Records that hold up in an audit.
The record, versioned
Every processing activity with its legal basis under Art. 6, its purposes and the categories of data subjects and of data. Setting it active creates a new version; the history stays readable.
An assessment with a score and a gap report
A guided questionnaire under Art. 32 with weighted questions calculates the maturity level, updates the measures and delivers the gap report as a PDF.
Data breaches with the 72-hour deadline
A risk assessment in a four-by-four matrix, the notification deadline under Art. 33 as a running countdown, a status sequence from open to closed.
The whole dossier as a ZIP
The record, published policies, the gap report, signed DPAs and active training material – at the press of a button, as a package for an audit or the supervisory authority.
Data protection, demonstrably maintained.
The module is the filing cabinet for data protection in the company: it records which processing activities exist, which measures protect them, which agreements stand behind them and what happened in the event of a data breach. All of it per tenant, with versions that can be frozen.
The dashboard asks the uncomfortable questions straight away. Which processing activity has no measure? Which has no erasure rule? Which follow-up on a data processing agreement is overdue? One click on the tile leads into the matching area.
The record describes what actually happens in the house. That happens in the other modules, with customer administration and order processing in Orders & invoices, author contracts and royalty statements in Contracts & royalties, the newsletter mailing in Correspondence and the administration of suppliers and service providers in Incoming invoices. Every entry is created from an industry template or by hand, with a legal basis under Art. 6 and, in the case of legitimate interest, with a justification. Setting it active creates a new version each time.
The technical and organizational measures sit in the catalog, grouped by the types of control in Art. 32, each with a traffic light, the date of the last check and an interval from which the module works out the next due date itself. Anyone who does not want to piece the current state together starts the assessment: weighted questions, a score at the end, updated measures and the gap report as a PDF.
Data processing agreements go from draft through “final” to “signed”, with a follow-up date and a due marker. Data protection policies consist of free-text and live chapters. The live chapters draw their content from the record, the measures, data breaches, agreements, training and the erasure policy, and are fixed in place on publication. The consents themselves are created in the CRM and are only evaluated here.
An incident is recorded with its cause, the immediate measures and a risk assessment, and the countdown to the 72 hours runs visibly alongside. Training courses are built from modules with a knowledge test, and the risk register shows, against the criteria of Art. 35, whether a data protection impact assessment is needed. And the module draws one boundary itself: it documents, but it does not replace legal advice. The contract, training and policy texts supplied with it are drafts and have to be checked by a lawyer.
When AI comes into play.
The AI features of open.junixx do not hang on a hard-wired provider but on a slot. For data protection that makes the difference – and the choice is yours.
On your own premises: no additional recipient
Anyone who sets up a local model hands nothing to anyone for the AI. That removes the additional processor, the transfer to a third country under Art. 44 ff. GDPR and the weighing of interests that goes with it.
In the cloud: your contract, not our shared access
Anyone who chooses a cloud provider concludes the contract with them directly and stores their own key. open.junixx is not interposed, and there is no account through which the requests of every publishing house run.
Demonstrable, not asserted
Every AI request is in the log with its model, tokens, cost and duration, and every field written back with its old and its new value. For a record of processing activities that means the entries can be substantiated.
And with no AI at all
AI is an ingredient, not a prerequisite. With no provider set up, open.junixx carries on unchanged – anyone who wants to keep the subject out of the record can do so.
The module in the application.



Where action is neededKey figures on processing activities, documented measures, open data breaches, training due and risks – above them the warning box with the open points, at the top right the dossier export as a ZIP.
Every processing activity, every versionOn the left the record with status and version, on the right the processing activity itself: legal basis under Art. 6, purposes, categories of data subjects and of data – beneath them the version history.
Measures and their maturityThe catalog by type of control with a traffic light and a status per measure, beside it the history of the assessments with date, status, score and the gap report to download.
See open.junixx at work. We show you on screen how the software fits your publishing workflows – with no obligation, and with time for your questions.
Book a demoImport and export through the API.
The filing cabinet is deliberately built to face inward: every record is created in the house. Facing outward it is about data subject rights, notification to the supervisory authority and keeping the service provider lists up to date.
Import – from external services
Data flowing into the module from outside:
- Lists of processors and sub-processors from cloud services → the DPA register and its annexes stay up to date
- A reference number and confirmation from the supervisory authority → proof right at the incident
- Signed contracts from the e-signature service → the status “signed” with no detour
- Attendance and completion records from a training platform → the training status per person
Export – to external services
Data the module passes outward:
- Incident data under Art. 33 to the supervisory authority's notification portal
- The record, measures and agreements to the external data protection officer or the law firm
- A machine-readable data export for an access request under Art. 15 and 20
- Records and evidence for auditors and certification bodies
Today every record is created in the module itself: the record of processing activities as PDF and CSV, the TOM catalog, the gap report, agreements and policies as PDF – and the complete GDPR dossier as a ZIP with a manifest. Connections to notification portals, e-signature services and training platforms can be added through the central API.
More on the interfaces
Detailed overview from the interface analysis: sources for import and possible targets for export.
Import – from external services
| Source (external) | What is imported | Use in the module |
|---|---|---|
| Processors and cloud services | A list of (sub-)processors, DPA metadata | Keep the DPA register and its annexes up to date automatically |
| Supervisory authority | Reference number, confirmation of the notification | Proof at the incident |
| E-signature service | Signed contracts (returned) | DPA status “signed” |
| Training platform (LMS) | Attendance and completion records | The training status per member of staff |
Export – to external services
| Purpose / trigger | External service (examples) | What is exported | Format / standard |
|---|---|---|---|
| Data breach notification | The supervisory authorities' notification portals | Incident data under Art. 33: categories, data subjects, measures | Authority portal, form |
| Have the compliance dossier checked externally | External data protection officer, law firm | The record, measures and agreements as a bundle | PDF, ZIP |
| Data subject access | An access request from a data subject | A machine-readable data export under Art. 20 | PDF, JSON, CSV |
| Evidence and audit | Auditors, certification bodies | Records and evidence | PDF, CSV |
Every feature of the GDPR module.
You will find the complete list in our brochure
What you see above is an excerpt. Every feature of this module – and of all the others – is collected in the open.junixx brochure. We will gladly send it to you, in print or as a PDF. And if you would rather watch than read: we are happy to show you open.junixx live on screen.
Get the brochureMandatory for every publisher.
Authors, subscribers, prospects, applicants, service providers – every house holds personal data. That is why this module is the only one that matters equally to every type of publisher.
Connected to the publishing ecosystem
- VLB
- IDNV
- doctronic
- Amazon
- Bookwire
- Arvato / VVA
- Brocom
- Prolit
- Zeitfracht
- Magento
- WordPress /
WooCommerce - Shopify
- Shopware
- Wirth & Horn
- Diamant
- DATEV
- BMD
- Abacus
- DHL
- DPD
Get to know open.junixx.
Arrange an appointment with no obligation. We will show you how the data protection documentation fits into your publishing routine.







