Skip to content

Bulk DSAR redactionFrankfurt, EUSheet 00 of 08

Keep the subject.
Redact redacted, everyone else

Nothing underneath.

An access request over a few hundred documents should not cost you a week. Declare who the request is about, drop in the files, and Veil redacts third-party personal data across all of them at once. What it cannot attribute to the subject, it redacts anyway and raises for you, so nothing is disclosed on a guess. It never edits your originals. It generates new documents with nothing underneath.

  • Residency

    Your case data never leaves the EU

  • Originals

    Originals are never modified

  • Verification

    Every document independently checked before release

  • Commercials

    Published pricing, no annual contract

01 / The exhibitTwo renders of one file · Sheet 01 of 08 · Updated 22 Sep 2026

Two files. One of them still contains the names.

Scroll to run the redaction pass. On the left, the file you hold, with rectangles drawn over the names. On the right, the document Veil generates from what it decided to release.

The file you hold, in placeLeaks
From Person 04a covered name To the data subject Following our conversation I have logged the outcome. The panel was Person 02a covered name and myself. Payroll have your reference on file as 000000-00000a covered name, which I have asked them to confirm. I copied Person 07a covered name so the handover is on record. Reply to lm@example.coma covered name.

Five rectangles. Five names, still in the file, underneath them.

What Veil releases, born redactedBy construction
From redacted, third party a To the data subject Following our conversation I have logged the outcome. The panel was redacted, third party b and myself. Payroll have your reference on file as redacted, national id, which I have asked them to confirm. I copied redacted, third party c, unknown so the handover is on record. Reply to redacted, email, third party.

A new document, generated from the decision. The subject stays. Everyone else became a label.

Redaction pass5 of 5 entities applied
02 / Nothing underneathText layer extraction · Sheet 02 of 08 · Updated 22 Sep 2026

Veil never edits your document. There is nothing underneath.

Drawing a black box over a name hides it from a reader. It does not remove it from the file. The text stays under the rectangle, a PDF keeps its earlier versions, a Word file keeps its tracked changes, a spreadsheet keeps its hidden columns, and an email carries a second copy of itself that your tool never showed you. These are not bugs. They are how the formats are specified to work.

A rectangle is a drawing. Ask the file what it says.

Against the in-place redaction
$ pdftotext redacted-in-place.pdf -

[ press extract ]

The file has five black rectangles drawn
over five names. Nothing has been removed
from the content stream.
Against the Veil render
$ pdftotext generated-by-veil.pdf -

[ press extract ]

A new document, generated from what Veil
decided to release. The redacted names were
never written into it.

GDPR Article 15(3) entitles the requester to a copy of their personal data, not to the original artifact. Supervisory authority guidance accepts extracts.

Eight places a covered name survives

  1. 01
    Text under the box
  2. 02
    Incremental update history
  3. 03
    Document metadata
  4. 04
    Embedded objects
  5. 05
    Tracked changes and comments
  6. 06
    Hidden sheets and columns
  7. 07
    Hidden slides
  8. 08
    Alternative MIME parts

Read the eight ways in-place redaction leaks

Veil does not edit your file. It reads it, decides, and generates.
03 / How a case runsThree steps · Sheet 03 of 08 · Updated 22 Sep 2026

Built for the difficult part of an access request.

Most DSAR software manages the request: intake, identity checks, the deadline clock, who is doing what. Veil does none of that and does not ask you to stop using whatever already does it. It does the part that eats the week, the disclosure review, where the requester's information sits in the same paragraph as their colleagues', their customers' and a witness's.

Stays where it already is

  • Receiving the request and checking who is asking
  • The one month clock, and any extension you rely on
  • Assigning the work and chasing it
  • The letter that goes back with the bundle

Veil's part

  • Working out who each person in the case is, across every document at once rather than file by file
  • Redacting third-party personal data, and redacting rather than disclosing whatever it cannot attribute
  • Generating new documents instead of drawing over the ones you hold
  • The bundle, the manifest and the quality report you actually release

Work out the deadline on the Desk

How a case runs

Three steps. Then close your laptop.

The work runs on European infrastructure whether your tab is open or not. A three hundred document case finishes while you do something else.

  1. 01

    Declare the subject

    Tell Veil who the request is about: name, email, the identifiers you hold. Everything that belongs to that person is kept.

  2. 02

    Drop in the documents

    Email with attachments, PDF, Word, Excel, PowerPoint, text and ZIP archives, several hundred at a time. Attachments are unpacked and treated as documents of their own.

  3. 03

    Review, then release

    Can withhold

    Veil presents one row per person it found, twenty to sixty rows for a large case. You confirm the ones it was not certain about. Every document is independently checked, then you release a bundle with a manifest and a quality report for your case file.

Drops in as it arrives

  • EML
  • MSG
  • PDF, native text
  • PDF, scanned via OCR
  • DOCX
  • XLSX
  • PPTX
  • TXT
  • ZIP archives
  • Nested attachments
04 / QuestionsSix questions · Sheet 04 of 08 · Updated 22 Sep 2026

The things a privacy team asks first.

What exactly does Veil redact?

Personal data belonging to anyone other than the data subject. Names, contact details, national identifiers, bank details, dates of birth and the identifying context around them. The data subject's own personal data is kept rather than removed, because that is what the access request entitles them to, and that turns on two things you do: marking the subject on the case, and declaring their identifiers in the form the documents actually write them. Anything we are not sure about is redacted and flagged for you rather than disclosed, so an identifier you have not declared comes back removed rather than kept.

What happens when the system is unsure?

It redacts and raises a flag. Uncertainty always resolves toward redaction, never toward disclosure, and that is enforced in the system rather than left to the interface. Turning a flagged entity into the data subject requires either a match against the anchors you declared, or an explicit attestation that is written to the audit log. This is why the product publishes no accuracy percentage: the part a percentage would describe as missed is not disclosed, it is covered and queued for a person.

Does the original document get modified?

No. Originals are read only from the moment they are uploaded. Veil produces new files alongside them and never writes back.

Where is the data processed and stored?

Entirely in the European Union. Database and object storage in Frankfurt, processing workers in Frankfurt, web functions pinned to Frankfurt, and model inference at a European provider, with no case, document or account identifier accompanying the content.

Which file formats are supported?

EML and MSG email with recursive attachment extraction, native and scanned PDF, DOCX, XLSX, PPTX, TXT, and ZIP archives. Scanned pages go through OCR. Every attachment inside an email becomes its own document in the case, with its parent recorded.

How is this different from a DSAR workflow platform?

Most DSAR tools manage the request: intake, deadline clocks, task routing. Almost none of them redact the documents themselves. Veil does that part, and only that part: it redacts third-party personal data across several hundred documents at once, and what it cannot attribute to the data subject it redacts anyway and raises for you. It sits alongside whatever you already use to track the request.

05 / The registryA synthetic case · Sheet 05 of 08 · Updated 22 Sep 2026

One decision. Every document.

The reason a large request takes a week is not that the decisions are hard. It is that the same manager appears in forty seven places across twelve documents, and each one is a separate decision made late in the afternoon. Veil resolves every mention of a person, across every file in the case, into a single row. You decide once. It applies everywhere that person appears, including the documents you have not opened.

Entity registry5 rows · 303 mentions
2 awaiting a decision247 of 303 mentions resolved
  • 212 · 38
    Kept, data subjectdeclared on the case
  • 47 · 12
  • 9 · 4
  • 31 · 17
    Redacted everywherematched by rule
  • 4 · 3
    Redacted everywherematched by rule
Person 04, 47 mentions across 12 documentsRedacted by default, awaiting your decision
  • 001
    ·
  • 002
    ·
  • 003
    ·
  • 004
    ·
  • 005
    ·
  • 006
    ·
  • 007
    ·
  • 008
    ·
  • 009
    ·
  • 010
    ·
  • 011
    ·
  • 012
    ·

Spellings, initials, short forms and email addresses fold into the same person.

Confirming someone as the data subject keeps their data in place across the whole case. The same decision, in the other direction.

Every decision is recorded: what was decided, by whom, and when.

A synthetic case. The counts are the demo's, not a customer's.
06 / Fail closedZero unknowns disclosed · Sheet 06 of 08 · Updated 22 Sep 2026

When Veil is not sure, it redacts.

No system reads every document perfectly, and we will not ask you to take an accuracy figure on faith. What protects you is which way the system errs when it is uncertain. Veil errs in one direction only.

  1. 01

    Uncertainty redacts

    Anyone who cannot be attributed to the data subject is redacted, then raised for a person to decide. Nothing goes from unknown to disclosed without a named person confirming it, and the confirmation is written to the audit log.

  2. 02

    Identifiers are matched, not judged

    National identifiers, bank details, contact details and dates of birth are recognised by rule. Nothing the automation infers afterwards can take one back out of the redaction set.

  3. 03

    A separate check has the last word

    Every generated document is re-read by a component built and run separately from the one that redacted it. Anything it cannot clear is withheld and the case stops, loudly, until a person looks.

What Veil will not guess at

Purely indirect identification, the colleague who broke his leg skiing. Badly degraded scans and handwriting. Original page imagery such as signatures. All of it is redacted first and raised for you second. None of it reaches a bundle because nobody looked.

Zero
Unknowns disclosed

Anyone who cannot be attributed to the data subject is redacted first, then raised for a person to decide.

07 / Security postureFrankfurt, EU · Sheet 07 of 08 · Updated 22 Sep 2026

European by construction, not by preference.

The parts of this product that touch personal data were designed on the assumption that they will one day be audited.

  • Residency

    Every component that touches a document runs inside the European Union, pinned rather than defaulted.

  • Keys

    Each case is encrypted under its own key. Purging a case destroys the key, so what was encrypted under it is unreadable everywhere, including in backups. The rest of the case is deleted, and survives only in a backup until that backup expires.

  • Retention

    Cases purge on a schedule you set. Logs never contain personal data. Storage cannot be browsed.

  • Record

    Every decision, download authorisation and settings change is written to an audit record that cannot be edited.

08 / PricingPriced on pages redacted · Sheet 08 of 08 · Updated 22 Sep 2026

Priced on pages redacted. Nothing else.

No per-seat charge on a team that answers four requests a year, and no annual contract to sign before you can try it on a real case.

Every plan carries the full detection capability, independent verification on every document, and the bundle, manifest and quality report. There is no reduced tier.

  • Pay as you go

    EUR0.50per page, no monthly fee

    0.25 per page beyond 750 in one case, metered monthly

    Documents per case
    Up to 2,000
    Active cases
    2
    Retention window
    Up to 30 days
    Seats
    3
  • Business

    EUR1,800per month, 9,200 pages included

    0.16 per page beyond the included volume

    Documents per case
    Unlimited
    Active cases
    Unlimited
    Retention window
    Up to 90 days
    Seats
    Unlimited

Worked example

Every document counts as at least two pages, so a 200 document access request is 400 billable pages at least, and costs 200 on pay as you go. On Team the same case is inside the included volume. In our own testing, a 1,000 upload case of 1,432 documents completed in 68 minutes.

Most recent run

68 minutes. A 1,000 upload mixed format case of 1,432 documents, completed in our own testing.

Full pricing and limits

ReleaseManifest and quality report attached

Nothing
underneath.

Open a case, declare the subject, drop the documents in. Veil redacts, raises what it is not sure of, and shows you its working.

Reference

  • The Access Request Desk

    The practitioner's reference for data subject access requests: what the law says in each jurisdiction, how a request is run, and what a redaction actually removes.

  • Guides

    Long-form answers on redacting a data subject access request: what the law requires, whose data comes out and whose stays, and how to check what you release.

  • API documentation

    The Pritect Veil API: bearer authentication and scopes, the error shape, cursor pagination, idempotency, every endpoint with examples, five webhook events.