Maintain the per-identity, per-purpose consent record behind the data your vehicles collect, assemble what a deletion or opt-out request rests on, and hold the response for the privacy officer who answers for it.
2Record assembledSignals, purposes, consent timestamps and recipients, each with its named source
3Response proposedScope, record classes, clock dates and confidence
4Controls appliedCompleteness checks, clock separation, no-verification routing and confidence threshold
No human action required
Stages 1 to 4 run unaided, and nothing is deleted or sent at any of them — the agent is assembling, and the officer's lane opens at the confidence gate.
5DecisionBranches at the confidence threshold
High confidence
Goes to the privacy officer.
Low confidence
Adds a privacy-counsel read first.
Officer approval
The response is held with its evidence, its open gaps and the confidence.
Approve · Amend · Send to counsel review
Approved — released to the requester▼
6Privacy systems updatedOnly where write access and approval policy allow it
7Outcome evaluatedAmendment rate, clock adherence, regulator queries and reopened requests
Amendments
Every officer amendment is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Deleting driver data, or certifying a deletion is complete.
Deciding a retention-schedule exception covers a record class.
Swearing the one-year compliance report under 28 U.S.C. §1746.
Deciding a telematics flow is a sale or a share.
Automation boundaryAgent acts unaided
✓Assemble the consent, purpose and recipient record per identity.
✓Carry each signal with the consent it was collected under.
✓Track the 15-business-day and the 45-day clocks separately.
✓Flag the gaps the officer should weigh, and hold the response.
The record is maintained here, not downstream, and no write runs ahead of the officer.
Deciding whether a recipient is a consumer reporting agency.
Granting, withdrawing or reconstructing a consumer's consent.
Classifying an element as raw, pre-processed or derived.
Changes to retention rules, clocks or response boundaries.
Example output
One request, annotated
Everything the agent assembles is attached to the record it was drawn from.
Consent-record output · single requestIllustrative example
A programme-level response rate can look settled while a small number of data categories absorb most of the reopened requests. Nestack reports the amendment rate by slice, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Precise geolocation
8.9%
3.7×
Review
Second drivers and passengers
7.1%
3.0×
Review
Resold and lease-return VINs
4.0%
1.7×
Watch
Single-driver owned vehicles
1.3%
0.5×
Normal
Bar: amendment-rate lift vs. single-driver-vehicle baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
Every cycle ends by adding a case
A cycle closes when the unsupported deletion is a regression case the next release must pass. That suite is what the next request.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Amendment rate rises in a data-category slice.
02Diagnose
The deletion request answered for one system out of nine is read back until the cause narrows to one.
03Improve
The fix gets a number, and the requests that raised it are held against it.
04Verify
No release while a touched consent case is outstanding; it reruns until green.
05Learn
The case is retained, and the categories it touches are logged beside it.
Learn → DetectThe return edge. The next request is answered against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, request workflow, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Privacy workflow discovery and boundary definition.
02Telematics and consent-source assessment.
03Retention, purpose and response-clock rule mapping.
04Consent-record ingestion and normalisation.
05Response assembly and source binding.
06Confidence scoring and gap routing.
07Privacy officer approval.
08Privacy and telematics system integration.
09Consent and request cases.
10Guardrails and response controls.
11Signal-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne brand, one jurisdictionProductionProduction privacy systemsAdvancedMultiple brands / regions
Introduced at Pilot
Assembly to your ledger and rules✓✓✓
Officer approval✓✓✓
Consent-coverage baseline✓✓✓
Introduced at Production
Reporting by data category—✓✓
Approval workflow in your systems—✓✓
Approved write-back—✓✓
Telematics-platform integration—✓✓
Introduced at Advanced
Multiple state and EU regimes——✓
Multi-stage privacy approvals——✓
High request volume——✓
Multi-jurisdiction consent controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, transaction volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your consent ledger and signal catalogue→Consent-record ingestion and evidence mappingWeek 1
02Representative requests already answered→Response baseline and source bindingWeek 2
03Your retention schedule and response clocks→Retention, purpose and response-clock rule mappingWeek 1
04Access to relevant APIs, feeds or exports→Telematics and consent-source assessment, then integration setupWeek 2
05Answers you would not want audited→Deletion cases and failure-mode testingWeek 4
06What no response may claim→Confidence scoring, gap routing, guardrails and response controlsWeek 3
07A named privacy officer to approve→Officer approval workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
The bands follow the request volume, which is why the fifth week carries both at once.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Privacy workflow discovery, rule mapping and the automation boundaryW2Consent-ledger integration and the response baselineW3Request workflow, confidence logic and approval controlsW4Evaluation suite, clock and routing checks and failure-mode testingW5Downstream-system integration, pilot requests and targeted correctionsW6One request cycle answered under the privacy officer, then Agent Care handover
Reading the bandA band spans only the weeks its work is named in. The week 5 overlap is real, not padding.
At the end of W6The final checks clear on live requests and monitoring moves to Agent Care.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Automotive AI agent
Build a consent-of-record agent around your privacy officer's desk.
Consent is logged, not signed, and Oregon HB 3875 leaves automakers no size threshold. Bring the general counsel who would swear your compliance report — the record is theirs too.