ConsentLo Privacy Policy

Effective 19 Sep 2026

ConsentLo builds software that helps organisations comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025. We hold ourselves to the same standard. This policy explains what personal data ConsentLo processes, why, for how long, and the rights you have.

1. Who this policy covers

This policy applies to the ConsentLo website at consentlo.com, to ConsentLo workspaces at <organisation>.consentlo.com, to the ConsentLo privacy portals and consent SDK, and to our emails and support.

In this policy, "ConsentLo", "we", "us" and "our" mean ConsentLo, the provider of the ConsentLo platform. "You" means a visitor to our website, a person who contacts us, or a user of a ConsentLo workspace.

2. Our role under the DPDP Act

ConsentLo is the Data Fiduciary for personal data we collect for our own purposes: website enquiries, demo requests, workspace user accounts, security logs and billing.

When a customer organisation uses ConsentLo to manage its own notices, consents, rights requests, grievances and breaches, that organisation is the Data Fiduciary for the personal data of its Data Principals, and ConsentLo is its Data Processor. We process that data only on the organisation's documented instructions and under a written contract. If your data sits in a customer's workspace, please contact that organisation first, for example through its privacy portal; we will help it respond to you.

3. Personal data we collect

Depending on how you interact with ConsentLo, we collect:

  • Enquiry and demo data: your name, work email, organisation, mobile number, purchase timeline, subject and message when you use our Contact or Book a demo forms.
  • Account data: name, work email, username, role and the workspace you belong to.
  • Authentication data: password hashes, encrypted authenticator secrets, short-lived one-time codes and session identifiers. We never store passwords in readable form.
  • Security and usage data: IP address, browser and device information, timestamps, and an audit trail of actions taken in a workspace.
  • Communications: emails and messages you exchange with ConsentLo support and sales.
  • Plan and billing data: the plan assigned to a workspace and its subscription status. Where card payments apply, card details are handled directly by our payment provider and are not stored by ConsentLo.

4. Why we use personal data

We use personal data only for specified purposes:

  • To reply to your enquiry, arrange and deliver a demo, and follow up on it.
  • To create and run your workspace account, sign you in securely and keep workspaces isolated from each other.
  • To send service emails such as verification codes, security alerts, deadline reminders and notifications.
  • To protect the service: detect abuse, investigate incidents and keep audit logs.
  • To manage plans and billing, and to meet our legal, tax and regulatory obligations.
  • To improve ConsentLo using aggregated information that does not identify you.

5. Lawful basis

We rely on your consent where you give it, for example when you submit a form and ask us to contact you. You can withdraw that consent at any time, as easily as you gave it, and it will not affect processing already done.

For other purposes we rely on the legitimate uses permitted by Section 7 of the DPDP Act, such as data you voluntarily provide for a specified purpose (for example, to use a workspace you signed up for) and compliance with law.

We do not sell personal data, we do not use customer workspace data for our own purposes, and we do not use personal data for targeted advertising.

6. Cookies and browser storage

ConsentLo uses only what is needed to run the service: session storage for signing in, and browser storage for preferences such as your workspace colour theme and sidebar layout. We do not use advertising or cross-site tracking cookies.

7. Who we share personal data with

We share personal data only with service providers that help us run ConsentLo, such as hosting, email delivery and payment processing. Each acts as our Data Processor under a written contract and may use the data only to provide its service to us.

We may also disclose personal data where the law requires it, for example to the Data Protection Board of India or another authority acting within its powers.

8. Where personal data is stored

ConsentLo is hosted in India. If a service provider processes personal data outside India, we do so only as the DPDP Act and any restrictions notified by the Central Government permit.

9. How long we keep personal data

We keep personal data only as long as the purpose needs it. Enquiry and demo data is kept for up to 24 months after our last contact with you unless you become a customer. Account data is kept while the account is active and erased after the account is closed, except where a law requires us to keep it longer. Security logs are kept for at least one year, as the DPDP Rules require.

Customer workspace data is kept and erased under that customer's own retention settings and our contract with them.

10. How we protect personal data

We use reasonable security safeguards, including encryption in transit (HTTPS), hashed credentials, role-based access control, isolation between workspaces, optional two-step sign-in, access logging and monitoring, and a tamper-evident evidence log. ConsentLo staff access customer data only when needed to support that customer.

11. Personal data breaches

If a personal data breach affects data for which ConsentLo is the Data Fiduciary, we will inform affected people and the Data Protection Board as the DPDP Act and Rules require. If it affects a customer's workspace data, we will notify that customer without delay so it can meet its own obligations.

12. Your rights

Under the DPDP Act you can ask ConsentLo to:

  • Give you a summary of the personal data we process about you and the processing activities, and tell you who we have shared it with.
  • Correct, complete or update inaccurate or incomplete personal data.
  • Erase personal data that is no longer needed, unless a law requires us to keep it.
  • Stop processing based on your consent by withdrawing it.
  • Nominate another person to exercise your rights if you die or become incapable.
  • Resolve a grievance about how we handle your personal data.

13. How to exercise your rights or raise a grievance

Contact the ConsentLo Grievance Officer through the contact form at consentlo.com/contact and write "Privacy request" in the subject. We may ask you to confirm your identity. We respond as quickly as we can and in any case within the period the DPDP Rules allow.

If you are not satisfied with our response, you may complain to the Data Protection Board of India.

14. Children

ConsentLo is a business service and is not directed at children. We do not knowingly collect personal data of anyone under 18 for our own purposes. If you believe a child has given us personal data, contact us and we will erase it.

15. Changes to this policy

We may update this policy as ConsentLo or the law changes. We will post the new version on this page with a new effective date, and tell workspace users about material changes by email or in the product.

16. Contact ConsentLo

For any question about this policy or about personal data at ConsentLo, write to the ConsentLo Grievance Officer through the contact form at consentlo.com/contact.

See also the ConsentLo Terms of Service.