Legal and business information

Privacy Notice

Last updated 19 August 2026

Service and trading name: Consentory
Legal operator and contracting party: AKSAMIT PROJECTS sp. z o.o.
Registered address: ul. Stefana Batorego 18/108, 02-591 Warsaw, Poland
Registration number: KRS 0001143745
VAT ID or status: NIP 1231570838
Customer support: support@consentory.io · Email support only
Legal notices: legal@consentory.io

Effective date: 2026-08-19
Document version: 2.0

1. Who this notice covers

This notice explains how AKSAMIT PROJECTS sp. z o.o., operating Consentory, processes personal data when you visit our public website, create or use an account, purchase a subscription, request support, or communicate with us. It does not replace the privacy notice of a customer website that uses the Consentory widget.

2. Our roles

We are the controller for account administration, security, billing, product analytics where enabled, support and our own business operations. When we receive consent records or website configuration on behalf of a customer, that customer is normally the controller and we act as processor under the applicable data processing terms. Stripe acts under its own terms for payment processing and may act as an independent controller for regulatory, fraud-prevention and payment-network purposes.

3. Data categories

  • Identity and account data: name, business name, role, email, phone and account identifiers.
  • Authentication and security data: password hashes, session records, MFA settings, recovery events, IP-derived security data, timestamps and audit logs.
  • Service data: registered domains, widget configuration, policy links, cookie and tracker scan findings, support requests and product usage.
  • Customer-controlled consent data: pseudonymous visitor identifier, consent categories, timestamps, region and configuration version.
  • Transaction data: plan, billing interval, Stripe customer and subscription identifiers, invoice, refund and dispute status, billing address and tax identifiers. We do not store full card numbers or card security codes.
  • Device and communications data: browser and device information, diagnostic logs and the contents of messages sent to us.

4. Purposes and legal bases

  • Providing accounts, subscriptions, scanning, consent tools and support: performance of a contract or steps requested before a contract.
  • Authentication, abuse prevention, service integrity, troubleshooting and auditability: our legitimate interests in operating a secure service and, where applicable, legal obligations.
  • Billing, tax, accounting, refunds and disputes: performance of contract and compliance with legal obligations.
  • Improving the service using aggregated or limited operational data: legitimate interests, balanced against user rights.
  • Optional analytics, marketing communications or device storage: consent where required. Consent can be withdrawn at any time.
  • Establishing, exercising or defending legal claims and responding to authorities: legitimate interests and legal obligations.

5. Required and optional data

Data marked as required is needed to create an account, secure the service or complete billing. Without it, we may be unable to provide the requested service. Optional profile fields and optional communications can be declined without losing core account functionality.

6. Recipients

We disclose data only as necessary to payment, hosting, infrastructure, email, security, monitoring, customer-support and professional-adviser providers; to public authorities where legally required; or in connection with a corporate transaction subject to appropriate safeguards. Providers are bound by contracts and access controls appropriate to their role.

7. International transfers

If personal data is transferred outside the EEA, United Kingdom or Switzerland, we use an applicable adequacy decision, approved standard contractual clauses or another lawful transfer mechanism and assess supplementary safeguards where required. Details relevant to customer-controlled processing are available through the contractual data protection documentation.

8. Retention

  • Account and service configuration: for the account term and normally up to 30 days after verified deletion, subject to backup cycles.
  • Security and audit records: according to configured security retention periods, normally up to 24 months unless a longer period is necessary for an incident or claim.
  • Billing, invoice and tax records: for the period required by the operator’s accounting and tax laws, which can be up to 10 years.
  • Support communications: normally 24 months after closure, unless linked to an active dispute or legal duty.
  • Customer-controlled consent evidence: according to the customer’s documented instructions and configured retention rules.
  • Failed password-reset and short-lived session records: automatically expired according to security configuration.

9. Your rights

Subject to applicable law, you may request access, correction, erasure, restriction, portability or object to processing. You may withdraw consent without affecting prior lawful processing. Contact privacy@consentory.io. We may need to verify identity and distinguish data we control from data held solely on a customer’s instructions.

10. Complaints

You can complain to the data protection authority in your EEA country of residence, employment or the alleged infringement. We encourage you to contact us first so we can investigate.

11. Automated decisions and children

We do not use account data for decisions producing legal or similarly significant effects solely by automated means. The service is intended for organisations and authorised adults, not for children to purchase directly.

12. Security and payment data

We use access controls, encryption in transit, credential hashing, MFA support, audit logging, backups and incident procedures appropriate to the service. Payments are completed on Stripe-hosted Checkout. Stripe is PCI DSS certified; full card details are transmitted directly to Stripe and are not stored on Consentory servers.

13. Changes

We will publish material changes on this page, update the version and provide additional notice where required.