GDPR built into the data model
Every Stockholm build is planned against the EU General Data Protection Regulation, which the national data protection authority enforces. We keep a plain list of what is collected and why, set retention rules in code, and make export and deletion ordinary features.