Privacy policy

How Conzent handles your data. Plain language, no legalese.

Privacy policy

Last updated: 31 August 2026

This policy explains what personal data Conzent ApS collects, why, who we share it with, how long we keep it, and what rights you have. We sell privacy compliance software, so we have tried to hold this page to the standard we would want from a supplier: specific, complete, and honest about the things most policies leave out.

Who we are

  • Company: Conzent ApS
  • Company registration (CVR): 45040631
  • Address: Rådhusstræde 15, 1466 Copenhagen K, Denmark
  • Privacy contact: privacy@getconzent.com
  • Security reports: security@getconzent.com

We have not appointed a data protection officer, as we are not required to under Article 37 of the GDPR. Privacy questions go to the address above and are answered by the people who build the product.

The two different roles we have

This distinction decides which rules apply, so it comes first.

  • We are the controller for data about visitors to this website, and for the account, billing and support data of our own customers. That processing is described below and is our responsibility.
  • We are a processor for the consent records generated on our customers' websites. There, our customer is the controller and decides what happens. If you are a visitor to a website that uses Conzent and you want to exercise your rights over those records, contact that website's owner. We will help them respond, but we cannot act on their data without their instruction.

Our customers can request a data processing agreement covering that second role at any time by writing to privacy@getconzent.com.

What we collect as controller, and why

If you visit this website

We use our own consent management platform on our own site. Before you make a choice in the banner, we set no analytics or advertising cookies and no persistent identifier.

If you consent, we use Google Tag Manager and a first-party analytics identifier stored in a cookie named conzent_tracking, which lets us understand how people move through the site and which pages lead to signups. That identifier is only created after you consent to the relevant category, and it is deleted if you later withdraw consent. Strictly necessary cookies used to remember your consent choice itself are set regardless, because without them we could not honour your choice on the next page.

  • What: pages viewed, referring page, approximate country, and a randomly generated identifier that is not linked to your name or email address.
  • Legal basis: your consent (Article 6(1)(a)), which you can withdraw at any time using the consent settings link on this site.

If you have a Conzent account

  • What: your name, email address, company name, hashed password, and a record of significant actions taken in your account.
  • Why: to provide the service, secure the account, and support you.
  • Legal basis: performance of our contract with you (Article 6(1)(b)), and our legitimate interest in keeping the platform secure (Article 6(1)(f)).

If you pay us

  • What: billing details and invoice records. Card details are handled by our payment provider and are never stored on our servers.
  • Legal basis: performance of our contract (Article 6(1)(b)) and our legal obligation to keep accounting records (Article 6(1)(c)).

If you contact support

  • What: the content of your message and whatever you choose to include in it, including chat conversations with our AI support agent.
  • Legal basis: performance of our contract, or our legitimate interest in answering enquiries from people who are not yet customers.

What we process as processor, for our customers

When a visitor interacts with a Conzent banner on a customer's website, we record evidence of that consent decision on the customer's behalf. Each record contains the consent choices per category, timestamps, the country, the language shown, the domain, and where applicable the IAB TCF string and Google Consent Mode state.

These records are pseudonymised, not anonymised, and the difference matters. The visitor's IP address is replaced by a keyed hash at the moment the record is written, and the raw address is never stored. That is enough to correlate records as proof of consent, and not enough to read an address back out. Pseudonymised data is still personal data under the GDPR, and we treat it as such. We do not collect a visitor's name, email address or any account identifier through the banner.

Who we share data with

We do not sell personal data, we do not share it for others' marketing, and we do not use it to train machine-learning models. We do use a small number of service providers, and these are the categories and the main providers in each:

  • Hosting and infrastructure: Hetzner Online GmbH, with servers in Germany and Finland.
  • Content delivery, DNS and network protection: Cloudflare, Inc.
  • Payment processing: our payment provider handles card data directly; we receive only the billing record.
  • Email delivery: a transactional email provider used to send service messages such as password resets and reports.
  • Support chat: heyfreyja, which powers the AI support agent on this website.
  • Analytics and tag management: Google, through Google Tag Manager, and only after you consent.

We may also disclose data where we are legally required to do so. Customers can request our current list of sub-processors, including any changes, by writing to privacy@getconzent.com.

Where your data is stored

Platform data is hosted in the European Union. Where a service provider is based outside the European Economic Area, or may access data from outside it, we rely on a valid transfer mechanism under Chapter V of the GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision.

How long we keep it

  • Account data: for as long as your account is active, then deleted within 30 days of closure.
  • Consent records: for a period the customer controls, which is 1095 days (three years) by default, after which they are purged automatically. Deleting a site permanently deletes its consent records.
  • Website analytics: aggregated after 90 days, so individual records no longer exist.
  • Invoices and accounting records: five years from the end of the financial year, as Danish bookkeeping law requires.
  • Support correspondence: up to 24 months, so we can pick up a thread you started earlier.

How we protect it

Traffic is encrypted in transit with TLS and backups are encrypted at rest. Passwords are stored using the bcrypt hashing function and never in readable form. Access is scoped per account and enforced on every request, and access to production systems is limited to authorised personnel. Consent records are written as append-only entries, so the evidence trail cannot be quietly altered. Database backups run nightly to off-site storage with monitoring that alerts us if a backup does not happen.

Because the core of our platform is published as open source under the Apache 2.0 licence, you do not have to take our word for how any of this works. You can read the code that processes the data.

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you, and receive a copy;
  • have inaccurate data corrected;
  • have your data deleted in the circumstances the law provides for;
  • restrict or object to processing, including processing based on legitimate interests;
  • receive your data in a portable, machine-readable format;
  • withdraw consent at any time, without affecting processing that already happened while consent was valid; and
  • lodge a complaint with a supervisory authority. In Denmark that is Datatilsynet, datatilsynet.dk.

Write to privacy@getconzent.com to exercise any of these. We will respond within one month, and will tell you if we need longer because the request is complex.

One honest limitation. Because consent records are pseudonymised by design, we usually cannot locate an individual visitor's records from a name, an email address or an IP address, since we never stored anything that links to those. We will help as far as it is technically possible. That limitation is a consequence of collecting as little as possible, which is the outcome the law asks for.

Automated decision-making

We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not profile you for that purpose.

Changes to this policy

We update this policy when our practices change. Material changes are notified to registered users by email, and the date at the top always reflects the current version.

Questions

Write to privacy@getconzent.com. If you are a customer and need a data processing agreement, subprocessor list or help answering a request from your own regulator, ask and we will send it.