Consentio
FeaturesPricingAbout usBlogDocumentation
EN
Log inStart free

Privacy Policy

Effective from: 2 February 2026

Contents

This privacy policy explains how we collect, use, and protect your personal data when you use the Consentio service. We take your privacy seriously and are committed to protecting your personal data in accordance with Regulation (EU) 2016/679 (GDPR).

1. Data Controller

The controller of your personal data is:

David Azarian

Business ID: 17064619

Email: [email protected]

Telephone: +420 774 147 594

Website: consentio.cz

As a sole trader, we are not required to appoint a Data Protection Officer (DPO). For any questions regarding personal data processing, please contact us at the email address above.

2. What Data We Process

2.1 Registered users (Consentio customers)

During registration and use of the service, we process:

Data category Specific data Requirement
Identification data First name, surname, email Required for registration
Access data Password (stored as a hash) Required for registration
Company data Company name, business ID, role Optional
Contact data Telephone Optional
Billing data Billing address, VAT ID Required for paid plans
Payment data Card details (processed by Stripe) Required for paid plans

2.2 Widget visitors (users of our customers' websites)

When interacting with the cookie widget on our customers' websites, we process:

Data Description Note
visitorId Anonymous visitor identifier It is not possible to identify the person retrospectively
Consent decision Consent choices by category necessary, analytics, marketing, preferences
Country Derived from IP address (geolocation) IP address is not stored
User Agent Browser and device type For analytical purposes
UTM parameters Marketing parameters from URL Optional, if present
Timestamp Date and time of consent grant/change For proof of consent
Important: We do not store visitor IP addresses. For geolocation, we only use the derived country information, which is not personal data.

2.3 Visitors to the consentio.cz website

On our consentio.cz website, we only use technically necessary cookies for:

  • Maintaining login sessions (session cookie)
  • User authentication (auth token)
  • Protection against CSRF attacks

We do not use third-party analytics or marketing cookies.

3. Purposes of Processing

3.1 Service provision

  • Creating and managing user accounts
  • Providing Consentio service functionality
  • Storing consent records for our customers
  • Displaying statistics and analytics

3.2 Invoicing and accounting

  • Issuing invoices and tax documents
  • Processing payments through Stripe
  • Maintaining accounting records as required by law

3.3 Communication

  • Sending transactional emails (registration confirmation, invoices, account changes)
  • Technical support and responding to queries
  • Important service announcements (changes to terms, outages)

3.4 Analytics (aggregated)

  • Improving the service based on anonymised data
  • Service usage statistics (without identifying individuals)

4. Legal Basis for Processing

Purpose Legal basis GDPR reference
Service provision Performance of a contract Art. 6(1)(b)
Invoicing and accounting Legal obligation Art. 6(1)(c)
Technical support Performance of a contract Art. 6(1)(b)
Service improvement Legitimate interest Art. 6(1)(f)
Fraud prevention Legitimate interest Art. 6(1)(f)

4.1 Legitimate interests

Our legitimate interests include:

  • Improving and developing the service
  • Protection against fraudulent conduct and service misuse
  • Ensuring service security

When processing on the basis of legitimate interest, we always carry out a balancing test and ensure that processing is proportionate and does not unduly interfere with your rights. Legitimate Interest Assessment (LIA) documentation is available upon request at [email protected].

5. Retention Period

Data type Retention period Reason
User account data Duration of the account Performance of a contract
Accounting documents (invoices) 10 years Legal obligation (Accounting Act)
Consent records (Free) 7 days As per plan
Consent records (Pro/Agency) Unlimited As per plan
Logs and security records 90 days Security and diagnostics

5.1 Erasure upon request

Upon account deletion or at your request, we will erase personal data immediately, with the exception of data we are legally obliged to retain (accounting documents).

6. Data Recipients (Sub-processors)

We only share your personal data with trusted partners who help us provide the service:

Service Provider Purpose Data location
Cloudflare D1 Cloudflare Inc. Database, storage of user data and consent records EU
Cloudflare Pages Cloudflare Inc. Web application hosting EU
Cloudflare Cloudflare Inc. CDN, protection, cache, geolocation EU
Resend Resend Inc. Sending transactional emails USA (DPF)
Stripe Stripe Inc. Payment processing USA (DPF)

We have data processing agreements (DPA) in place with all sub-processors in accordance with Art. 28 GDPR.

7. Transfers to Third Countries

Some of our sub-processors are based in the USA. For transferring personal data to the USA, we use the following safeguards:

7.1 Data Privacy Framework (DPF)

Stripe and Resend are certified under the EU-US Data Privacy Framework, which provides adequate protection of personal data as per the European Commission's decision.

  • Stripe: DPF certified - Verify certification
  • Resend: DPF certified - Verify certification

7.2 Standard contractual clauses

In the event that DPF certification becomes invalid, we have standard contractual clauses (SCCs) approved by the European Commission in place with all sub-processors.

8. Data Subject Rights

In connection with the processing of your personal data, you have the following rights:

8.1 Right of access (Art. 15 GDPR)

You have the right to obtain confirmation as to whether your personal data is being processed, and if so, to access it and obtain information about the processing.

8.2 Right to rectification (Art. 16 GDPR)

You have the right to rectification of inaccurate personal data and to have incomplete data completed.

8.3 Right to erasure (Art. 17 GDPR)

You have the right to erasure of personal data ("right to be forgotten") if the data is no longer needed, you withdraw consent, or you raise an objection.

8.4 Right to restriction of processing (Art. 18 GDPR)

You have the right to restriction of processing in certain cases, for example when verifying the accuracy of data.

8.5 Right to data portability (Art. 20 GDPR)

You have the right to receive your personal data in a structured, commonly used format (e.g. JSON, CSV).

8.6 Right to object (Art. 21 GDPR)

You have the right to object to processing based on legitimate interest.

8.7 How to exercise your rights

Email: [email protected]

Subject: GDPR - [Request type]

Response time: 30 days

8.8 Right to lodge a complaint

You have the right to lodge a complaint with the supervisory authority:

Office for Personal Data Protection (UOOU)

Pplk. Sochora 27, 170 00 Prague 7

Website: www.uoou.cz

Email: [email protected]

8.9 Automated decision-making (Art. 22 GDPR)

We do not use automated decision-making or profiling within the meaning of Article 22 GDPR. No decision with legal effects is made solely on the basis of automated processing.

9. Cookies on the consentio.cz Website

On our website, we only use technically necessary cookies that do not require your consent:

Name Purpose Duration Type
sb-access-token User authentication Session / 1 hour Necessary
sb-refresh-token Authentication renewal 7 days Necessary

9.1 How to refuse cookies

You can refuse or delete cookies in your browser settings. Please note that refusing necessary cookies may affect website functionality (e.g. login).

10. Data Security

We implement technical and organisational measures to protect your personal data:

10.1 Technical measures

  • Transit encryption: All communication is encrypted using HTTPS (TLS 1.3)
  • Password encryption: Passwords are stored as hashes using bcrypt
  • Data encryption: Sensitive data is encrypted at rest
  • Access rights: Data access based on role only (RBAC)
  • Data isolation: Individual customer data is isolated

10.2 Organisational measures

  • Regular security audits
  • Data minimisation principle
  • Personal data protection training
  • Incident response plan

10.3 Data location

The primary database and hosting are located in the EU through Cloudflare.

11. Changes to the Policy

We may update this privacy policy from time to time. We will inform you of significant changes:

  • By email at least 30 days before the changes take effect
  • By notification in the Dashboard application
  • By updating the effective date on this page

We recommend regularly checking this page for up-to-date information.

12. Effectiveness

Version 1.0: This privacy policy takes effect on 2 February 2026.

Have questions?

Email: [email protected]

Telephone: +420 774 147 594

Consentio

Cookies without stress. GDPR without a lawyer.

VisaMastercardApple PayGoogle Pay

Product

  • Features
  • Pricing
  • Documentation
  • Sitemap

Company

  • About us
  • Blog
  • Dictionary
  • Contact

Legal

  • Terms of Service
  • Privacy Policy
  • GDPR
  • Request your data

Contact

  • [email protected]
  • +420 774 147 594
  • ID: 17064619

© 2026 Consentio | By Kosmoweb.cz