Last updated 1 June 2026
Draft, pending counsel review. This document is a working draft and does not yet constitute final legal terms. It may change before publication.
This Privacy Policy explains how ConsentX collects, uses, discloses and protects personal data through this marketing website, and describes the privacy rights available to you under the laws that apply where you live. Please read it carefully. If you do not understand any part of it, contact our privacy team and we will be glad to help.
ConsentX is a consent and preference management platform. This Privacy Policy applies to the ConsentX marketing website at consentx.io and its subpages (the “Website”). For the personal data described in this policy, ConsentX acts as the data controller, meaning we decide why and how that personal data is processed.
This policy does not cover personal data that our customers process through the ConsentX product at app.consentx.io. In the product, our customer is the controller and ConsentX acts as a processor (or service provider) on the customer’s documented instructions. Our processing of product data is governed by our customer agreement and our Data Processing Addendum. If you are an end user of a website that uses ConsentX and you want to exercise rights over data collected on that website, please contact the operator of that website, who is the controller.
Where we are required to designate a representative in the European Economic Area under Article 27 of the EU GDPR, the details will be published here.
You have the right to lodge a complaint with the Information Commissioner’s Office, the UK supervisory authority for data protection, as set out in section 10.
Information Commissioner’s OfficeThe following terms are used throughout this policy:
References in this policy to the following data protection laws mean:
We aim to collect as little personal data as possible and only what we need for the purposes described in this policy. Depending on how you interact with the Website, we may collect the following categories of personal data.
Website visitors. When you browse the Website we may collect:
Leads, demo requests and enquiries. When you request a demo, contact us, sign up for updates or otherwise reach out, we collect the details you provide, which may include:
Account and billing data. If you create an account or purchase a paid plan through us, we (or our payment processor) collect account credentials, contact details, billing contact, company details and transaction records. We do not store full payment card numbers; these are handled by our payment processor.
The paid plans that produce this billing data, and the Fees charged for them, are:
| Plan | Billed monthly | Billed annually | Annual total |
|---|---|---|---|
| Free | USD 0 | USD 0 | USD 0 |
| Pro | USD 49 / month | USD 39 / month | USD 468 / year |
| Business | USD 199 / month | USD 165 / month | USD 1,980 / year |
| Enterprise | Custom pricing, quoted in an order form or written agreement. | ||
Fees are shown in US dollars and exclude taxes; the annual rate is the per-month equivalent of paying for twelve months in advance. Current Fees and plan entitlements are on our pricing page, and billing terms are set out in our Terms of Service.
Support data. When you contact support, we collect the messages, attachments and contact details you share, along with records of our correspondence so we can help you and keep accurate records.
Cookie and analytics data. We use privacy-friendly analytics to understand aggregate traffic and improve the Website. We also run the ConsentX consent banner on this Website, and when you make a cookie choice we keep a record of that choice so we can honour it and so we have evidence of consent. See section 5 and our Cookie Policy for details.
We do not intentionally collect special categories of personal data (such as health, biometric or political data) through the Website, and we ask that you do not send us such information.
We process personal data for the purposes set out below. Where the GDPR or UK GDPR applies, we rely on the legal basis stated for each purpose.
Where we rely on legitimate interests, we balance those interests against your rights and freedoms, and you can object to that processing as described in section 9. We do not sell your personal data.
We use cookies and similar technologies to operate the Website, remember your preferences and understand aggregate usage. Strictly necessary cookies are used to provide core functionality and do not require consent. Non-essential cookies, including analytics, are only set with your consent, which you give or refuse through the consent banner and can change at any time. For a full description of the cookies we use, their purposes and how to manage your choices, please see our Cookie Policy.
We do not sell personal information and we do not share it with third parties for their own marketing. We disclose personal data only in the following circumstances:
We operate globally, so your personal data may be processed in countries other than your own. The ConsentX product is hosted on Amazon Web Services in the Asia Pacific (Mumbai) region, ap-south-1, in India. This marketing Website is hosted on Vercel, and we use Cloudflare for content delivery, domain name services and web application firewall protection. These providers may process data in other regions.
Where we transfer personal data outside the European Economic Area or the United Kingdom, we put in place appropriate safeguards, which include the European Commission Standard Contractual Clauses together with the UK International Data Transfer Addendum, and reliance on the EU-US Data Privacy Framework where the recipient is certified under it. You can request more information about the safeguards we use by contacting us at privacy@consentx.io.
We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting or reporting requirements. Our typical retention periods by category are:
When personal data is no longer needed, we securely delete or anonymise it.
We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse or alteration. These measures include access controls, encryption in transit, network protection and regular review of our practices. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. For more information, please see our Security page.
The rights available to you depend on the laws that apply where you live. We honour the rights described below and will not discriminate against you for exercising them.
European Economic Area and United Kingdom (GDPR and UK GDPR). If you are in the EEA or the UK, you have the right to:
California (CCPA and CPRA). If you are a California resident, you have the right to:
We do not sell or share personal information as those terms are defined under California law. We honour the Global Privacy Control (GPC) signal as a valid opt-out of sale and sharing.
India (Digital Personal Data Protection Act). If you are in India, you have the right to:
Brazil (LGPD) and other jurisdictions. If you are protected by Brazil’s Lei Geral de Protecao de Dados or by another comprehensive privacy law, you may have rights similar to those described above, such as confirmation of processing, access, correction, anonymisation or deletion, portability and information about sharing. We will honour the rights granted to you under the privacy law that applies in your jurisdiction. If you are unsure which rights apply to you, contact us and we will help.
To exercise any of the rights described above, email us at privacy@consentx.io. To protect your privacy, we may need to verify your identity before acting on your request, and we may ask for additional information for that purpose. If an authorized agent submits a request on your behalf, we may ask for proof of authorisation.
We will respond within the time required by applicable law. Under the GDPR and UK GDPR we aim to respond within 30 days, and under California law within 45 days, with extensions where permitted. We provide our responses free of charge, except where the law allows a reasonable fee for excessive or repetitive requests.
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing, including profiling. If this changes, we will update this policy and provide the information and safeguards required by law.
Our Service is not directed to individuals under 18, and we do not knowingly collect personal data from anyone under 18 without verifiable parental or guardian consent, as required under India's DPDPA and, where applicable, the GDPR/UK GDPR. We do not profile, track, or advertise to individuals under 18. If you believe a child has provided us data without consent, contact privacy@consentx.io for prompt deletion.
Where required under Article 27 of the GDPR and the UK GDPR, we have appointed IntelligenceX, a compliance representation firm (intelligencex.org), as our representative in the European Union and the United Kingdom. You can contact our representative on matters relating to the processing of your personal data. The registered address of the representative is available on request, and you can reach us at privacy@consentx.io to be put in contact.
You can contact our privacy team about any matter relating to this policy or your personal data at privacy@consentx.io. For legal matters, contact legal@consentx.io, and for security matters, contact dpo@consentx.io. Where a Data Protection Officer is appointed, their contact details will be published here and you can reach them through our privacy address.
We may update this Privacy Policy from time to time to reflect changes in our practices, our services or the law. When we make material changes, we will update the date at the top of this page and, where appropriate, provide additional notice. We encourage you to review this policy periodically.
If you have a concern about how we handle your personal data, please contact us first at privacy@consentx.io so we can try to resolve it. You also have the right to lodge a complaint with your local supervisory authority or Data Protection Authority. We would, however, appreciate the chance to address your concerns before you approach a regulator.