Privacy policy
How consented.eu handles data — once for account holders and once for visitors to websites that use this CMP.
This translation is provided for convenience only; the German version is authoritative.
Details will be added.
Data processed: Email address, name, optionally the organisation name, an Argon2id hash of your password, the time of your last sign-in, and for each session the device class and an HMAC hash of your IP address.
Purpose and legal basis: Provision of the service (Art. 6 Abs. 1 lit. b DSGVO) and protection against abusive sign-ins (Art. 6 Abs. 1 lit. f DSGVO).
Retention period: Until the account is deleted. Sessions and rate-limit counters expire automatically.
Cookies:
A single technically necessary session cookie (ce_session, HttpOnly, SameSite=Lax). No tracking, no analytics cookies in the dashboard.
Here the website operator is the controller; we act as a processor under Art. 28 DSGVO.
What is stored: your choice per category and service, the time, the configuration version, the language, the domain, a coarse device type ("Firefox/Windows"), a SHA-256 hash of the page URL and an HMAC of your IP address with a rotating key.
What is not stored: your IP address in clear text, your full user agent, your location and any kind of cross-site identifier. There is no profiling.
Purpose: Proof of consent under Art. 7 Abs. 1 DSGVO. Without this record the website operator could not demonstrate that you gave consent.
Retention period: 36 months by default, shorter if configured that way. After that an automatic job deletes the record.
Access and deletion: On the lookup page you can use your consent ID at any time to see what is stored and have it deleted — without an account and without telling us who you are.
This instance runs on our own infrastructure in the European Union. There is no transfer to third countries.
No third-party services are embedded: no external fonts, no CDN, no analytics tools. The website uses only its own CMP.
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 DSGVO). You can withdraw a consent you have given at any time with effect for the future.
You also have the right to lodge a complaint with a data protection supervisory authority.