Access and erasure requests,tracked to a deadline.
When someone asks what your AI tools hold about them, or asks you to delete it, OpenWatch opens a ticket with the right deadline, cites the records involved and keeps every step on file until it's closed.

The request is simple.Answering it isn't.
01
AI data is spread across tools
Prompts can sit in device transcripts, claude.ai chats and exports. Finding every one by hand takes days.
02
Vendor sessions can't be deleted
Anthropic's Compliance API session endpoints are read-only, so the answer has to record what exists and where.
03
The clock starts on arrival
Under GDPR, you generally have one month to respond. Requests that arrive by email are easy to lose.
What you get
A request becomes a ticket,and the ticket becomes the record.
Deadlines
Each request gets a type, an owner and a clock
Access and erasure requests open with a 30-day deadline and retention requests with 7. Status moves from new to resolved, with the handler's attestation recorded on close.
- Status: new, triaged, in progress, resolved or dismissed
- Requester, subject and handler on every ticket
- Hours spent and attestation recorded on close
Evidence
Citations that can't be rewritten
Tickets cite the exact messages, sessions and records involved. Citations and ticket events are append-only, so the history reads the same months later.
- Cite messages, sessions, database rows or log lines
- Append-only event log on every ticket
- Linked back to the sessions in the dashboard
Intake
File a request wherever it arrives
Your team can open a ticket from the dashboard's assistant, through the API or from Claude itself over MCP. Erasure requests ask for confirmation before they're filed.
- Assistant in the dashboard
- REST endpoint for your intake form
- Optional HelpScout sync that closes with the ticket
Everything an auditorwill ask to see.
Deadline clocks
30 days for access and erasure, 7 for retention, counted from the day it's filed.
Attestation
The handler's attestation is recorded when the ticket is resolved.
Append-only history
Ticket events and citations are added, never edited.
HelpScout sync
Optionally opens a HelpScout conversation and closes it with the ticket.
Handlers and requesters
Who asked, who it's about and who is handling it, on every ticket.
Carried out by Attri
In managed deployments, Attri's team performs the export or deletion.
From inbox to closed.
A request arrives
Someone on your team files it from the dashboard, your intake form or Claude.
OpenWatch opens the ticket
The deadline starts, a handler is assigned and the relevant records are cited.
Attri acts, you attest
Attri carries out the export or deletion. The handler records the attestation and resolves the ticket.
Ticket types and deadlines.
Privacy requests share the ticket system with anomaly findings, so one queue holds everything that needs a response.
| Type | Deadline | Used for |
|---|---|---|
| Access (DSAR) | 30 days | Someone asks what your AI tools hold about them |
| Erasure | 30 days | Someone asks for that data to be deleted |
| Retention | 7 days | Data kept past its retention period |
| Anomaly | 3 days | Cost spikes and unusual usage |
| Policy violation | 3 days | Prompts that likely breach your AI policy |
| Custom | 7 days | Anything else your team needs to track |
The 30-day deadlines follow GDPR Article 12(3). This page describes how OpenWatch tracks requests, not legal advice.
Questions about privacy requests
Does OpenWatch delete the data itself?
No. It tracks the request and the evidence. In an Attri deployment, Attri's managed-service team carries out the export or deletion, and the ticket records it.
Can data be deleted from Anthropic?
Anthropic's Compliance API session endpoints are read-only. OpenWatch records what exists and where, so your response can say so accurately.
Does it produce the response package for the requester?
Not yet. The ticket holds the citations and history; the export itself is prepared by Attri's team.
Is it in the open-source repo?
Not yet. Ticketing runs in Attri deployments.
Someone will ask what happened.Have the answer ready.
Run OpenWatch on sample data in minutes, or have Attri deploy it inside your cloud with live data from your organisation.