What we hold, and why
Attesso exists to help people collect consent honestly, so it would be absurd for us to be vague about our own data. This says exactly what we keep, why we keep it, and when it goes.
Two different sets of people
It matters which one you are, because our role is different for each.
- Customers: you, with an Attesso account. We decide how your account data is handled, so we are the controller of it, and this policy covers it.
- Your visitors: people who see a consent banner on your website. That data is yours; you decide what happens to it and we only process it on your instructions. Your visitors should look at your privacy policy, not ours. The terms of that arrangement are in our data processing agreement.
What we collect from customers
Payment card numbers never reach us. Our payment provider handles the card and tells us only whether the payment worked and what the last four digits are.
What a consent record actually contains
This is the part people assume is invasive, so here is the whole of it:
- Which categories the visitor accepted or rejected, and whether they accepted all, rejected all, or chose.
- Which version of your banner and policy they were shown.
- A timestamp, and the broad region the request came from.
- A one-way hash of the browser’s user-agent string, so a record cannot be quietly swapped for another.
- A signature over the record, so you can show it has not been altered since.
What the scanner does
When a site is scanned we load its pages the way a browser would, and note the third-party hosts and cookies that appear. We keep the resulting report so you can compare scans over time. The scanner identifies itself honestly as AttessoScanner/1.0 and obeys reasonable rate limits.
A scan run from our home page before anyone signs up is anonymous: we keep it for 30 days so the link you were given keeps working, then delete it. If you create an account and claim that scan, it becomes part of your account and follows the schedule above instead.
Our own website
We hold ourselves to what we sell. Attesso’s marketing pages set no analytics or advertising cookies before you agree, and if you say no, none are set at all. The one cookie we always set records that choice, so we can honour it.
Who else sees it
We use a small number of service providers, each under contract and each limited to what they need:
Beyond that: nobody. We do not sell or rent personal data, and we do not share it for anyone else’s advertising. We will disclose data if the law genuinely requires it, and we will tell you unless we are forbidden from doing so. If our business is ever sold, your data moves with it under this same policy, and we will tell you first.
Where it lives
Customer accounts and consent records are stored in the EU, Frankfurt region. Where a provider needs to move data outside the EEA or the UK, that transfer is covered by Standard Contractual Clauses or an equivalent approved mechanism.
Keeping it safe
Access is limited to the people who need it, everything travels encrypted, and one customer’s data is isolated from another’s at the storage layer rather than only in the application. Passwords are stored hashed and cannot be read by us or recovered, only reset.
Your rights
Depending on where you live you can ask for a copy of your data, correct it, delete it, restrict or object to how we use it, or take it elsewhere in a portable format. Most of this you can do yourself in the dashboard immediately; for anything else, email [email protected] and we will respond within 30 days.
We do not need your consent to run your account (we need the data to provide the service you asked for), so there is no consent to withdraw for that. If you are in the EEA or UK and you think we have got something wrong, you can complain to your local data protection authority, though we would rather you told us first.
If you are a visitor to a site that uses Attesso and you want your consent record removed, contact that site’s owner. They control it; we act on their instruction.
Children
Attesso is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, tell us and we will delete it.
Changes
If we change something that matters we will email account owners before it takes effect and update the date at the top of this page.
Contact
[email protected] for any privacy question, including data requests.