Consentio
FuncionalidadesPreçosSobre nósBlogDocumentação
PT
EntrarComeçar grátis

GDPR Information for Customers

Effective from: 2 February 2026

Contents

1. Introduction

1.1 What is Consentio?

Consentio is a SaaS service for managing cookie consent (Consent Management Platform - CMP). It helps website operators ensure compliance with GDPR and the ePrivacy Directive through:

  • Customisable cookie banner for collecting consent
  • Automatic cookie scanning and categorisation
  • Consent record storage and management (proof of consent)
  • Google Consent Mode v2 integration
  • Consent analytics and reporting

1.2 Who is this document for

This document is intended for Consentio customers (website operators) who need to understand:

  • What role Consentio plays in personal data processing
  • What obligations arise from the data processing agreement
  • How their visitors' data is protected
  • What obligations they have towards their visitors

2. Consentio's Role in Data Processing

Key distinction: Consentio acts in two different roles depending on the type of data being processed.

2.1 Consentio as controller

For Consentio customer data (your account details, login credentials, billing data), we act as the data controller.

  • We determine the purposes and means of processing
  • We bear responsibility for processing in accordance with GDPR
  • Details can be found in our Privacy Policy

2.2 Consentio as processor

For consent data from your website visitors, we act as a data processor.

  • You (the customer) are the controller of this data
  • Consentio processes data only according to your instructions
  • The relationship is governed by the data processing agreement (DPA)
Data type Controller Processor
Customer account (email, password, billing details) Consentio -
Consent records from your website visitors You (the customer) Consentio

3. Data Processing Agreement (DPA)

3.1 Automatic conclusion

The Data Processing Agreement (DPA) is automatically concluded upon registration and acceptance of the Terms of Service. You do not need to sign any additional documents.

3.2 Subject of processing

Under the DPA, we process consent data from your website visitors for the purpose of:

  • Consent record storage and management
  • Providing proof of consent for compliance purposes
  • Displaying consent analytics and statistics
  • Google Consent Mode integration

3.3 Consentio's commitments as processor

As a processor, we commit to:

  • Processing data only according to the controller's documented instructions
  • Ensuring that persons authorised to process data are bound by confidentiality
  • Implementing all technical and organisational measures to secure data
  • Using sub-processors only with your consent
  • Assisting the controller in fulfilling their obligations (data subject rights, DPIA)
  • Deleting or returning all data upon termination of the service
  • Allowing audits and inspections

3.4 Your obligations as controller

As the controller of consent data, you are obliged to:

  • Inform visitors about the processing of their data (privacy policy)
  • Ensure a legal basis for processing
  • Respond to data subject requests (access, erasure, etc.)
  • Report security breaches to the supervisory authority (where relevant)

4. What Data We Process on Behalf of the Customer

When a visitor interacts with the cookie widget on your website, we process the following data:

Data Description Is it personal data?
visitorId Anonymous randomly generated identifier Pseudonymised. Not personal data on its own, but in combination with other data (e.g. IP address) it may constitute personal data within the meaning of GDPR.
Consent choices Decisions for individual categories (necessary, analytics, marketing, preferences) Yes (in combination with visitorId)
Timestamp Date and time of consent grant/change No
Country Derived from IP using geolocation (IP is not stored) No
User Agent Browser and device type No (general information)
UTM parameters Marketing parameters from URL (if present) No
We do not store IP addresses. For geolocation, we only use the derived country information, which is not personal data in itself.

4.1 What we do NOT process

  • Visitor IP addresses
  • Visitor names or emails
  • Third-party cookies
  • Website content
  • Visitor behavioural data on the website (beyond consent interactions)

5. Data Security

5.1 Technical measures

  • Transit encryption: All communication is encrypted using HTTPS (TLS 1.3)
  • Encryption at rest: Data is encrypted at the database level
  • Data isolation: Individual customer data is strictly separated
  • Automatic backups: Daily backups with 30-day retention
  • DDoS protection: Cloudflare for attack prevention

5.2 Data location

Primary database: EU - Cloudflare D1

CDN and edge: EU - Cloudflare

Hosting: EU - Cloudflare Pages

All consent data is stored and processed exclusively within the European Union.

5.3 Access rights

  • Only authorised employees/administrators have access to data
  • All access is logged
  • We apply the principle of least privilege

6. Rights of Customer Website Visitors

Your website visitors have rights under GDPR. As the controller, you are responsible for fulfilling them.

6.1 Consent withdrawal

Visitors can change their consent preferences at any time:

  • By clicking the "Cookie settings" button (if implemented)
  • Via the floating button
  • By clearing browser cookies (forces a new consent dialogue)

6.2 Right to erasure

If a visitor requests erasure of their consent data:

  1. The visitor contacts you (the controller) through your website
  2. You contact us at [email protected] with the visitorId identifier
  3. We will erase the record within 72 hours

Note: Without the visitorId, we cannot identify the record, as we do not store any other identifying data.

6.3 Right of access

A visitor may request access to their consent data. The procedure is the same as for erasure. We will provide a consent record export in JSON format.

6.4 Your obligations

As the controller, you should:

  • Inform visitors about consent data processing in your privacy policy
  • Provide contact information for exercising rights
  • Respond to requests within 30 days

7. Sub-processors

We use the following sub-processors to provide the service. By registering, you consent to their involvement:

Service Provider Purpose Location Safeguards
Cloudflare D1 Cloudflare Inc. Database, consent record storage EU DPA, SCC
Cloudflare Cloudflare Inc. CDN, geolocation, protection EU DPA, SCC
Cloudflare Pages Cloudflare Inc. Application hosting EU DPA, SCC

7.1 Changes to sub-processors

We will inform you by email of any changes to the sub-processor list at least 14 days in advance. If you do not agree with a new sub-processor, you have the right to raise an objection within 14 days of notification. In the event of an unresolved objection, you have the right to terminate the agreement without penalty, effective as of the date the new sub-processor is due to begin processing.

7.2 Sub-processors outside the EU

The following services are based in the USA, but we do not process consent data through them directly:

  • Stripe - for customer payments only (not consent data)
  • Resend - for transactional emails to customers only (not consent data)

8. Incident Management

8.1 Security breach procedure

In the event of a personal data security breach (data breach):

  1. Detection and analysis - Identification of the scope and impact of the incident
  2. Customer notification - Within 48 hours of discovery
  3. Remedial measures - Immediate steps to prevent further leakage
  4. Documentation - Recording the incident for compliance purposes

8.2 What the notification contains

  • Description of the nature of the breach
  • Categories and approximate number of affected data subjects
  • Likely consequences
  • Measures taken or proposed
  • Contact for further information

8.3 Your obligations

As the controller, you are obliged to:

  • Report the breach to the supervisory authority (UOOU) within 72 hours, if the breach is likely to result in a risk to data subject rights
  • Notify the affected data subjects if there is likely a high risk

9. Audit and Compliance

9.1 Right to audit

As the controller, you have the right to audit data processing. An audit may be carried out:

  • Through a questionnaire that we will send upon request
  • By reviewing certifications and security measures
  • On-site by prior arrangement (at the controller's expense)

On-site audits are limited to a maximum of once per year by prior arrangement. The primary form of audit is completion of a security questionnaire.

9.2 Available documentation

Upon request, we will provide:

  • Description of technical and organisational measures
  • List of sub-processors with contacts
  • Records of processing activities (Art. 30 GDPR)
  • Results of security audits (in anonymised form)

9.3 Compliance certifications

SOC 2 Type II and ISO 27001 certifications are planned. Current security measures are described in section 5 and available for review upon request.

  • SOC 2 Type II (planned)
  • ISO 27001 (planned)

10. Contact for GDPR Queries

For any questions regarding GDPR, the data processing agreement, or personal data protection, please contact us:

David Azarian

Email: [email protected]

Telephone: +420 774 147 594

We respond to queries within 5 working days.

10.1 Related documents

  • Terms of Service
  • Privacy Policy

Version 1.0: This document takes effect on 2 February 2026.

Consentio

Cookies sem stress. RGPD sem advogado.

VisaMastercardApple PayGoogle Pay

Produto

  • Funcionalidades
  • Preços
  • Documentação
  • Mapa do site

Empresa

  • Sobre nós
  • Blog
  • Dicionário
  • Contacto

Legal

  • Termos de Serviço
  • Política de Privacidade
  • RGPD
  • Solicite os seus dados

Contacto

  • [email protected]
  • +420 774 147 594
  • NIF: 17064619

© 2026 Consentio | By Kosmoweb.cz