Legal

Data Processing Addendum

The processor terms that attach to every subscription. It sets out what we process, on whose instructions, with which subprocessors, and what happens when you ask for it back. Schedule 2 names every third party in the path.

Effective
31 July 2026
Version
1.0
Incorporated into
The Terms of Service
Data residency
United States only

1 Scope and roles

This Addendum forms part of the Terms of Service between Efferent Media LLC d/b/a Consential ("Processor", "we") and the Customer ("Controller", "you"), and applies whenever we process personal data on your behalf.

You are the controller (or, under California law, the business). We are the processor (or service provider). You determine the purposes; we act only on your documented instructions, of which the Terms and your configuration of the Service are the primary ones.

Where protected health information is involved, the Business Associate Agreement governs and prevails over this Addendum to the extent of any conflict.

2 Definitions

"Personal data", "processing", "controller", "processor", "sale", "share", "service provider", "consumer" and "deidentified" have the meanings given in the applicable US state privacy statutes, including the California Consumer Privacy Act as amended, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Virginia Consumer Data Protection Act, the Washington My Health My Data Act, and their successors. Customer Personal Data means personal data we process on your behalf under the Terms, described in Schedule 1.

3 What we commit to

We will:

  1. process Customer Personal Data only on your documented instructions, and tell you if we believe an instruction violates applicable law;
  2. not sell it and not share it for cross-context behavioural advertising;
  3. not retain, use, or disclose it for any purpose other than performing the Service, including not combining it with personal data received from anyone else, except as permitted by statute;
  4. not use it to train machine-learning models;
  5. bind every person we authorise to access it to confidentiality;
  6. maintain the measures in Schedule 3; and
  7. give you the information reasonably necessary to demonstrate our compliance with this Addendum.

We certify that we understand these restrictions and will comply with them.

4 What you commit to

You warrant that you have the authority and lawful basis to instruct the processing described in Schedule 1, that your own privacy notice discloses it, and that your configuration of the Service reflects what you actually intend to be held and released.

5 Subprocessors

You give general authorisation for the subprocessors listed in Schedule 2. We remain fully liable to you for their performance.

We will give you at least 30 days' written notice before adding or replacing a subprocessor that will process Customer Personal Data. If you have a reasonable, documented objection based on data protection grounds, tell us within that window and we will use reasonable efforts to make the Service available without the change; if we cannot, you may terminate the affected part of the subscription and receive a pro-rata refund of the unused balance.

Every subprocessor that processes Customer Personal Data is bound by written terms no less protective than this Addendum.

6 Security

We maintain the technical and organisational measures in Schedule 3. We may change them, but not in a way that materially reduces the protection of Customer Personal Data during a paid term. The controls actually running are described, and dated, on our Security page.

7 Security incidents

We will notify you without undue delay and in any event within 48 hours of determining that a security incident has resulted in the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Customer Personal Data.

The notice will describe what happened, the categories and approximate volume of data involved, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once we will provide it in phases without further undue delay. We will assist you with your own notification obligations.

An unsuccessful attempt that does not compromise data — a blocked scan, a failed login, a rejected request — is not a reportable incident, and we will not paper you with them.

8 Consumer rights requests

Taking into account the nature of the processing, we will assist you in responding to consumer requests to access, correct, delete, or obtain a portable copy of personal data, and to opt out. The Service provides self-service export and lookup for this purpose.

If a consumer contacts us directly about data we process for you, we will not respond substantively; we will forward the request to you and tell the consumer we have done so.

One limit, stated plainly

The consent event table is append-only by design: UPDATE and DELETE are revoked at the database permission level. A deletion request against a consent record therefore cannot be satisfied by erasing the row, and we will not claim otherwise. A withdrawal is recorded as a new, dated event that supersedes the previous one, which is both the honest mechanism and the one that leaves you with a defensible history. Where a statute nonetheless compels erasure, we will work with you on the narrowest lawful route, which may require retiring the record set rather than editing it.

9 Audit

On reasonable written notice, no more than once in any twelve months unless a regulator or a security incident requires otherwise, we will respond to a reasonable security questionnaire and make available the documentation needed to verify our compliance with this Addendum. Any on-site audit is at your expense, during business hours, subject to confidentiality, and must not interfere with our operations or with another customer's data.

10 Deletion and return

On termination you may request, and we will provide within 30 days and free of charge, a complete machine-readable export of Customer Personal Data.

After that, we retain consent records for the balance of the six-year period described in Privacy Policy section 9, on the basis of compliance with a legal obligation and the establishment or defence of legal claims, and continue to apply this Addendum to them for as long as we hold them. All other Customer Personal Data is deleted within 90 days of termination, except for backups, which age out on their ordinary cycle.

11 International transfers

Customer Personal Data is processed and stored in the United States only. There is no cross-region replication and no offshore processing. If that ever changes, it is a subprocessor change under section 5 and you get 30 days' notice.

12 General

This Addendum takes effect with the Terms and continues while we process Customer Personal Data. Our liability under it is subject to the limitations in section 10 of the Terms. If a provision is invalid, the rest stands. New York law governs.

S1 Schedule 1 — Details of processing

Subject matter and duration

Provision of consent management and accessibility monitoring for your websites, for the term of the subscription plus the retention period in section 10.

Nature and purpose

Recording and storing website visitors' consent decisions; holding and releasing third-party tags according to those decisions; signalling consent state to platforms you configure; scanning your websites for accessibility defects; producing dated reports.

Categories of data subject

Visitors to your websites. Your personnel who hold accounts.

Categories of personal data

Consent records — ten fields: practice identifier; a random first-party visitor identifier; a SHA-256 hash of the IP address; a US state code derived server-side; the user agent string; a hash of the policy version in force; the consent action; four category booleans; the source of the decision; and a timestamp.

Account data: name, work email address, practice name, website domain.

Scan data: the URLs scanned on your own sites and the defects found.

Data not collected

No name, email address or telephone number in a consent record. No raw IP address. No device or browser fingerprint. No page URL, title or referrer. No treatment, condition or symptom context. No special-category or sensitive data as those terms are used in the state statutes.

Frequency

Continuous, on visitor interaction; scans on the schedule in your plan.

S2 Schedule 2 — Authorised subprocessors

Current as at the effective date above. This schedule is the authoritative list; changes are made here and notified under section 5.

Amazon Web Services, Inc. — United States

Object storage and content delivery for the consential.io website and for the consent widget file itself, and the HIPAA-eligible services running the consent API and its PostgreSQL database. This is where consent records are stored and processed. Infrastructure provider only: it has no application-level access and does not use the data for any purpose of its own. Covered by an AWS Business Associate Addendum executed 13 July 2026.

Cloudflare, Inc. — global anycast

Authoritative DNS for the consential.io domain. Traffic is not proxied through Cloudflare; it resolves names and nothing more. Does not receive consent records.

IPinfo LLC — United States

IP-to-US-state lookup, so the correct state notice can be shown. Receives an IP address at the moment a configuration request is served. Does not receive a consent record, and the lookup happens before any decision exists.

Google LLC — United States

Tag Manager and Analytics on the consential.io marketing website only, held until a visitor grants the analytics category. It is absent from the product and from every customer site. Listed for completeness; it never touches Customer Personal Data.

Why this list is short

The consent record is built so that it carries nothing that constitutes protected health information — ten fields, no name, no raw IP, no URL, no clinical context. That is what keeps the subprocessor list this short, and it is the reason a decision can be stored and proven without any subprocessor ever holding a patient's identity. See BAA section 3, which is the clause that carries this.

Any addition to this schedule is made here first, and you are notified under section 5 before the new subprocessor begins processing.

Not subprocessors

Destinations you configure — your CRM, your tag manager, your ad platforms — receive consent signals at your direction. They are your vendors under your agreements, not ours, and we do not control what they do with what you send them.

S3 Schedule 3 — Technical and organisational measures

  • Encryption in transit. TLS 1.2 or better on every public route, with no plaintext listener to fall back to.
  • Encryption at rest. Volume-level encryption on the database host.
  • Immutability. UPDATE and DELETE are revoked on the consent event table at the database permission level, so history cannot be rewritten by the application, by a compromised credential, or by us.
  • Data minimisation by construction. The record has ten fields and the omitted ones are enumerated in Schedule 1. A field that is never collected cannot leak.
  • Tenant isolation. Every data access is scoped by practice in a single data-access layer, with automated cross-tenant tests in the build.
  • Network exposure. The database publishes no host port; it is reachable only from the application over a private network.
  • Access control. Production access limited to named individuals, on least-privilege credentials, logged.
  • Backups. Nightly logical backups, each automatically restore-tested; a backup that fails verification fails the job loudly. Fourteen daily copies retained plus every month-start copy.
  • Secrets. Held outside source control; no credential in the repository.
  • Change control. Automated tests, including an append-only enforcement test, gate every release.
  • Personnel. Confidentiality obligations for everyone with access.