Claim & review
An engineer has forwarded you a draft record built from their real systems — the structure, never the rows. This page is how you open it, sign in, and get your bearings — what the record shows, which calls are already made, and which are waiting for you. Reviewing needs no account; signing does.
- Open the link on your own laptop. It opens from any machine — no install, no password. (how ↓)
- Sign in with the one-time email link — only to fill or confirm; reading needs no account. (how ↓)
- Know what reviewing commits you to: nothing. Reading and filling sign nothing. (why ↓)
- Read what the record shows — the activities, the coverage, the per-field badges. (how ↓)
- Do the three first-read checks — the activities, the open legal calls, the sensitive data. (the checks ↓)
- Decide what’s missing — and if a system is unreached, get the engineer to re-scan. (how ↓)
Walk one claim all the way through (the worked example)
Before the detail, do one claim end to end so the loop is concrete. An engineer at Aurelia Payments Oy forwarded a draft built from their systems. Here is each of the six steps for it:
| Step | What you do | What you see / decide |
|---|---|---|
| 1 · Open | Click the forwarded claim link on your laptop. | The live record loads — no login needed to read. (If the link looks like localhost, see the branch below — the one you were sent is the hosted address.) |
| 2 · Sign in | Enter your work email, press Email me a sign-in link, open the email, click through Confirm it’s you. | You’re signed in — no password set. The first verified sign-in becomes the record’s admin. (Signed in but see “no role on this record”? That’s the branch below — the draft was addressed to a specific person.) |
| 3 · Commit? | Nothing yet. | Reading and filling commit you to nothing. The record stays DRAFT; signing is a separate, later act. |
| 4 · Read | Read the intro block, the coverage banner and the activities. | Three activities — Manage customer accounts, Customer due diligence (KYC/AML), Take and record payments — on 2 of 4 systems reached. The “Where this stands” panel counts what’s still blank: some calls are yours, the rest your engineering team’s. |
| 5 · Three checks | Activities right? · open legal calls? · sensitive data? | KYC/AML is present and correctly named. Purpose, basis and retention are still suggestions. “0 Art. 9” is flagged — sanity-check it, since KYC rarely looks sensitive by column name. |
| 6 · What’s missing | Note the coverage banner. | snowflake-dwh and stripe were unreachable — email the engineer to re-scan. You’ll know it worked when the banner clears. |
Every claim is that same six-step pass. The rest of this page is each step in full — including the three branches a real reviewer hits: the link that looks like phishing, a system that is missing, and a record that is not yours to sign yet.
What the engineer forwards
The engineer either runs regixo invite on their machine, or presses Make the
invitation on their own portal — the same thing, either way. That produces two things they send
you, and nothing else leaves their machine but metadata:
- A draft PDF —
RoPA_DRAFT.pdf, a readable Record of Processing Activities you can open with no tools. It carries the DRAFT stamp and a “claim this in the portal” link. - A claim link — the same link, on its own, so you can open the live record in your browser:
https://app.regixo.com/claim/clm_<token>. The token in the link is the credential; whoever holds it can open the record.
Both point at the same record. The PDF is for forwarding and reading offline; the link is for filling and, later, signing. The engineer never had to create an account to send them.
The engineer’s own Record page carries the same hand-off: ↓ Download the draft PDF is a
one-click download there (with the DORA register as an HTML file, for financial firms), beside a
See what they’ll get preview of exactly the page you will open. And before anything is sent,
regixo serve-claim serves that record page locally — the engineer reads exactly what you
will read.
The exact payload that arrived
What reached you is metadata only — the same list the engineer saw and approved on their own invite screen before anything was sent. It is:
- the table paths of the tables that look personal;
- the kinds of personal data in them (the categories — never the column name);
- the drafted record and your organisation name;
- the recipient address, only if one was typed, exactly as typed.
And never: a row or a value, column names, column types, credentials, or table owners.
Everything else is a count, not a name. The list you can read on the claim is identical to the
one the engineer confirmed at the regixo invite gate — the same preview, on both sides of
the hand-off, so nothing reaches you that they did not watch leave.
1 · Open the link on your own laptop
The claim link points at whichever portal your engineer forwarded it to — app.regixo.com is the default once that host is switched on, and it is not yet, so today the link names the portal they ran. Either way you install nothing and set no password. Opening it lands you straight on the record; reading needs no account. The token in the link is the credential, so treat the link as you would a shared secret: whoever holds it can open the record.
http:// or a localhost link is the shape a security-minded person is
trained to distrust — so here is why the one you were sent is safe, and how to open it. A
localhost link only ever works on the machine that made it: that is the engineer’s
local address. Once the hosted portal is switched on, the link you are sent points there and
opens anywhere; until then it names the portal your engineer is running. You never create a password and never install anything — you prove who you are with
a one-time link sent to your email, so there is no account to be phished. The fix, if a link ever looks
wrong, is the ordinary one: confirm with the colleague who sent it before you open it. The full
vendor due diligence is Is it safe to sign?2 · Sign in with the one-time email link
Opening the claim link lands you straight on the record — no login to look. When you are ready to change or confirm anything, you sign in with a one-time email link (a “magic link”). Here is the exact flow, and the one branch where the record turns you away:
Reading the draft needs no account — the claim link is enough. To change or confirm anything, press Email me a sign-in link: Regixo sends a one-time link, good for 15 minutes. Corporate mail scanners often open links first, so it lands on a Confirm it’s you page — press Continue to sign in → and you are in, with no password to set. The first person to sign in on a claim becomes the record’s admin. A tour: the compliance portal tour.
Signing in is a portal act — no terminal command signs a person in. The engineer’s side is
regixo invite to send the claim, and later regixo seal pull to bring
the sealed copy home.
An agent can read the draft over the read-only API, but it never signs in and never signs — signing names a verified person.
- Enter your work email and press Email me a sign-in link. Regixo sends a single-use link, good for 15 minutes.
- Open the email and click the link. Corporate mail scanners often open links first, so it lands on a Confirm it’s you page — press Continue to sign in → and you are in, with no password to set or remember.
- The first verified sign-in becomes the record’s admin, so the record you later sign carries a verified identity — the signature can name who you are. The admin can then add the rest of the team.
3 · Reviewing commits you to nothing
This is worth stating plainly, because your name may one day go on this record. Opening the link, reading every activity, even filling in the legal calls — none of it signs anything. The record stays a DRAFT until a named person deliberately signs it, and the DRAFT is free forever. Nothing on the claim asks for a card to read or to fill. Signing is a separate step, covered on Unlock, sign & maintain — you reach it only when your team decides the record is ready.
4 · Read what the record shows
The record opens as a finished-looking document built from the engineer’s real tables — not a blank form. Three things orient you:
- The activities — each thing done with personal data, grouped from the scanned tables, with the Article 30 fields. (What each field means: Understand the record.)
- A coverage meter — how much of the estate the draft is built on, stated plainly (for example, “18 of 22 datasets mapped · 5 of 6 sources reached”). A partial scan is honest about what it missed, never silent.
- Per-field badges — every field shows its state: auto-filled (Regixo measured it), suggested (a starting point to confirm), or needs you (only you can supply it). Special-category data is marked ⚠ Art. 9.
A “Read this first” block sits at the top of the claimed record, under the letterhead: what it is, where it came from, what is done and what is still blank — with a provenance line stating exactly what left the engineer’s machine, a coverage banner when a source could not be reached, and a “Where this stands” card in the rail carrying the counts:
GDPR · Art. 30 · Record of Processing — drafted from your own systems
Record of Processing Activities
A plain list of every way your company uses people’s personal data — drafted from the sources you configure. EU law (GDPR Art. 30) makes most companies keep one. Each entry is an activity: your datasets, grouped by the job they serve. Not yet defensible — it becomes official when the legal fields are confirmed and a named person signs.
3 records · 3 named · 3 with open calls
Your engineering team answered their part on 2026-07-10. 3 fields came from them — security measures, recipients, data subjects. They are facts about the systems, not legal decisions: yours to review and confirm below.
Read this first
- What this is — the list of how your company uses people’s personal data — the “Record of Processing” most EU organisations must keep.
- Where it came from — your engineering team mapped the sources they configure with Regixo, which drafted this from their schemas.
- What’s done — the data inventory is mapped for you.
- What needs you — 10 legal calls are still blank — purpose, your lawful basis, retention and transfers. Your team fills them below; then you sign.
- Your privacy — what reached this page is metadata only: the drafted record, the names of the 4 tables behind it, and counts. No column names, no column types, no row values — they never left your team’s machine.
- What’s not covered —
snowflake-dwh,stripe(unreachable at the last scan).
Forwarded draft — received 2026-07-10 · what left their machine: metadata only — the names of the 4 tables these activities are built from, the drafted record, and counts (4 datasets · 9 personal-data flags). No column names or row values, ever. No account needed to review. · what changed → · who is Regixo? →
The same summary, as plain text:
Record of Processing Activities — DRAFT GDPR Article 30 · not defensible until your team confirms the legal calls and signs Coverage 18 of 22 datasets · 5 of 6 sources reached Auto-filled 23 mechanical fields Needs you 14 legal fields across 6 activities Special category 2 activities carry Art. 9 data
One more state to know: staleness. If the engineer’s catalog changes after they send the invitation, their own Record page says so plainly — “Your catalog has changed since you made this … The record behind this link no longer matches what Regixo sees today.” The fix is theirs, not yours: they re-scan and make a fresh invitation. The new link replaces the old one, and everything your team filled in carries over — answers, licence and team members all move to the fresh record.
And if their machine is paired, the record can move while you are reading it. You do not have to watch for that: a small bar appears at the bottom of the page saying “This record was updated <when>”, with See what changed and Reload. It never reloads by itself, and if you have typed an answer that is not yet saved it asks a second time before throwing it away. On a record you have already signed it adds “What you signed is unchanged” — a new copy of the draft arriving never touches the sealed snapshot.
5 · The three first-read checks
You do not need to read every field to know where you stand. On a first pass, check three things:
- The activities are right — the tables were grouped into activities that match how you actually work. Any grouping tagged “best guess — review” is one to confirm or split first.
- The outstanding legal calls — scan for needs you: the purposes, lawful bases, retention periods and transfer decisions that are yours to make. The engineer’s facts — security measures, recipients, data subjects — usually arrive answered; review them as you go. These are the work of the next page.
- The sensitive data — any ⚠ Art. 9 or criminal-offence (Art. 10) activity needs a specific ground before the record can be signed. Start there; those are the strictest calls.
6 · Decide what’s missing — and get a re-scan
The coverage meter and the banner name any source the last scan could not reach, so a missing system is visible, not silent. Closing that gap is the engineer’s job, not yours — a scanner runs on their machine, against their credentials. What you do is ask, and name the system.
- Email the engineer the name of the missing source (the record shows it — for example
snowflake-dwh) and ask them to re-scan it into the catalog. - They re-scan —
regixo watchpicks up a source that is now reachable, or they re-run the scan and make a fresh invitation for one that was down. - You’ll know it worked three ways: the coverage banner clears (or the count rises — “2 of 4 systems” becomes “4 of 4”), the activities that lived only in that system appear, and if they had to send a fresh link it replaces the old one and carries your team’s work over — answers, licence and members all move to the new record.
You never re-do filled fields to gain coverage: a re-scan adds what was missing and leaves your confirmed legal calls untouched.
How you know you’re done
You are ready to move on to the legal calls when all of these are true:
- You have opened the record on your own machine — and signed in, if you will fill or confirm.
- You know reviewing has committed you to nothing: the record still reads DRAFT.
- You have read the activities, the coverage banner and the per-field badges.
- You have done the three first-read checks and noted every needs you.
- For any unreached system, you have emailed the engineer and know the signal it worked — the coverage banner clears (or the count rises).
Nothing here signs anything. The record stays a DRAFT until a named person deliberately signs it, which is two stations further on.
The engineer’s side is done: they scanned your real systems, answered their three facts (security measures, recipients, data subjects), and forwarded the draft — only structure ever left their machine. Your side starts now: claim the link, review, and fill the legal calls. The one thing you may still need from them is a re-scan if a system is missing (above); everything else on the record is yours to complete.