1 Who we are
Consential is a product of Efferent Media LLC, a New York limited liability company ("Consential", "we", "us"). We publish this website at consential.io and we operate the Consential consent management and accessibility monitoring platform, which medical and aesthetic practices install on their own websites.
This policy explains what we do with information. It is written to be read, not to be survived. Where a sentence would normally hedge, we have tried to state the fact instead.
2 The two roles we play, and why it matters to you
Almost every complaint about a privacy policy comes from a company blurring these two roles. We keep them apart.
2.1 As a controller
For visitors to consential.io and for our own customers — the practices who buy the product — we decide what is collected and why. That is the information covered by sections 5 and 6.
2.2 As a processor
For the consent records written on a practice's own website, the practice decides, and we act on its instructions. We do not decide what those records are used for, we do not use them for our own purposes, and we do not move them between practices. If you are a patient or a visitor to a practice's site and you want a record changed or explained, the practice is the party who holds that decision, and section 10.3 explains how to reach us anyway.
Our commercial interest is in the practice paying a subscription. It is not in the data. We have no advertising business, no data-brokerage business, and nothing downstream that would be worth more if these records were richer.
3 What a consent record contains
When a visitor to a practice's website accepts, declines, or changes a choice, exactly ten fields are written. This is the whole row.
- practice_id — which practice's website the visitor was on.
- visitor_id — a random identifier: the string
vis_followed by 32 hexadecimal characters from the browser's cryptographic random number generator, kept in a first-party cookie. Nothing about the device is measured to produce it, so it cannot follow a person to another practice's website. - ip_hash — a SHA-256 hash of the originating IP address. The address itself is never written to disk.
- ip_geo_region — a US state code, derived on our server from the address the request already carried, so the correct state notice can be shown. A region supplied by the browser is discarded.
- user_agent — the browser identification string sent with the request.
- policy_version — a SHA-256 hash of the policy text in force at that moment, so the record shows what was actually agreed to rather than what the policy says today.
- consent_action — one of
granted,denied,revoked,updated. - categories — the four category switches and their state.
- source — where the decision came from: the consent box, the preference centre, the API, or a Global Privacy Control signal.
- created_at — the timestamp, to the microsecond, with time zone.
4 What a consent record never contains
These are not fields we happen to omit today and might add later. Several of them are the reason the product exists, and adding one would be a change to this policy under section 14.
- A name, email address, or telephone number.
- The raw IP address.
- A device or browser fingerprint.
- The page URL, page title, or referrer. On a medical website the URL is frequently the most sensitive thing on the page — a path naming a procedure is a health inference about the person reading it. We do not want it, so we do not take it.
- Any treatment, condition, or symptom context.
- Anything a practice would recognise as protected health information.
If a practice later associates an email address with a consent record when a patient submits a form, that association happens in the practice's own systems, under the practice's own agreements, and it is the practice's responsibility.
5 This website
consential.io runs the same consent box we sell, against the same rules.
Before you consent to anything, this website makes no third-party requests. One analytics container (Google Tag Manager, feeding Google Analytics) is present and is held — the browser is given it as inert text and never executes it — unless and until you grant the analytics category. There are no advertising or remarketing tags on this website at all, and there is no analytics of any kind inside the product itself.
You can change your choice at any time, including withdrawing it. We honour Global Privacy Control signals sent by your browser as a refusal, without requiring you to interact with the box.
Our web server produces ordinary request logs (IP address, timestamp, path, user agent) for security and abuse investigation. They are not joined to consent records and are not used to build a profile.
6 Customer and prospect information
If you buy the product, ask for a quote, or run a scan on our free scanner, we hold what you gave us: a name, a work email address, a practice name, a website domain, and the correspondence itself. If you run a scan, we also keep the domain scanned, the grade, the score, and the IP the request came from, so we can tell a real enquiry from an abuse pattern.
We do not receive or store full payment card numbers. Where a card payment is taken it is handled by a third-party payment processor, and we see only the result and the last four digits.
7 Why we are allowed to use it
We rely on these bases, and no others:
- Performing the contract you or your practice entered into with us.
- Our legitimate interest in operating, securing, and improving the service — including request logs, abuse prevention, and aggregate counts that never identify a visitor.
- Consent, for the analytics on this website, which you can withdraw at any time.
- Compliance with a legal obligation, and the establishment or defence of legal claims. This is the basis for the retention period in section 9, and it is deliberate: a record that disappears is worth nothing to the practice that needs it.
8 Who else is involved
The complete current list of subprocessors, what each one does, where it runs, and whether it can see consent data, is published in the Data Processing Addendum, Schedule 2, summarised alongside every stored field in the privacy hub, and is kept current there rather than restated here. A practice that wants advance written notice of a change should say so in its agreement with us.
Two commitments hold regardless of that list. We do not sell personal information, and we do not share it for cross-context behavioural advertising — as those terms are defined under California, Colorado, Connecticut, Virginia and comparable state law. We have never done so and the product has no mechanism that would make it possible. And we will not add a subprocessor that handles consent records without a written agreement covering it.
We may disclose information if compelled by law. If we receive a demand for records belonging to a practice, we will tell that practice before responding unless we are legally prohibited from doing so, so that the practice can object on its own behalf.
9 How long things are kept
9.1 Consent records
Six years. The consent event table is append-only: UPDATE and DELETE
are revoked at the database permission level, so the history cannot be quietly rewritten by a
practice, by an attacker who reaches the application, or by us.
Six years is the window that the accounting-of-disclosures right at 45 CFR § 164.528(a)(1) reaches back. We use that provision rather than the Security Rule documentation period at § 164.316(b)(2)(i), because a tag firing on a health-intent page is closer to a disclosure than to Security Rule documentation. That is a reading of the rule, not settled law, and it is under review with counsel.
9.2 Retention is not tied to billing
Cancelling stops collection, the dashboard, and the reports. It does not delete the archive. The record is worth most after a relationship ends, because inquiries and claims arrive late, and a trail that evaporates with the invoice is a subscription to a promise. On cancellation a practice is entitled to a complete export of its records — a transfer of custody, not a destruction. They are the covered entity; it is their evidence. We will never condition access to an archive on payment.
9.3 Everything else
Account and billing records are kept while the account is open and for seven years afterwards for tax and audit purposes. Enquiries and scan results are kept for two years. Web server logs are kept for 90 days.
10 Your rights
10.1 If you are a customer or a visitor to this website
You may ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, withdraw a consent you gave, and object to processing based on legitimate interest. Depending on your state you may also have the right to appeal a refusal, and to be free of discrimination for exercising any of these rights. We do not charge for any of it, and we will not treat you differently for asking.
We respond within 45 days and will tell you if we need a further 45, which is the outer limit under the state statutes that set one.
10.2 Verification
We will ask you to confirm control of the email address on the account. We will not demand identity documents for a request of this kind, because collecting a government ID to service a privacy request makes the situation worse rather than better.
10.3 If you are a patient or a visitor to a practice's website
The practice is the controller of that record and is the right party to ask. If you contact us instead, we will forward the request to the practice and tell you we have done so. We cannot delete a consent record on request, for the reason given in section 9.1, and we would rather say that plainly than imply an ability we do not have. What you can always do is change or withdraw your choice on the practice's website, which writes a new, dated record superseding the old one.
11 State-specific disclosures
Roughly twenty US states now have a comprehensive consumer privacy law, and several more have a health-data-specific one. Rather than a table that goes stale, the operative facts:
- We do not sell personal information and do not share it for cross-context behavioural advertising. There is therefore no opt-out of sale to offer, but the "Privacy choices" control in our footer is present on every page regardless.
- We do not engage in profiling that produces legal or similarly significant effects, and we make no automated decisions about anyone.
- Sensitive data. The product is designed so that we do not receive it. See section 4.
- Washington, Nevada and Connecticut consumer health data. These statutes reach further than HIPAA and can attach to a website visit rather than a patient record. The same answer applies: we do not collect the page URL, so we do not hold the signal these laws are aimed at.
- California. We are a "service provider" with respect to consent records and are contractually barred from retaining, using, or disclosing them for any purpose other than performing the service.
12 Security
Every public route is TLS 1.2 or better, with no plaintext listener to fall back to. The database publishes no host port. Access to production is limited to named individuals and is logged. Backups run nightly and each one is automatically restore-tested; a backup that fails verification fails the job loudly rather than sitting on a shelf. The controls that are actually running are described in more detail, and dated, on our Security page.
No system is immune. If we determine that a breach affecting your information has occurred, we will notify you and, where the information belongs to a practice, that practice, without unreasonable delay and within the timeframes required by applicable law and by our Business Associate Agreement.
13 Children
The product is sold to businesses and this website is not directed to children. We do not knowingly collect information from a child under 13. Because a consent record contains no identifier, we cannot determine a visitor's age, and we do not attempt to.
14 Changes to this policy
When this policy changes we update the effective date at the top and, for any change that broadens what we collect or who receives it, we give notice to customers by email at least 30 days before it takes effect. Prior versions are retained and available on request, because a company selling versioned policy records should keep its own.
15 Contact
Privacy questions, rights requests, and anything you think this page gets wrong: Contact. A person reads it.
Efferent Media LLC, New York, United States. Our registered mailing address is available on request and is stated in full in any executed agreement.