Last updated: 2026-09-06 Version: 1
This is a navigational index only, not a substitute for the numbered sections below — if anything here appears to conflict with a numbered section, the numbered section controls.
Consentivo is a product operated by Filova Ltd ("Filova", "we", "us", "our"), a company registered in England and Wales.
This policy explains how we handle personal data in two distinct roles:
When you create a Consentivo account: name, email address, and an email and role for each member of your Organization.
Billing is not enabled during the controlled beta. No payment provider is currently engaged, no payment method is requested, and no billing details or card numbers are collected or stored — see Section 5.
When a visitor to an Organization's website interacts with a Consentivo banner, we record:
anon_id) — not a name,
email, or account identifier. It is not linked to any Consentivo account.proof_hash) of the record, so the record can be shown not to have been
altered after the fact.We do not knowingly collect or store the name, email address, or any other directly identifying information of an Organization's website visitors as part of this consent-recording function. We also do not intentionally collect any special category / sensitive personal data (such as health, racial or ethnic origin, religious belief, or sexual orientation) as part of this function.
These are the categories we decide the purposes and means for — our own customer relationship, not our customers' website visitors.
| Data | Purpose | Legal basis (GDPR/UK GDPR Art. 6) |
|---|---|---|
| Organization account data | Provide the Consentivo service to the Organization, and support it | Contract (Art. 6(1)(b)) |
| Site/cookie/banner configuration | Provide the banner-configuration and (where enabled) scanning features | Contract (Art. 6(1)(b)) |
| Security, abuse-prevention and service-administration data (e.g. rate limiting, account audit log) | Protect the Service and its users; administer and secure our own systems | Our legitimate interest (Art. 6(1)(f)) in the security and integrity of the Service |
For consent and consent-evidence data collected from an Organization's own website visitors, the Organization is the controller. The Organization determines and is responsible for documenting the lawful basis on which that visitor data is processed, and for giving visitors the information its own law requires.
Filova processes that data solely on the Organization's documented instructions, under the agreement and the Data Processing Agreement between us, except where we are required to process it by law applicable to us. Our contract with the Organization is what governs our processing; it is not, and we do not present it as, a lawful basis for processing the visitor's personal data. That determination belongs to the Organization.
Retention periods by data category:
Account data, site/cookie/scan data, and configuration data — deleted on verified request, except where retention is required by law or an active legal or regulatory obligation. Consentivo does not currently provide a self-service deletion tool; these requests are handled manually.
Consent records — retained for as long as reasonably necessary to demonstrate the consent decisions actually collected and to comply with applicable legal obligations. Because their evidential value depends on their integrity, they are not altered and are not deleted on any fixed schedule, and no ordinary application path can remove one.
This is a matter of how the records are protected, not a claim that they can never be erased. Where the controlling Organization gives a documented erasure instruction, or where erasure is required by applicable law or by a competent authority, the records concerned are erased through a restricted internal process, targeted at the specific organization or the specific visitor identifier in question. That process is manual, is available only to authorized personnel, and records that the erasure took place without retaining the identifier that was erased.
| Sub-processor | Role | Location | Status |
|---|---|---|---|
| Supabase | Database (Postgres) and authentication | EU (eu-central-1), with the provider's own sub-processors (infrastructure, support) located in the US and Singapore |
Live |
| Vercel | Application hosting | United States (default function region) — an EU region is not currently configured for this deployment | Live |
| Google Cloud Platform (Cloud Run) | Execution environment for the cookie-scanning worker | Region set at deployment; not currently fixed | Feature disabled. The scanner is switched off across the Service, so no personal data is processed on this infrastructure at present |
No payment provider is currently engaged. Billing is not enabled, so no payment data is processed by anyone on our behalf. If and when a provider is selected, this table and the DPA's sub-processor annex will be updated and Organizations notified before it begins processing.
We do not sell personal data. We do not share consent records with any party other than the Organization that collected them and the sub-processors above, acting on our instructions, except where required to do otherwise by law applicable to us (for example, a valid court order or regulatory demand).
Our primary database infrastructure (Supabase) is hosted in the EU
(eu-central-1); our application hosting (Vercel) currently processes in
the United States by default.
Personal data may be transferred outside the UK/EEA — to our sub-processors' own infrastructure, and through remote access to EU-hosted data from our UK operations. Where a transfer requires a safeguard under UK GDPR or GDPR, we rely on the safeguard offered in the relevant sub-processor's own data processing terms, which are the terms we contract on. Section 7 of our Data Processing Agreement (consentivo.com/en/legal/dpa) identifies each sub-processor and the terms relied on.
We describe those terms rather than asserting a specific mechanism for each route, because the mechanism that applies depends on the contracting entity and the destination in each case. Where we have not verified which mechanism applies, we say so in the DPA rather than assuming one.
Subject to applicable law (GDPR, UK GDPR, CCPA/CPRA, or other), you may have the right to:
To exercise any of these rights, contact privacy@filova.io. To protect your data, we may need to verify your identity and authority before fulfilling a request. If your request concerns consent-record data collected via an Organization's website, we may direct you to that Organization, as they are the controller of that relationship — but we will still assist as their processor.
Consentivo does not currently provide self-service access, export or deletion tooling, and no particular file format is offered. Verified requests are handled manually, and we will tell you what we can provide and in what form when we acknowledge the request.
We implement appropriate technical and organisational measures under Article 32 GDPR, including:
proof_hash) computed over the record's contents, so alteration by a party
without the signing key can be detected.Your legal basis for processing and rights are as described in Sections 3 and 7. You have the right to lodge a complaint with your local supervisory authority: in the UK, the Information Commissioner's Office (ico.org.uk); if you are in the EEA, the competent supervisory authority in your own EEA Member State.
Data Protection Officer: Filova has not appointed a Data Protection Officer. Whether an appointment is required under GDPR/UK GDPR Article 37 depends on the nature, scope and purposes of the processing actually carried out; we keep that assessment under review and will appoint one if and when it becomes required.
EU representative under GDPR Article 27: Filova is established in the United Kingdom and has not appointed an EU representative. Whether Article 27 is engaged depends on whether our processing falls within Article 3(2), which turns on the processing we actually carry out rather than on any fixed point in time. We will appoint an EU representative where and when that obligation applies, before the relevant EU-facing processing begins.
If you are in Türkiye, see our separate KVKK Aydınlatma Metni at consentivo.com/tr/yasal/kvkk-aydinlatma-metni, which follows the disclosure format expected under Law No. 6698.
California (CCPA/CPRA) residents have the right to know what personal information is collected, to request deletion, and to opt out of the "sale" or "sharing" of personal information. We do not sell personal information, and we do not sell or share personal information for cross-context behavioral advertising. Our banner reads and records the browser's Global Privacy Control (GPC) signal alongside each consent decision, so the Organization operating the website has that signal in its own consent evidence. The banner does not currently act on the signal automatically — it does not, by itself, change the choices presented or override the visitor's selection. Acting on a GPC signal where the Organization's own law requires it is therefore the Organization's responsibility as controller.
Other US states with a comprehensive privacy law in effect (a growing list that, as of this writing, includes states such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others) generally give their residents similar rights: access, deletion, correction, and an opt-out of sale/targeted advertising. As described above, our banner records the Global Privacy Control signal in the consent evidence but does not act on it automatically. Note that for Organizations' website visitors, Consentivo typically acts as a data processor/service provider on the Organization's behalf — if you are an end visitor, the Organization operating the website you visited is usually the right party to contact first to exercise these rights; we assist them as needed.
If you are located somewhere not named above, you may still have similar rights under your local data protection law (for example, access, correction, deletion, or objection to processing). Contact us at privacy@filova.io and we will do our best to honor a verified request under the law that applies to you, even where this policy doesn't name your jurisdiction specifically.
Consentivo is a business-to-business product and is not directed at children. We do not knowingly collect personal data from anyone under the age of 13 (or the applicable minimum age of digital consent in your jurisdiction, which may be higher — for example, up to 16 in some EEA Member States).
If Filova is involved in a merger, acquisition, or sale of assets, personal data we hold as a controller (Organization account data, site/cookie/ config data) may be transferred as part of that transaction, subject to this policy or a policy that offers materially equivalent protections. Data we hold as a processor on an Organization's behalf (consent records) would only transfer to the acquiring party as a new sub-processor or successor processor under the terms of our Data Processing Agreement with that Organization — including the Organization's right to prior notice and to object, per Section 4.4 of the Data Processing Agreement — not merely "subject to this policy."
We will update the "Last updated" date above when this policy changes, and for material changes, notify Organization account holders by email.
Filova Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. privacy@filova.io. Phone: +44 20 3967 8386.
Sections 4 and 6 of this policy were prepared based on official regulatory sources (European Commission, EDPB, UK ICO, KVKK Kurumu) and the relevant vendors' own published data processing terms, current as of the "Last updated" date above. This is not a substitute for legal advice.