1. Introduction
1.1 What is Consentio?
Consentio is a SaaS service for managing cookie consent (Consent Management Platform - CMP). It helps website operators ensure compliance with GDPR and the ePrivacy Directive through:
- Customisable cookie banner for collecting consent
- Automatic cookie scanning and categorisation
- Consent record storage and management (proof of consent)
- Google Consent Mode v2 integration
- Consent analytics and reporting
1.2 Who is this document for
This document is intended for Consentio customers (website operators) who need to understand:
- What role Consentio plays in personal data processing
- What obligations arise from the data processing agreement
- How their visitors' data is protected
- What obligations they have towards their visitors
2. Consentio's Role in Data Processing
2.1 Consentio as controller
For Consentio customer data (your account details, login credentials, billing data), we act as the data controller.
- We determine the purposes and means of processing
- We bear responsibility for processing in accordance with GDPR
- Details can be found in our Privacy Policy
2.2 Consentio as processor
For consent data from your website visitors, we act as a data processor.
- You (the customer) are the controller of this data
- Consentio processes data only according to your instructions
- The relationship is governed by the data processing agreement (DPA)
| Data type | Controller | Processor |
|---|---|---|
| Customer account (email, password, billing details) | Consentio | - |
| Consent records from your website visitors | You (the customer) | Consentio |
3. Data Processing Agreement (DPA)
3.1 Automatic conclusion
The Data Processing Agreement (DPA) is automatically concluded upon registration and acceptance of the Terms of Service. You do not need to sign any additional documents.
3.2 Subject of processing
Under the DPA, we process consent data from your website visitors for the purpose of:
- Consent record storage and management
- Providing proof of consent for compliance purposes
- Displaying consent analytics and statistics
- Google Consent Mode integration
3.3 Consentio's commitments as processor
As a processor, we commit to:
- Processing data only according to the controller's documented instructions
- Ensuring that persons authorised to process data are bound by confidentiality
- Implementing all technical and organisational measures to secure data
- Using sub-processors only with your consent
- Assisting the controller in fulfilling their obligations (data subject rights, DPIA)
- Deleting or returning all data upon termination of the service
- Allowing audits and inspections
3.4 Your obligations as controller
As the controller of consent data, you are obliged to:
- Inform visitors about the processing of their data (privacy policy)
- Ensure a legal basis for processing
- Respond to data subject requests (access, erasure, etc.)
- Report security breaches to the supervisory authority (where relevant)
4. What Data We Process on Behalf of the Customer
When a visitor interacts with the cookie widget on your website, we process the following data:
| Data | Description | Is it personal data? |
|---|---|---|
| visitorId | Anonymous randomly generated identifier | Pseudonymised. Not personal data on its own, but in combination with other data (e.g. IP address) it may constitute personal data within the meaning of GDPR. |
| Consent choices | Decisions for individual categories (necessary, analytics, marketing, preferences) | Yes (in combination with visitorId) |
| Timestamp | Date and time of consent grant/change | No |
| Country | Derived from IP using geolocation (IP is not stored) | No |
| User Agent | Browser and device type | No (general information) |
| UTM parameters | Marketing parameters from URL (if present) | No |
4.1 What we do NOT process
- Visitor IP addresses
- Visitor names or emails
- Third-party cookies
- Website content
- Visitor behavioural data on the website (beyond consent interactions)
5. Data Security
5.1 Technical measures
- Transit encryption: All communication is encrypted using HTTPS (TLS 1.3)
- Encryption at rest: Data is encrypted at the database level
- Data isolation: Individual customer data is strictly separated
- Automatic backups: Daily backups with 30-day retention
- DDoS protection: Cloudflare for attack prevention
5.2 Data location
Primary database: EU - Cloudflare D1
CDN and edge: EU - Cloudflare
Hosting: EU - Cloudflare Pages
All consent data is stored and processed exclusively within the European Union.
5.3 Access rights
- Only authorised employees/administrators have access to data
- All access is logged
- We apply the principle of least privilege
7. Sub-processors
We use the following sub-processors to provide the service. By registering, you consent to their involvement:
| Service | Provider | Purpose | Location | Safeguards |
|---|---|---|---|---|
| Cloudflare D1 | Cloudflare Inc. | Database, consent record storage | EU | DPA, SCC |
| Cloudflare | Cloudflare Inc. | CDN, geolocation, protection | EU | DPA, SCC |
| Cloudflare Pages | Cloudflare Inc. | Application hosting | EU | DPA, SCC |
7.1 Changes to sub-processors
We will inform you by email of any changes to the sub-processor list at least 14 days in advance. If you do not agree with a new sub-processor, you have the right to raise an objection within 14 days of notification. In the event of an unresolved objection, you have the right to terminate the agreement without penalty, effective as of the date the new sub-processor is due to begin processing.
7.2 Sub-processors outside the EU
The following services are based in the USA, but we do not process consent data through them directly:
- Stripe - for customer payments only (not consent data)
- Resend - for transactional emails to customers only (not consent data)
8. Incident Management
8.1 Security breach procedure
In the event of a personal data security breach (data breach):
- Detection and analysis - Identification of the scope and impact of the incident
- Customer notification - Within 48 hours of discovery
- Remedial measures - Immediate steps to prevent further leakage
- Documentation - Recording the incident for compliance purposes
8.2 What the notification contains
- Description of the nature of the breach
- Categories and approximate number of affected data subjects
- Likely consequences
- Measures taken or proposed
- Contact for further information
8.3 Your obligations
As the controller, you are obliged to:
- Report the breach to the supervisory authority (UOOU) within 72 hours, if the breach is likely to result in a risk to data subject rights
- Notify the affected data subjects if there is likely a high risk
9. Audit and Compliance
9.1 Right to audit
As the controller, you have the right to audit data processing. An audit may be carried out:
- Through a questionnaire that we will send upon request
- By reviewing certifications and security measures
- On-site by prior arrangement (at the controller's expense)
On-site audits are limited to a maximum of once per year by prior arrangement. The primary form of audit is completion of a security questionnaire.
9.2 Available documentation
Upon request, we will provide:
- Description of technical and organisational measures
- List of sub-processors with contacts
- Records of processing activities (Art. 30 GDPR)
- Results of security audits (in anonymised form)
9.3 Compliance certifications
SOC 2 Type II and ISO 27001 certifications are planned. Current security measures are described in section 5 and available for review upon request.
- SOC 2 Type II (planned)
- ISO 27001 (planned)
10. Contact for GDPR Queries
For any questions regarding GDPR, the data processing agreement, or personal data protection, please contact us:
We respond to queries within 5 working days.
10.1 Related documents
Version 1.0: This document takes effect on 2 February 2026.