Data processing agreement
Anyone using a CMP processes personal data of their visitors through us. That makes us a processor under Art. 28 DSGVO — and a data processing agreement is mandatory, not an extra.
This translation is provided for convenience only; the German version is authoritative.
LW IT Solutions Company Lukas Wójcik
LW IT Solutions Company Lukas Wójcik, al. Tadeusza Kościuszki, nr 80/82, lok. 301, 90-437 Łódź, POLAND
The controller within the meaning of this agreement is the respective website operator who uses consented.eu on their website.
Nature and purpose: Collection, storage and provision of the consent decisions made by the visitors of the controller, for the purpose of demonstrating consent under Art. 7 Abs. 1 DSGVO.
Categories of data subjects: Visitors to the websites of the controller.
Categories of data: Consent decision per category and service, timestamp, configuration version, language, domain, device family, hashed page URL, HMAC-pseudonymised IP address.
| Measure | Implementation |
|---|---|
| Pseudonymisation | IP addresses only as HMAC-SHA-256 with a rotating pepper; page URLs only as a SHA-256 hash |
| Encryption in transit | TLS enforced, HSTS active, HTTP redirects to HTTPS |
| Access control | Role model with four levels, every permission change in the audit log |
| Password security | Argon2id with pepper, minimum length 12 characters, progressive lockout |
| Input control | Append-only history: changes to a consent overwrite nothing |
| Separation control | Tenant separation by organisation and Property on every query |
| Resilience | Rate limiting on sign-in, registration, password reset and the consent endpoint |
| Deletion | Automatic expiry after the configured period, 36 months by default; immediate deletion via the data subject interface |
This instance runs on our own infrastructure without sub-processors. No data is transferred to third countries. Should that change, it will be documented here in advance.