FAQ · KNOWLEDGE BASE

Frequently Asked Questions

Technical, cryptographic, and statutory guidance on how ConsentPlix creates audit-ready, tamper-evident consent records under the DPDP Act 2023, GDPR, and CCPA.

Definition

What is ConsentPlix?

ConsentPlix is consent infrastructure that turns every consent decision into a signed, Merkle-sealed receipt stored in an append-only ledger. It combines a consent widget and SDK in 22 languages, a rights portal, signed webhooks and a site scanner, and it stores only pseudonymous consent records, hosted on AWS Mumbai by default.

How it works

From notice to proof in four steps

  1. 01

    Notice is shown

    The widget renders the notice for the visitor's jurisdiction and language, and records a hash of the exact text displayed.

  2. 02

    Decision is signed

    Each grant, rejection or withdrawal becomes a pseudonymous receipt signed with HMAC-SHA256.

  3. 03

    Receipt is sealed

    Receipts are appended to the ledger and rolled into periodic Merkle checkpoints, so later edits are detectable.

  4. 04

    Proof is exported

    Signed webhooks push every receipt to your own systems, ready for an audit or a regulator request.

20 answers

All questions

20 questions shown

  • 01

    ConsentPlix stores pseudonymous consent receipts only. Each receipt contains a pseudonymous session ID, timestamp, the exact policy notice hash displayed to the visitor, granular purposes granted or rejected, and an HMAC-SHA256 signature. We do not store visitor IP addresses, browsing histories, behavioral analytics, or personal customer profiles.

  • 02

  • 03

  • 04

  • 05

  • 06

  • 07

  • 08

  • 09

  • 10

  • 11

  • 12

  • 13

  • 14

  • 15

  • 16

  • 17

  • 18

  • 19

  • 20

Keep reading

Related pages

Still have questions?

Walk through your consent setup with our team

We can review your current tags, data flows and DPDP gaps on a short call, and show how receipts are signed and verified.