This privacy policy explains how we collect, use, and protect your personal data when you use the Consentio service. We take your privacy seriously and are committed to protecting your personal data in accordance with Regulation (EU) 2016/679 (GDPR).
1. Data Controller
The controller of your personal data is:
David Azarian
Business ID: 17064619
Email: [email protected]
Telephone: +420 774 147 594
Website: consentio.cz
As a sole trader, we are not required to appoint a Data Protection Officer (DPO). For any questions regarding personal data processing, please contact us at the email address above.
2. What Data We Process
2.1 Registered users (Consentio customers)
During registration and use of the service, we process:
| Data category | Specific data | Requirement |
|---|---|---|
| Identification data | First name, surname, email | Required for registration |
| Access data | Password (stored as a hash) | Required for registration |
| Company data | Company name, business ID, role | Optional |
| Contact data | Telephone | Optional |
| Billing data | Billing address, VAT ID | Required for paid plans |
| Payment data | Card details (processed by Stripe) | Required for paid plans |
2.2 Widget visitors (users of our customers' websites)
When interacting with the cookie widget on our customers' websites, we process:
| Data | Description | Note |
|---|---|---|
| visitorId | Anonymous visitor identifier | It is not possible to identify the person retrospectively |
| Consent decision | Consent choices by category | necessary, analytics, marketing, preferences |
| Country | Derived from IP address (geolocation) | IP address is not stored |
| User Agent | Browser and device type | For analytical purposes |
| UTM parameters | Marketing parameters from URL | Optional, if present |
| Timestamp | Date and time of consent grant/change | For proof of consent |
2.3 Visitors to the consentio.cz website
On our consentio.cz website, we only use technically necessary cookies for:
- Maintaining login sessions (session cookie)
- User authentication (auth token)
- Protection against CSRF attacks
We do not use third-party analytics or marketing cookies.
3. Purposes of Processing
3.1 Service provision
- Creating and managing user accounts
- Providing Consentio service functionality
- Storing consent records for our customers
- Displaying statistics and analytics
3.2 Invoicing and accounting
- Issuing invoices and tax documents
- Processing payments through Stripe
- Maintaining accounting records as required by law
3.3 Communication
- Sending transactional emails (registration confirmation, invoices, account changes)
- Technical support and responding to queries
- Important service announcements (changes to terms, outages)
3.4 Analytics (aggregated)
- Improving the service based on anonymised data
- Service usage statistics (without identifying individuals)
4. Legal Basis for Processing
| Purpose | Legal basis | GDPR reference |
|---|---|---|
| Service provision | Performance of a contract | Art. 6(1)(b) |
| Invoicing and accounting | Legal obligation | Art. 6(1)(c) |
| Technical support | Performance of a contract | Art. 6(1)(b) |
| Service improvement | Legitimate interest | Art. 6(1)(f) |
| Fraud prevention | Legitimate interest | Art. 6(1)(f) |
4.1 Legitimate interests
Our legitimate interests include:
- Improving and developing the service
- Protection against fraudulent conduct and service misuse
- Ensuring service security
When processing on the basis of legitimate interest, we always carry out a balancing test and ensure that processing is proportionate and does not unduly interfere with your rights. Legitimate Interest Assessment (LIA) documentation is available upon request at [email protected].
5. Retention Period
| Data type | Retention period | Reason |
|---|---|---|
| User account data | Duration of the account | Performance of a contract |
| Accounting documents (invoices) | 10 years | Legal obligation (Accounting Act) |
| Consent records (Free) | 7 days | As per plan |
| Consent records (Pro/Agency) | Unlimited | As per plan |
| Logs and security records | 90 days | Security and diagnostics |
5.1 Erasure upon request
Upon account deletion or at your request, we will erase personal data immediately, with the exception of data we are legally obliged to retain (accounting documents).
6. Data Recipients (Sub-processors)
We only share your personal data with trusted partners who help us provide the service:
| Service | Provider | Purpose | Data location |
|---|---|---|---|
| Cloudflare D1 | Cloudflare Inc. | Database, storage of user data and consent records | EU |
| Cloudflare Pages | Cloudflare Inc. | Web application hosting | EU |
| Cloudflare | Cloudflare Inc. | CDN, protection, cache, geolocation | EU |
| Resend | Resend Inc. | Sending transactional emails | USA (DPF) |
| Stripe | Stripe Inc. | Payment processing | USA (DPF) |
We have data processing agreements (DPA) in place with all sub-processors in accordance with Art. 28 GDPR.
7. Transfers to Third Countries
Some of our sub-processors are based in the USA. For transferring personal data to the USA, we use the following safeguards:
7.1 Data Privacy Framework (DPF)
Stripe and Resend are certified under the EU-US Data Privacy Framework, which provides adequate protection of personal data as per the European Commission's decision.
- Stripe: DPF certified - Verify certification
- Resend: DPF certified - Verify certification
7.2 Standard contractual clauses
In the event that DPF certification becomes invalid, we have standard contractual clauses (SCCs) approved by the European Commission in place with all sub-processors.
8. Data Subject Rights
In connection with the processing of your personal data, you have the following rights:
8.1 Right of access (Art. 15 GDPR)
You have the right to obtain confirmation as to whether your personal data is being processed, and if so, to access it and obtain information about the processing.
8.2 Right to rectification (Art. 16 GDPR)
You have the right to rectification of inaccurate personal data and to have incomplete data completed.
8.3 Right to erasure (Art. 17 GDPR)
You have the right to erasure of personal data ("right to be forgotten") if the data is no longer needed, you withdraw consent, or you raise an objection.
8.4 Right to restriction of processing (Art. 18 GDPR)
You have the right to restriction of processing in certain cases, for example when verifying the accuracy of data.
8.5 Right to data portability (Art. 20 GDPR)
You have the right to receive your personal data in a structured, commonly used format (e.g. JSON, CSV).
8.6 Right to object (Art. 21 GDPR)
You have the right to object to processing based on legitimate interest.
8.7 How to exercise your rights
8.8 Right to lodge a complaint
You have the right to lodge a complaint with the supervisory authority:
Office for Personal Data Protection (UOOU)
Pplk. Sochora 27, 170 00 Prague 7
Website: www.uoou.cz
Email: [email protected]
8.9 Automated decision-making (Art. 22 GDPR)
We do not use automated decision-making or profiling within the meaning of Article 22 GDPR. No decision with legal effects is made solely on the basis of automated processing.
10. Data Security
We implement technical and organisational measures to protect your personal data:
10.1 Technical measures
- Transit encryption: All communication is encrypted using HTTPS (TLS 1.3)
- Password encryption: Passwords are stored as hashes using bcrypt
- Data encryption: Sensitive data is encrypted at rest
- Access rights: Data access based on role only (RBAC)
- Data isolation: Individual customer data is isolated
10.2 Organisational measures
- Regular security audits
- Data minimisation principle
- Personal data protection training
- Incident response plan
10.3 Data location
The primary database and hosting are located in the EU through Cloudflare.
11. Changes to the Policy
We may update this privacy policy from time to time. We will inform you of significant changes:
- By email at least 30 days before the changes take effect
- By notification in the Dashboard application
- By updating the effective date on this page
We recommend regularly checking this page for up-to-date information.
12. Effectiveness
Version 1.0: This privacy policy takes effect on 2 February 2026.