Privara
GDPR and CCPA / CPRA data requests, each on its own deadline, with every system checked and recorded.
For teams that answer data subject requests. Often replaces Termly, Enzuzo or Osano.
Single license $79 · Extended license $179 · paid once, yours for good
What it does
The dashboard flags overdue and due-soon requests, with Article 12(3) deadline maths, month-end clamping included.
Load your list of systems onto a request. Each gets an owner and a done mark with who, when and a note.
Each request runs on its own clock: GDPR's one month or the CCPA / CPRA's 45 days, extendable once.
Write to the requester from a template with the reference, name and deadline filled in. What you sent stays in the timeline.
Record each check beyond the email link, with who and when. Set a minimum before any request is answered.
A public form that confirms the requester controls the email address they gave.
The form, status page and verification email in English, German, French, Spanish, Italian, Dutch and Polish.
Put the request form on your privacy page with one snippet. Only the sites you list can show it.
The identity document, the reply letter and the export you sent, filed on the request. Only a signed-in controller can open them.
One page per request: answered on time or late, and every system checked, with who and when.
Switched on in Settings, each owner of an open system gets one email a day. References and deadlines only.
Access, deletion, rectification, portability, objection and restriction of processing, each shown throughout.
Also: an audit trail on every change, CSV and JSON export, reusable templates and an installable phone app.
What Privara deliberately doesn’t do.
- No automated data-discovery across systems — it tracks requests, it does not scan your databases for personal data
- Not a full GRC suite: no policies, DPIAs, breach management, or staff training records
- Not built for multi-tenant SaaS platforms needing isolated per-customer workspaces
- Using Privara doesn't itself make you GDPR-compliant — legal sufficiency of your responses is your responsibility
What renting costs instead
6 months of Termly costs what Privara costs once.
Read Sep 26, 2026 · source9 months of Enzuzo costs what Privara costs once.
Read Sep 3, 2026 · sourceThe full comparison: every rival, what each does better, and who should stay with them →
Replacing one of these? Termly alternative · Enzuzo alternative · Osano alternative
Release history
For Privara, 4.1 makes two changes that every app gets. What’s new in 4.1 →
For Privara, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and… What’s new in 4.0 →
Privara 3.3 turns your response templates into replies: write to the requester from one, with the reference, name, request type and deadline filled in, send it through… What’s new in 3.3 →
The 3.2 wave gave Privara a checklist of the systems to search, correct or erase on each request, with an owner and a done mark per system, and California's CCPA /…
The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar…
An AI assistant can read the register, log a request that arrived by post and move requests through the workflow over MCP — writing through the same transition…
Privara 2.0 adds the 2.0 owner layer.
What’s in the zip
The tree as the zip ships it — the working leftovers the packager deletes are not listed
- .htaccess
- API.md
- Dockerfile
- QUICKSTART.txt
- assets/
- bin/
- config.sample.php
- controllers/
- deploy/
- index.php
- install/
- lang/
- manifest.json
- offline.html
- router.php
- src/
- sw.js
- tests/
- views/
src/Dsar.php: a real module, the first 24 of 307 lines
Chosen as the largest module in src/ that is not one of the shared cores — this product's own logic, not a file every product carries.
<?php /** * Dsar.php — THE core: GDPR DSAR lifecycle management (fully covered by tests/run.php, offline). * * 1. DEADLINE MATH (GDPR Art 12(3)), counted per Reg. (EEC, Euratom) No 1182/71 — the EU's * own period-counting rules, which the EDPB's guidance follows: * - Art. 3(1): the day of receipt does NOT count; the period starts the following day. * - Art. 3(2)(c): a month-period ends on the same-numbered day of the last month, clamped * to month-end when that day does not exist (Jan 31 + 1 month = Feb 28/29). * - Art. 3(4): if the last day is a Saturday, Sunday or public holiday, the period runs to * the end of the next working day. * Extension to 3 calendar months is available for complex requests. * (counting from the received date without Art. 3(1)/3(4) marked requests overdue up to * 3 days EARLY — conservative, but wrong in the register a controller shows a regulator.) * * 2. DERIVED STATUS. The stored status is one of: new / verifying / in_progress / completed / * refused. deriveStatus() maps these to a display status by injecting 'overdue' when the * effective deadline is past and the request is not closed. * Precedence: refused -> completed -> overdue -> in_progress -> verifying -> new * * 3. REFERENCE CODES. Public ref: 8 chars from no-lookalike alphabet (no 0/O/1/I). * Verify token: 32 random hex bytes (unguessable). * * 4. EXPORT. CSV/JSON of the request register.
Runs on: 2-minute web installer, plain PHP 8.1+ with MySQL or SQLite (WAL mode), no Composer or build step — Dockerfile included. Tested on PHP 8.3. Or run it in Docker: the Dockerfile is in the zip.
Technical owners can install it with one line and their license key: curl -fsSL https://ownware.io/install.sh | sh -s -- privara <your license key>
Nothing is obfuscated or encoded; what you read is what runs. Manual · API · the test run
Which license do I need?
It comes down to how many installations you need. Running your own business on one site is the Single license. A second domain of your own, or sites you build or run for other people, is the Extended license.
- Install it on one domain or subdomain you own or operate
- Change the source however you like for that installation
- Run your own business on it commercially, client work included
- Re-download the current build any time from your buyer portal
- A second site, or an installation you hand to a client as theirs, needs the Extended license
- No reselling, redistributing or sublicensing the source
- Not for offering it to other people as a hosted service
- Everything the Single license grants
- Install it on as many domains as you own or operate — no cap on the number
- Up to ten client installations, one per client project, handed over or hosted for each client; for more, buy another Extended license
- White-label: remove or replace the product name and logo in the screens of client installations
- Still no reselling or redistributing the source itself
- Running it as a multi-tenant service others sign up for needs a SaaS agreement
Every download carries the full terms as LICENSE.txt. The complete wording is on the terms page.
After you buy
The app’s Updates page installs a new release with your license key, with the release’s signature checked and a backup taken first. Your download link always serves the current build. Download again any time from your order page or the buyer portal; there is no renewal fee.
Email support for installation and for defects in the code as delivered: a person reads and answers every message. It does not cover custom development or server administration. What support covers
Refunds are handled by Lemon Squeezy as merchant of record, case by case. EU consumers keep the statutory 14-day right until delivery starts. Refund terms
It keeps running: your server, the full PHP source, no license check that can fail. If no stable release is published for 365 days, the domain limit lifts; after three such years your copy becomes MIT-licensed. The terms have the exact wording: continuity.
Questions
Does this make me GDPR-compliant?
Does it actually send emails?
What request types are supported?
What if the developer disappears?
Will it run on my shared host?
Can I attach files to a request?
Is Privara a subscription?
What exactly do I get for the money?
Can I get the request records out?
Does it decide whether a request is valid?
Some tools have a free plan. Why pay for Privara?
Covered in these guides
- What's new in Own It 3.3
- The Compliance Suite: five registers, and a clock in four of them
- What's new in Own It 3.1
- A Self-Hosted DSAR Portal — Handling GDPR Requests on Your Own Server
- EU Data Residency for Business Software — The Buyer's Guide
- Compliance Software Cannot Make You Compliant — And Buying It Once Raises a Question Worth Asking
Also covered in: From spreadsheet to system: when a business tool pays for itself.
More about Privara
A self-hosted register for GDPR and CCPA / CPRA data requests, each tracked against its own deadline.
The problem it solves
DSARs arrive by email and the clock starts immediately, but most organizations have nothing tracking them — no deadline dashboard, no audit trail, just a shared inbox. Enterprise GRC platforms cover far more than DSAR tracking and are usually priced by quote; Privara is for a team that just needs to log requests and see, at a glance, how many days each one has left in the one-month period.
- Requests tracked in an inbox with no deadline visibility
- No audit trail of who did what and when
- Enterprise GRC suites priced and scoped for far more than DSAR tracking
Every feature
- Correspondence attachments per request. The identity document, the reply letter, the export you sent — filed on the request record itself, byte-sniffed on upload and served only through a signed-in controller. The paper trail lives where the deadline does.
- Deadline tracking against Article 12(3). The dashboard flags overdue and due-soon requests, with deadline math that follows Article 12(3) as the product implements it, month-end clamping included.
- Public submission form. A public form that confirms the requester controls the email address they gave. Any further identity checks are yours to run and record.
- Append-only audit log. Every status change, internal note and extension grant is timestamped in the request's history.
- Six request types. Captures access, deletion, rectification, portability, objection and restriction-of-processing requests, shown throughout the admin interface.
- Reusable response templates. Save canned acknowledgment, completion, and refusal text for reuse across requests.
- CSV/JSON export. Export request data for reporting or record-keeping.
- Installable mobile app (PWA). Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is not stored offline on the device; what you see is read live.
- A checklist for every request. Keep a list of the systems that hold personal data (CRM, mailing tool, accounts, backups) and load it onto a request in one click. Each system gets an owner and a done mark with who, when and a note, so your register shows which systems were searched, corrected or erased, and by whom. Privara records the work; it never connects to those systems.
- California requests too. Each request runs on its own clock: GDPR's one month or the CCPA / CPRA's 45 days, extendable once. Your form can ask which law applies.
- Identity checks you can show. Record each check beyond the email link, with who and when, and set a minimum before any request is answered.
- In your requesters' languages. The form, status page and verification email in English, German, French, Spanish, Italian, Dutch and Polish.
- On your own website. Put the request form on your privacy page with one snippet; only the sites you list can show it.
- Reply from your templates. Write to the requester from one of your templates, with the reference, name, request type and deadline already filled in. Send it through your own mail server; the message you sent stays in the request's timeline.
- Updates from inside the app. The Updates page installs a new release with your license key: Ownware's signature is checked, a backup is taken first, and the app puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. It never checks by itself.
- Backups by themselves. Automatic backups, an optional copy to S3-compatible storage you own, and a weekly check that the latest backup reads back. The Health page names anything that needs attention.
- Own It 4.0.1 — fixes and an up-to-date manual. For Privara, 4.0.1 fixes an installer and its invite page that had lost their styling, a rollback that a page opened during an update could stop and a command-line update that ended in an error after putting the previous version back. Its manual, FAQ and QUICKSTART now cover everything 4.0 added, including two Nginx rules that keep the data folder private. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
- Own It 4.0.2 — the installer opens on every host. For Privara, 4.0.2 fixes a fresh install on an Apache host: the one-page setup at /install/ looped back to itself and never opened, and now it opens. Privara's Docker image also gives the web server the whole app folder, so a Docker install can finish and update itself. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
Release notes in full
- Own It 4.1: client installations and your other tools. For Privara, 4.1 makes two changes that every app gets. An Extended license bought from October 4, 2026 covers up to ten client installations, one per client project: hand each one over to the client or host it for them, with the client's logo and colors from the app's branding settings. The API reference now shows how to connect Privara to Zapier, Make or n8n, using its own webhooks and API key. Your license covers the update: press Check for updates on the Updates page, or download it from your order page.
- Own It 4.0: it updates and backs itself up. For Privara, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. A new install can start with a sample business and remove it in one click; backups run by themselves, with an optional offsite copy and a weekly check that the latest one reads back; and the Health page says whether the install is looking after itself.
- Own It 3.3: replies from your templates. Privara 3.3 turns your response templates into replies: write to the requester from one, with the reference, name, request type and deadline filled in, send it through your own mail server, and keep what you sent in the request's timeline. The template import's dry run now also shows a row with an unknown request type as skipped before you confirm.
- Own It 3.2: every system, every clock. The 3.2 wave gave Privara a checklist of the systems to search, correct or erase on each request, with an owner and a done mark per system, and California's CCPA / CPRA clock beside GDPR's month. It also records the identity checks you made, puts the request form on your own website and in your requesters' languages, and prints a one-page response record that says whether a request was answered on time.
- Own It 3.1: it writes to the people you serve. The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Each outbound feature ships switched off and runs on your own credentials; a failed send is recorded, and the action that triggered it stands. What this app gained is listed at the top of this section.
- Own It 3.0: works for your AI, not just for you. An AI assistant can read the register, log a request that arrived by post and move requests through the workflow over MCP — writing through the same transition function the browser uses, so it cannot set a status the screen would refuse. Overdue is computed from the Article 12(3) deadline and cannot be set by anyone.
- Own It 2.0: API, 2FA, backups, dark mode. Privara 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase.
Browse self-hosted: Compliance software · Software for builders & agencies · Accountancy & bookkeeping software · IT support & managed-service software