Legal · Privacy

Privacy Policy

How ConsentPlix captures, seals and protects consent records, what we never collect, and how to reach our Grievance Officer.

Effective
October 2026
Entity
ConsentPlix Private Limited

What this policy covers

ConsentPlix is consent infrastructure: a consent widget, an append-only ledger of signed consent receipts and a rights portal. This policy explains that, when deployed on a client website, ConsentPlix processes only pseudonymous consent records on behalf of the client, stores them in AWS Mumbai, and does not track or profile visitors.

At a glance

  • Visitor data

    No visitor tracking or profiling

  • Receipts

    Signed with HMAC-SHA256

  • Region

    AWS Mumbai (ap-south-1)

  • Grievances

    Dedicated Grievance Officer

Architectural role and scope

ConsentPlix Private Limited ("ConsentPlix", "we", "our", or "us") provides cryptographically verifiable consent capture and custody infrastructure. When business clients deploy our sub-12KB JavaScript embed on their websites or web applications, ConsentPlix acts as a Data Processor (and under the Indian Digital Personal Data Protection Act, 2023, as an agent processing data on behalf of the registered Data Fiduciary).

This Privacy Policy explains how our ledger captures and safeguards data, our minimal-data architectural mandate, and how we handle inquiries from Data Fiduciaries and individuals.

Pseudonymous consent records only

Unlike legacy cookie management platforms that track visitor profiles, retain browsing histories, or sell audience intelligence, ConsentPlix stores pseudonymous cryptographic consent records only.

When a visitor interacts with our consent notice, we generate an append-only consent receipt containing only:

  • A randomly generated anonymous session token (receipt_uuid)
  • ISO-8601 UTC timestamp of the decision
  • SHA-256 hash of the exact privacy notice text and purposes displayed
  • Granular category bitmask (for example Essential=1, Analytics=1, Marketing=0)
  • HMAC-SHA256 signature generated via KMS

We do not log visitor IP addresses, geolocation beyond high-level country or region determination, device fingerprints, or browsing histories.

Data residency

All ConsentPlix primary production infrastructure, key custody, and Merkle checkpoint ledgers are hosted in AWS Mumbai (ap-south-1), India. No customer consent receipts are transferred out of India unless the enterprise customer expressly configures it.

Data subject rights and one-click withdrawal

Under Section 6(4) of the DPDP Act 2023 and Article 7(3) of the EU GDPR, withdrawing consent must be as easy as granting it.

ConsentPlix provides a preference widget embedded into client sites, letting any visitor switch off non-essential categories in one click. If an individual wishes to exercise statutory rights (access, erasure, or grievance redressal), our hosted rights portal timestamps and routes the request directly to the Data Fiduciary's registered Grievance Officer with automated 72-hour countdown timers.

Security and encryption standards

ConsentPlix implements defence-in-depth security:

  • All traffic in transit encrypted via TLS 1.3 with strict HSTS enforcement.
  • All ledger blocks encrypted at rest via AES-256-GCM.
  • Cryptographic keys isolated in FIPS 140-2 Level 3 validated hardware security modules.
  • Continuous vulnerability scanning and automated security controls monitoring.

Grievance redressal and registered office

In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, you may address any concerns or complaints directly to our designated Grievance Officer at [email protected]. Every grievance receives a reference number and is acknowledged within 24 hours.

Registered Office & Operations: ConsentPlix, Porbandar, Gujarat, India (PIN: 360575). Attn: Grievance Officer & Data Protection Officer.

Privacy questions

Does ConsentPlix track the visitors on my website?

No. ConsentPlix records the consent decision itself, not visitor behaviour. Receipts hold an anonymous token, a timestamp, a notice hash, the category choices and a signature.

Is ConsentPlix a Data Fiduciary or a Data Processor?

For consent captured on client websites, ConsentPlix acts as a Data Processor on behalf of the client, who is the Data Fiduciary (or controller under GDPR).

Where is consent data stored?

In AWS Mumbai (ap-south-1), India. Receipts leave India only if an enterprise customer expressly configures it.

How do I raise a privacy complaint?

Email [email protected]. Every grievance receives a reference number and an acknowledgement within 24 hours.

RelatedTerms of Service Licence, SLA, billing and jurisdiction.RelatedPricing Starter, Growth and Enterprise plans.RelatedRequest a demo See sealed receipts on your own site.

Questions about data handling?

Walk through the receipt format with an engineer.

Book a demo