ConsentX runs on AWS in the Mumbai region (ap-south-1), with intra-region processing by default, encryption in transit and at rest, and Cloudflare protection.
Last reviewed: 27 August 2026 by the ConsentX Security & Compliance Team
The ConsentX application and its consent data store run on Amazon Web Services in the Asia Pacific Mumbai region (ap-south-1), in India.
Primary processing of consent data remains intra-region in India. Where any onward transfer occurs, Standard Contractual Clauses with the UK Addendum apply.
Data is encrypted in transit with TLS between the browser, our edge and our application, and at rest using storage-layer encryption on AWS. Backups are encrypted too.
Our edge is protected by Cloudflare, including a web application firewall and DDoS mitigation, in front of the India-hosted application.
On certifications, we are transparent: ConsentX does not yet hold SOC 2 or ISO 27001, and we will not claim either until it is independently verified. Both are on our roadmap. See the ConsentX security practices and ConsentX Trust Center certifications pages.

India’s Digital Personal Data Protection Act governs how digital personal data about people in India is collected, stored and used. It is built around notice and consent rather than a blanket localisation mandate: the Act permits transfer outside India except to countries the government restricts, and the Rules can prescribe additional measures for certain data. In practice, many Indian organisations still prefer a consent management platform whose data storage stays in India, because it keeps the evidence trail inside one jurisdiction and simplifies what has to be explained to a regulator or an enterprise buyer. ConsentX is built for that preference: consent data in India by default, encryption in transit and at rest, a tamper-evident consent record, and a signed DPA with a DPDPA addendum. Your specific DPDPA compliance obligations depend on your organisation and processing activities, so confirm them with legal counsel.
The ConsentX application and its consent data store run on Amazon Web Services in the Asia Pacific Mumbai region, ap-south-1 — an India data centre region. A visitor’s browser reaches the banner over TLS through our Cloudflare edge, which puts a web application firewall and DDoS mitigation in front of the India-hosted application. The consent decision is then written to the data store in the same region, encrypted at rest using AWS storage-layer encryption. Primary processing of consent data remains intra-region in India by default; where any onward transfer to a subprocessor occurs, it is governed by Standard Contractual Clauses with the UK Addendum, and our subprocessor list is published so you can see who is involved. That is the whole path: browser, edge, India region, encrypted record.
We take regular backups of the consent data store, and those backups are encrypted at rest in the same way as the primary data. Our business continuity approach is designed to let us restore service and data following a disruption, and we keep the recovery procedures under review as the platform evolves. To be straight with you about the limits of what we publish: ConsentX does not currently advertise a separate named disaster recovery region or public RPO and RTO targets for this page, and we would rather say so than publish a number we have not committed to contractually. What we do state is the part that matters for residency — primary processing stays intra-region in India, and backups are encrypted. If your procurement or security review needs the underlying detail, ask us and we will answer it directly.
Consent records exist to be evidence, so they are retained for as long as you need them to demonstrate a valid consent basis, under the terms of your agreement with us. On termination or expiry, our Data Processing Agreement commits us to delete or return all personal data processed on your behalf — your choice — and to delete existing copies, unless applicable data protection law requires us to keep them. That deletion or return happens within a reasonable period after the services end, subject to the wind-down period set out in the DPA. Personal data still sitting in routine backups is deleted in line with our documented backup retention schedule, and is not used for anything other than continuity while it remains there. On written request, we will certify that we have done it.
Run consent on infrastructure in India with verifiable, audit-ready evidence.