How we handle your visitors’ data
When your visitors use the consent banner, that data is yours. We only ever act on your instructions. This is the agreement that says so, in the form your own clients and auditors will ask for.
Who is who
You are the controller: it is your website, your visitors, and your decision about what to collect. We are the processor: we handle that data only to provide the service, and only as you instruct. This agreement forms part of our terms of service.
What we process, and why
Our obligations
- We process this data only on your documented instructions, and using the service is the instruction. If a law forces us to do otherwise, we will tell you first unless that law forbids it.
- Everyone with access is bound by confidentiality.
- We keep appropriate technical and organisational security measures (section 5).
- We help you respond to requests from your visitors, and with your data protection impact assessments and regulator consultations, so far as is reasonable.
- We tell you without undue delay if we become aware of a personal data breach affecting your data, with what we know and what we are doing.
- We will not sell this data, and we will not use it for our own purposes, including training any model.
Your obligations
You are responsible for having a lawful basis for what you collect, for what your banner says, for the categories you configure, and for your own privacy policy. You confirm your instructions to us are lawful.
Security
- Data is encrypted in transit and at rest.
- Each customer’s data is isolated from every other customer’s at the storage layer, not merely by application logic.
- Access is limited to staff who need it, and is logged.
- Passwords are stored hashed and are not recoverable by us.
- Backups are taken regularly and their restoration is tested.
Sub-processors
You give us general authorisation to use sub-processors for hosting, payments, email delivery, and error monitoring. Each is bound by terms no less protective than these. The current list, by category, is in the privacy policy; for the named list, email [email protected].
We will give you at least 30 days’ notice by email before adding or replacing one. If you reasonably object on data protection grounds, tell us within those 30 days and we will work with you; if we cannot resolve it, you may terminate the affected service and we will refund the unused portion.
Where data goes
Consent records are stored in the EU, Frankfurt region. Where any transfer outside the EEA or the UK is necessary, it is covered by the European Commission’s Standard Contractual Clauses, the UK Addendum where applicable, or another approved mechanism. Those clauses are incorporated into this agreement by reference and take precedence if they conflict with anything here.
Deletion and return
You can export or delete your consent records at any time from the dashboard. When your account closes, we delete your data within 30 days, except where we are legally required to keep something (billing records, for instance). Backups age out on their own cycle, within 90 days.
Consent records are otherwise retained for 24 months by default, which is what most regulators expect for demonstrating consent. You can shorten that in your workspace settings.
Audits
On reasonable notice, and no more than once a year unless a regulator requires otherwise, we will answer a security questionnaire and provide the documentation we hold, so you can verify our compliance with this agreement. We will treat a regulator’s request as taking precedence over that limit.
Liability and precedence
Liability under this agreement is subject to the limits in our terms of service. If this agreement conflicts with those terms, this agreement wins for anything concerning the processing of your visitors’ data.
Contact
[email protected] for sub-processor lists, signed copies, questionnaires, and breach notifications.