Available with an Attri deployment

Access and erasure requests,tracked to a deadline.

When someone asks what your AI tools hold about them, or asks you to delete it, OpenWatch opens a ticket with the right deadline, cites the records involved and keeps every step on file until it's closed.

An OpenWatch erasure request, showing the 30-day deadline, cited sessions, messages and chats, hours logged and the ticket history

The request is simple.Answering it isn't.

  1. 01

    AI data is spread across tools

    Prompts can sit in device transcripts, claude.ai chats and exports. Finding every one by hand takes days.

  2. 02

    Vendor sessions can't be deleted

    Anthropic's Compliance API session endpoints are read-only, so the answer has to record what exists and where.

  3. 03

    The clock starts on arrival

    Under GDPR, you generally have one month to respond. Requests that arrive by email are easy to lose.

What you get

A request becomes a ticket,and the ticket becomes the record.

Deadlines

Each request gets a type, an owner and a clock

Access and erasure requests open with a 30-day deadline and retention requests with 7. Status moves from new to resolved, with the handler's attestation recorded on close.

  • Status: new, triaged, in progress, resolved or dismissed
  • Requester, subject and handler on every ticket
  • Hours spent and attestation recorded on close

Evidence

Citations that can't be rewritten

Tickets cite the exact messages, sessions and records involved. Citations and ticket events are append-only, so the history reads the same months later.

  • Cite messages, sessions, database rows or log lines
  • Append-only event log on every ticket
  • Linked back to the sessions in the dashboard

Intake

File a request wherever it arrives

Your team can open a ticket from the dashboard's assistant, through the API or from Claude itself over MCP. Erasure requests ask for confirmation before they're filed.

  • Assistant in the dashboard
  • REST endpoint for your intake form
  • Optional HelpScout sync that closes with the ticket

Everything an auditorwill ask to see.

  • Deadline clocks

    30 days for access and erasure, 7 for retention, counted from the day it's filed.

  • Attestation

    The handler's attestation is recorded when the ticket is resolved.

  • Append-only history

    Ticket events and citations are added, never edited.

  • HelpScout sync

    Optionally opens a HelpScout conversation and closes it with the ticket.

  • Handlers and requesters

    Who asked, who it's about and who is handling it, on every ticket.

  • Carried out by Attri

    In managed deployments, Attri's team performs the export or deletion.

From inbox to closed.

  1. A request arrives

    Someone on your team files it from the dashboard, your intake form or Claude.

  2. OpenWatch opens the ticket

    The deadline starts, a handler is assigned and the relevant records are cited.

  3. Attri acts, you attest

    Attri carries out the export or deletion. The handler records the attestation and resolves the ticket.

Ticket types and deadlines.

Privacy requests share the ticket system with anomaly findings, so one queue holds everything that needs a response.

TypeDeadlineUsed for
Access (DSAR)30 daysSomeone asks what your AI tools hold about them
Erasure30 daysSomeone asks for that data to be deleted
Retention7 daysData kept past its retention period
Anomaly3 daysCost spikes and unusual usage
Policy violation3 daysPrompts that likely breach your AI policy
Custom7 daysAnything else your team needs to track

The 30-day deadlines follow GDPR Article 12(3). This page describes how OpenWatch tracks requests, not legal advice.

Questions about privacy requests

Does OpenWatch delete the data itself?

No. It tracks the request and the evidence. In an Attri deployment, Attri's managed-service team carries out the export or deletion, and the ticket records it.

Can data be deleted from Anthropic?

Anthropic's Compliance API session endpoints are read-only. OpenWatch records what exists and where, so your response can say so accurately.

Does it produce the response package for the requester?

Not yet. The ticket holds the citations and history; the export itself is prepared by Attri's team.

Is it in the open-source repo?

Not yet. Ticketing runs in Attri deployments.

Someone will ask what happened.Have the answer ready.

Run OpenWatch on sample data in minutes, or have Attri deploy it inside your cloud with live data from your organisation.