeping software · IT support & managed-service software

Privara$79 once
Demo Buy