Folelse
Full platform overview

Every tool your DPO actually needs

Folelse consolidates ROPA, DPIAs, SARs, breaches, DSPT Toolkit, supplier due diligence, and policy management into one audit-ready platform — built for NHS and UK organisations.

Core Compliance

Record of Processing Activities (ROPA)

Maintain a fully auditable ROPA in minutes. Map data flows, legal bases, and retention schedules across every system. Auto-generate ICO-ready reports in PDF or Excel.

  • Drag-and-drop data flow mapping
  • Legal basis library (Art. 6 & Art. 9)
  • Retention schedule engine with reminders
  • One-click ROPA export (PDF/XLSX)

Data Protection Impact Assessments (DPIAs)

Step-by-step DPIA wizard aligned to ICO guidance. Automated risk scoring and built-in approval workflows keep your team on track.

  • ICO-aligned necessity & proportionality tests
  • Automated risk heat-map scoring
  • DPO sign-off and version history
  • Integration with ROPA assets

Subject Access Requests (SARs)

Log, track, and respond to SARs with statutory deadlines, automated reminders, and a built-in response template library.

  • 30-day deadline countdown and alerts
  • Identity verification workflow
  • Redaction annotation tool
  • Audit trail for every action

Breach Management

Capture and categorise incidents with guided ICO 72-hour reporting. Evidence packs generated automatically.

  • Guided severity classification
  • 72-hour ICO notification workflow
  • Evidence pack auto-generation
  • Staff notification tracking
NHS & Healthcare

DSPT Toolkit Support

NHS Edition

Evidence-linked controls mapped directly to NHS Data Security & Protection Toolkit assertions. Never miss a submission deadline again.

  • All mandatory DSPT assertions pre-loaded
  • Evidence upload and linking per assertion
  • Progress dashboard with submission deadline
  • ODS code sync for trust hierarchy

NHS CIS2 & Smartcard SSO

NHS Edition

Single sign-on for NHS staff via NHS login (CIS2) and Smartcard authentication — no separate passwords needed.

  • NHS login (CIS2) OAuth 2.0 integration
  • Smartcard-based identity assurance
  • Automatic role mapping from NHS directory
  • Audit log for all clinical access

Caldicott Guardian & SIRO Roles

NHS Edition

Dedicated role management for Caldicott Guardians, SIROs, and DPOs within NHS organisation structures.

  • Named role assignment and tracking
  • Handover documentation workflow
  • Role-specific task queues
  • Annual review reminders
Supplier & Policy

Third-Party Supplier Due Diligence

Send, track, and score supplier data-protection questionnaires. Maintain a live contract and DPA register.

  • Customisable supplier questionnaire builder
  • Automated scoring and risk tiering
  • DPA and contract expiry reminders
  • Supplier portal for self-service responses

Policy & Procedure Management

Publish, version-control, and distribute policies to staff. Automated acknowledgment tracking and renewals.

  • Drag-and-drop policy editor with TipTap
  • Staff acknowledgment tracking dashboard
  • Scheduled review and version history
  • Pre-loaded NHS and UK GDPR policy templates
Platform & Security

Azure AD & SSO

Single sign-on through Microsoft Entra ID for any UK organisation — works alongside NHS CIS2 for mixed environments.

  • Microsoft Entra ID (Azure AD) OIDC
  • SAML 2.0 enterprise support
  • MFA enforcement policies
  • Automatic user provisioning (SCIM)

Compliance Dashboard & Reporting

Real-time compliance health scores, overdue tasks, and board-ready reporting at a glance.

  • RAG status across all compliance areas
  • Exportable board reports (PDF)
  • Trend charts for breaches and SARs
  • Custom KPI widgets

Automated Notifications

Never miss a deadline. Folelse sends smart reminders for SARs, DSPT submissions, policy reviews, and supplier renewals.

  • Email and in-app notifications
  • Configurable escalation paths
  • Digest mode for busy periods
  • Microsoft Teams webhook integration

UK Data Residency & Security

All data stored in UK datacentres, with role-based access control, a full audit trail, and annual penetration testing.

  • UK-only data residency (Microsoft Azure, UK South)
  • Role-based access with least-privilege
  • Immutable audit log
  • Annual CREST-certified pen test

Ready to see it in action?

Start your free trial today — no credit card required. Or talk to our team for a personalised demo.