Attesso
Terms of servicePrivacy policyData processing
( Data processing agreement )

How we handle your visitors’ data

When your visitors use the consent banner, that data is yours. We only ever act on your instructions. This is the agreement that says so, in the form your own clients and auditors will ask for.

Last updated 29 July 2026
This agreement applies automatically to every Attesso account. You do not need to sign or request anything; if your legal team needs a countersigned copy on letterhead, email [email protected] and we will send one.
01

Who is who

You are the controller: it is your website, your visitors, and your decision about what to collect. We are the processor: we handle that data only to provide the service, and only as you instruct. This agreement forms part of our terms of service.

02

What we process, and why

Item
Detail
Subject matter
Recording and honouring the consent choices of visitors to your sites
Duration
For as long as your account is open, plus the deletion window in section 8
Nature and purpose
Storing consent records, serving your banner, and producing your reports
Types of data
Consent choices, banner and policy version, timestamp, broad region, a hashed user-agent string, and a record signature
Categories of people
Visitors to the websites you add to your account
We do not receive names, email addresses, IP addresses, or advertising identifiers from your visitors. A consent record is deliberately built so that neither we nor anyone who obtains it can identify an individual.
03

Our obligations

  • We process this data only on your documented instructions, and using the service is the instruction. If a law forces us to do otherwise, we will tell you first unless that law forbids it.
  • Everyone with access is bound by confidentiality.
  • We keep appropriate technical and organisational security measures (section 5).
  • We help you respond to requests from your visitors, and with your data protection impact assessments and regulator consultations, so far as is reasonable.
  • We tell you without undue delay if we become aware of a personal data breach affecting your data, with what we know and what we are doing.
  • We will not sell this data, and we will not use it for our own purposes, including training any model.
04

Your obligations

You are responsible for having a lawful basis for what you collect, for what your banner says, for the categories you configure, and for your own privacy policy. You confirm your instructions to us are lawful.

05

Security

  • Data is encrypted in transit and at rest.
  • Each customer’s data is isolated from every other customer’s at the storage layer, not merely by application logic.
  • Access is limited to staff who need it, and is logged.
  • Passwords are stored hashed and are not recoverable by us.
  • Backups are taken regularly and their restoration is tested.
06

Sub-processors

You give us general authorisation to use sub-processors for hosting, payments, email delivery, and error monitoring. Each is bound by terms no less protective than these. The current list, by category, is in the privacy policy; for the named list, email [email protected].

We will give you at least 30 days’ notice by email before adding or replacing one. If you reasonably object on data protection grounds, tell us within those 30 days and we will work with you; if we cannot resolve it, you may terminate the affected service and we will refund the unused portion.

07

Where data goes

Consent records are stored in the EU, Frankfurt region. Where any transfer outside the EEA or the UK is necessary, it is covered by the European Commission’s Standard Contractual Clauses, the UK Addendum where applicable, or another approved mechanism. Those clauses are incorporated into this agreement by reference and take precedence if they conflict with anything here.

08

Deletion and return

You can export or delete your consent records at any time from the dashboard. When your account closes, we delete your data within 30 days, except where we are legally required to keep something (billing records, for instance). Backups age out on their own cycle, within 90 days.

Consent records are otherwise retained for 24 months by default, which is what most regulators expect for demonstrating consent. You can shorten that in your workspace settings.

09

Audits

On reasonable notice, and no more than once a year unless a regulator requires otherwise, we will answer a security questionnaire and provide the documentation we hold, so you can verify our compliance with this agreement. We will treat a regulator’s request as taking precedence over that limit.

10

Liability and precedence

Liability under this agreement is subject to the limits in our terms of service. If this agreement conflicts with those terms, this agreement wins for anything concerning the processing of your visitors’ data.

11

Contact

[email protected] for sub-processor lists, signed copies, questionnaires, and breach notifications.

Questions about any of this? [email protected]