Privacy policy
Version 1.0, last updated 9 September 2026.
Consentics is not yet a registered legal entity. The details below will be completed once incorporation is finished.
Who we are and how to contact us #
Consentics
company registration pending
registered address to be published on incorporation
Contact: hello@consentics.com
If you have a question about this policy or about your data, write to hello@consentics.com.
The two capacities we act in #
We act in two different capacities, depending on which part of the service you are dealing with, and this policy is split to match. In Part A, we are the controller: we decide why and how we process the data ourselves, for people who create an account with us, request our free cookie scan, join our launch list, contact us, or visit our own website. In Part B, we are the processor: we handle website visitor data on behalf of our customers, who are the controllers of their own visitors' data, and we act only on their instructions.
If you are a visitor to one of our customers' websites, Part B describes what happens to your data. If you are a Consentics customer or a visitor to consentics.com itself, Part A describes what happens to your data.
Part A: when we are the controller #
Data we collect when you create an account #
When you register an account, we collect your email address, your name, and the language you prefer to use. We keep a record of your account security activity, including the IP address used at your last login and your multi-factor authentication settings if you turn them on. Your login IP address is kept as recorded, without being shortened or masked.
We also keep a security log of sign-in attempts on your account, successful and failed, recording the IP address and browser identification string (user agent) the attempt came from. A failed attempt also records the email address that was entered.
If you invite a colleague to join your account, we record their email address and any message you include with the invitation, even before they have created an account themselves.
If your account belongs to an organisation, we keep the contact details, address, and tax information you provide for that organisation.
Free cookie scan requests #
If you request our free cookie scan, we ask for your email address so we can send you the report, and we ask whether you would also like to receive marketing email. We keep a record of the web address you asked us to scan and the results of that scan.
We do not store the IP address you make the request from directly. Instead, we store a one-way scrambled version of it, created using a method that lets us apply a daily limit on requests without being able to work back to your original IP address from the stored value alone.
The scan report is sent to you by email as a link. That link is not password-protected, so anyone who obtains the link can view the report. We keep scan requests and their results automatically deleted after 365 days.
Launch list and contact form #
If you join our launch list or submit our contact form, we keep the email address and any message you provide, so that we can respond to you or keep you updated as we said we would.
Marketing messages we send include an unsubscribe link that turns off further marketing email for that address. The contact form is for a one-off message only and is not a marketing opt-in. If you want us to delete your details, or you no longer have a message with an unsubscribe link, email us at hello@consentics.com and we will act on your request.
Visiting consentics.com #
Consentics.com runs its own product on itself. This means that when you visit our website, our own tracking tag collects data about your visit in the same way it does on our customers' sites, and this section describes what that means for you as a visitor to our own site.
The tag records the page you viewed, including the full web address and any information included in it, the page that referred you here, and general information about your device and browser. If you consent to tracking, we also set a cookie that lets us recognise you as a returning visitor. If you do not consent, we still record that a page was viewed, but without any cookie or identifier that would let us connect that visit to any other visit you make. See "What changes when a visitor declines" below for the full detail, which applies here in exactly the same way it applies on a customer's site.
Regardless of whether the tag is active, our server keeps a short-lived cache of IP addresses making requests to our systems, for up to one hour, solely to detect and prevent abuse such as excessive automated requests. This cache expires automatically and is not a database record.
Lawful bases #
The lawful basis for each activity described in Part A above is:
- Contract: processing your account and organisation details, and the free cookie scan you request, is necessary to provide the service you asked us for.
- Legitimate interests: keeping a record of login activity, applying rate limits, and keeping server logs of rejected requests, is necessary for our legitimate interest in keeping our service secure and available.
- Consent: we only send marketing email, such as launch updates, if you opt in specifically. You can withdraw that consent at any time using the unsubscribe link in any marketing message we send you.
- Consent: our own tracking tag, when it runs on consentics.com, sets a cookie that identifies you as a returning visitor only if you consent to it on our cookie banner.
Part B: when we are the processor for our customers #
What our tag collects #
When you visit a website that uses our service, our tracking tag may collect the page you viewed, including the full web address and any information included in it, the page that referred you there, general information about your device and browser, and, if you have clicked a link to another website or downloaded a file, the destination and the text of the link you clicked. If the site includes a search feature, we may also record the term you searched for.
Some of this happens automatically as soon as a page loads, before you have made any consent decision. What differs by your consent decision is described in the next section.
We process this data on behalf of, and only on the documented instructions of, the website you are visiting. That website is the controller of your data in this relationship, and its own privacy policy should tell you more about how it uses the results. We do not currently publish a separate Data Processing Agreement for this relationship; the processor commitments described throughout this policy apply to how we handle this data.
What changes when a visitor declines #
If you decline, we do not set or read any cookie that identifies you across visits, and we do not store any persistent identifier for you. We still record the page view itself, without a persistent identifier, so the site owner can count traffic.
If you consent, the only differences are that we set a cookie so we can recognise you as a returning visitor within the cookie's lifetime, and any consent-gated third-party tools the website owner has added are switched on.
IP addresses #
We do not store your full IP address in our analytics records. Before anything is saved, the last part of the address is removed, so what remains cannot be traced back to a specific device or connection. This is a one-way process: there is no way to reconstruct your original IP address from the stored value.
Your IP address is, however, held briefly in two other places. It sits in a short-lived cache, for up to one hour, used to detect and prevent abuse of our systems. It may also appear in a server log entry if a request from your device is rejected by our system, for example for exceeding a rate limit. We do not claim that we never store an IP address anywhere: the accurate statement is that it is never stored in our analytics data, and is held only transiently elsewhere for security purposes.
Retention #
We keep the different kinds of data described in this policy for different lengths of time, set out below.
| What | How long |
|---|---|
| Individual page-view and event records | 90 days |
| Whether your consent decision is currently in effect | 365 days |
| The record that a consent decision was made (kept as evidence even after it stops being in effect) | 2555 days |
| The analytics session cookie, set only after you consent to tracking | 30 minutes |
| The account sign-in session cookie, set when you sign in | 14 days |
| The technical cookie our website uses to protect forms from tampering | 364 days |
| Cookie scan requests and results | automatically deleted after 365 days |
Aggregated traffic statistics, individual visit-level detail records, launch list and contact form entries, and email verification records are each kept until you ask us to delete them: none of these currently has an automatic deletion job.
Who we share data with #
We use a small number of other companies to help us run our service.
- DigitalOcean (compute and Managed PostgreSQL database; United Kingdom)
- Let's Encrypt (TLS certificates; sees domain names only, no personal data)
- MaxMind (a static database file download for coarse geolocation; sees no visitor data)
- Brevo delivers the emails we send, such as account verification messages and cookie scan reports.
Where data is stored #
Our data is stored in United Kingdom.
Security #
We protect data in transit using industry-standard encryption. Our database is professionally managed, with each customer's data logically separated from every other customer's. Account passwords must meet a minimum strength requirement, and you can turn on multi-factor authentication for extra protection. We do not hold any security certification, and we make no claim to one.
Your rights #
If you have consented to tracking on a website that uses our service, you can withdraw or change that consent at any time using the cookie preferences option on that site, and it takes effect immediately.
For any other request, including asking what data we hold about you, asking us to correct it, or asking us to delete it, email us at hello@consentics.com. We do not currently offer an automated, self-service way to export or delete your data: every request like this is handled manually by us, and we aim to respond within one month.
If you declined consent on a website using our service, we generally hold no data that can be linked back to you specifically, since no persistent identifier was ever created for you. This means we are often unable to locate any record in response to a request from a visitor who declined, which is a consequence of how little we collect about you, not a refusal to help.
Automated decisions and children's data #
We do not use your data to make any automated decision that has a legal or similarly significant effect on you. Our service is intended for use by businesses and their staff, not by children, and we do not knowingly collect data from children.
Cookies #
Full detail on the cookies we and our tag use, including a table of every cookie, its purpose, and how long it lasts, is in our cookie policy.
Complaints #
If you are unhappy with how we have handled your data, please contact us first at hello@consentics.com so we can try to put it right. You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator. ICO registration to be published once obtained
Changes to this policy #
We may update this policy from time to time. The version number and date at the top of this page tell you when it was last changed.