What we'll deliver in Year 2. Monthly Sam × Ramses review cadence. Five anchor metrics drive everything.
How theHUB protects A'DAM Works (and its members) under EU data-protection law. Mirrored on the Hub Ibiza side so both tenants are covered.
| Risk | Mitigation | Owner / when |
|---|---|---|
| EU→US data transfer when using Claude / Gemini for analysis | Sign Anthropic DPA (Standard Contractual Clauses) + enable Zero Data Retention on the commercial Claude account. Same for Gemini Gem (Google). | Sam · by Fri 22 May |
| Member PII exposure in AI prompts | Pseudonymisation layer — Claude sees lead_id_XXXX, never raw names/emails. Real PII stays on Mac Mini local store; dashboard UI un-pseudonymises for human readers with legitimate access. | Sam + Claude · by 5 Jun |
| Outdated consent for AI-driven analysis of member data | GDPR consent refresh email to all 318 ADAM Works members. Explicit opt-in for: MRM Gemini Gem, Claude orchestration, future Community Graph, Outlook inbox cross-ref. | Sam + Nienke · by 23 May |
| Profiling (Art 22) via the Community Knowledge Graph | DPIA before launch · explicit fresh consent (not retroactive) · purpose limited to matchmaking, never scoring/exclusion · one-click opt-out · automatic erasure on departure. | Sam + Ramses · DPIA by 15 Jun · launch pushed to mid-Jul |
| Right to access (Art 15) not yet honoured at scale | Build /me/ self-service profile page on adamworks.thehubibiza.com. Member sees their data + exercises rights with one click each (export, rectify, erase, object). | Sam + Claude · by 12 Jun |
| Stale T&Cs in Nexudus member portal | Updated T&Cs + AI processing disclosure in Nexudus Document Templates (both tenants). Force re-acceptance on next member login via billing/proposals. Form submission footers link to updated terms — opt-in at source. | Sam + Nienke · by 5 Jun |
| Sub-processor disclosure incomplete in privacy notices | Update privacy notices on adamworks.nl + thehubibiza.com to list every AI sub-processor (Anthropic, Google, Microsoft if Outlook live) with purpose + lawful basis + retention. | Sam + Claude · by 28 May |
| Risk | Watching for | Action |
|---|---|---|
| Phase 2 CPA > €55 | Mid-Jun first 7d data | Hold at €5k/day, troubleshoot ad copy + keyword set |
| MRM Round 1 stalls below 50 coffees | End of Jun | Restructure incentive for Nienke + Laly time-on-coffees |
| Six Senses doesn't consolidate to Floor 10 | Jul update from Ramses | Re-plan Floor 9 strategy; fill from Floor 14 surplus pipeline |
| Toon P&L data still missing by Aug | Monthly Sam × Ramses review | Build reporting from invoicing CSV alone (Sabrina), flag gap to Duncan |
| GTM dedupe fails final attempt | Once Kim's permission lands | Drop 3 GA4 IDs anyway via Site Kit-managed config + GA4 settings UI |