Consentia — Privacy Policy
1. Identity of the provider
This Privacy Policy describes how TRANSYLVANIA MARKETING LTD SRL (“we”, “us”, “our”, the “Provider”) handles personal data in connection with the application Consentia (the “App”).
| Legal name | TRANSYLVANIA MARKETING LTD SRL |
|---|---|
| Company registration code | CUI 43230933 |
| Registered address | Str. Crișanei 2, 550012 Sibiu, România |
| contact@transilvaniamarketing.ro | |
| Website | https://transilvaniamarketing.ro |
Email is our designated channel for all privacy matters, including data subject requests, processor instructions from merchants, and questions about this Policy. Written correspondence to the registered address is also accepted.
2. Purpose, scope and audience
Purpose. This Policy explains, in full, which categories of data the App processes, for which purposes, on which legal basis, for how long, with whom they are shared, and which rights the individuals concerned have.
What this Policy covers. Data generated by visitors of an online store on which a merchant has installed and activated the App (“Visitor Data”), and data relating to the merchant that installs and operates the App (“Merchant Data”).
What this Policy does not cover. The privacy practices of the merchant who installs the App, who publishes its own privacy policy and is responsible for it; the privacy practices of the store platform itself; the privacy practices of Google or of any other third-party tool a merchant has installed on its store independently of the App; and any cookie, tag, pixel or script placed on a merchant’s store by anyone other than the App.
Audience. Merchants evaluating or using the App, visitors of stores on which the App is active, and app marketplace reviewers.
Interpretation. Where this Policy states that something is not done, that statement is absolute and is not subject to unstated exceptions. Where a figure, period or region is given, it is the figure, period or region actually applied. Headings are for convenience only and do not limit the text beneath them.
3. Definitions
GDPR means Regulation (EU) 2016/679. Personal data, processing, controller, processor, sub-processor, data subject and personal data breach have the meanings given in Article 4 GDPR.
Merchant means the person operating an online store who installs the App on that store. Visitor means any person who visits a store on which the App is active and to whom the consent banner is displayed. Consent Record means a single row stored by the App describing one consent-related event, as itemised in section 6. Store Platform means the store platform, the platform on which the store and the App run.
4. What the App does
The App has exactly four functions:
- it displays a cookie consent banner on the store;
- it transmits the Visitor’s choice to Google Consent Mode v2 and to the Store Platform’s customer privacy interface;
- it maintains a register of consents, which the Merchant can export as a CSV file;
- it shows the Merchant aggregated statistics about that Merchant’s own store: banner impressions, response rate, acceptance rate, and a breakdown by region.
The App performs no function beyond these four. It is not an analytics product, not an advertising product, not a marketing product and not a customer relationship management product.
5. Roles: controller and processor
Visitor Data — the Merchant is the controller, we are the processor. For all Visitor Data described in section 6, the Merchant determines the purposes and means of processing. We act solely as a processor under Article 28 GDPR and process Visitor Data only to provide the four functions in section 4 to that same Merchant, and only on that Merchant’s documented instructions, which include its configuration of the banner and its installation of the App.
In practice, we do not decide why Visitor Data is collected, we do not use it for our own purposes, we do not combine data from different Merchants’ stores into any cross-merchant product or dataset, and we disclose it to no one other than the Merchant whose store generated it and the sub-processors listed in section 16.
Merchant Data — we are the controller. For the merchant account data described in section 7, we determine the purposes and means of processing, in order to provide, secure, maintain and support the App.
Nothing in this Policy makes us a joint controller with a Merchant, with the Store Platform or with Google. If a Merchant gives us an instruction we consider to infringe data protection law, we will inform the Merchant and may suspend execution of that instruction, under Article 28(3) GDPR.
6. Visitor data: exactly what is stored
For each consent-related event the App stores one row, containing the following and nothing else:
| Data element | Description and example |
|---|---|
| Consent identifier | A pseudonymous, random identifier generated by the Store Platform. It is not created by us and is not derived from any identifying attribute of the Visitor. |
| Action | One of: banner displayed, accepted everything, refused everything, chose by category. |
| Three yes-or-no values | Preferences, statistics, marketing: allowed or not. |
| Region code | An ISO 3166-2 code, for example “RO”, “ROMS” or “DE”. |
| Page path | The path of the page on which the banner was shown, for example /collections/all. |
| Banner text version | The version of the wording that was displayed. |
| Date and time | The moment of the event. |
| Store domain | The store on which the event occurred. |
Purposes
- To give effect to the Visitor’s choice, by transmitting it to Google Consent Mode v2 and to the Store Platform.
- To enable the Merchant to evidence the consent obtained, through the register and its CSV export.
- To produce the aggregated statistics shown to that same Merchant.
- To let the Merchant see where and under which wording consent was collected, for example to detect a misconfigured page or outdated text.
Legal basis
As stated in section 5, the Merchant is the controller and therefore determines and documents the legal basis. We do not determine it. Typically a Merchant relies on Article 6(1)(c) GDPR, compliance with the legal obligation under Article 7(1) GDPR to be able to demonstrate that the data subject consented, and/or Article 6(1)(f) GDPR, its legitimate interest in operating a functioning consent mechanism and keeping proof of the choices made. Our own processing of Visitor Data has no independent legal basis, because we process it only as processor.
Pseudonymous nature of the records
A Consent Record contains no direct identifier of the Visitor. The consent identifier is a random value generated by the Store Platform. We hold no key, table or additional dataset that would let us link it to a named individual, an email address, an order or a customer account. We nevertheless treat Consent Records as personal data and apply this Policy to them in full.
The region code identifies a country or a country subdivision. It is not a precise location, not a postal address, not GPS coordinates and not an IP address.
7. Merchant data: exactly what is stored
| Data element | Purpose | Legal basis |
|---|---|---|
| Store domain | Identifies the installation and attributes records, settings and statistics to the correct store. | Article 6(1)(b) GDPR — performance of the contract |
| Access token issued by the Store Platform | Lets the App communicate with the store and operate. | Article 6(1)(b) GDPR — performance of the contract |
| Banner settings chosen by the Merchant | Stores the chosen configuration so the banner behaves as set. These are held as an application-owned metafield on the the store platform platform, not in our own database. | Article 6(1)(b) GDPR — performance of the contract |
| Server access logs (see section 10) | Security and troubleshooting. | Article 6(1)(f) GDPR — legitimate interest |
Where a Merchant is a sole trader, or where these items can otherwise be associated with an identifiable individual, we treat them as personal data and this Policy applies to them in full.
The access token is a credential. It is stored solely to operate the App, is never exported, is never shared with anyone outside the sub-processors in section 16, and is deleted on uninstall.
8. Permissions and the limits of our access
One permission only. The only permission the App requests from the Store Platform is read access to themes. It is used exclusively to tell the Merchant whether the banner is active in the published theme, and for nothing else.
No access to protected customer data. The App does not request and does not have access to protected customer data. Within the Store Platform’s classification, the App operates at Level 0 — no customer data.
The App does not read orders, customers, carts, checkouts, payment data, fulfilment data or any customer account. It cannot do so, because it does not hold the permissions required.
9. What the App does not collect or do
The consent register described in section 6 contains none of the following, under any circumstances and through any mechanism:
- names;
- email addresses;
- telephone numbers;
- IP addresses;
- order data of any kind;
- customer accounts or any data from them;
- device identifiers;
- browser fingerprinting data of any kind.
The App does not:
- carry out profiling;
- track a Visitor across websites;
- set any advertising cookie of its own;
- make automated decisions producing legal effects;
- sell data;
- share data with advertising networks;
- use data to train any model.
These statements are unconditional. They are not limited to a particular plan, tier, configuration or region, and no setting a Merchant may choose waives them. If any of them ceases to be accurate, this Policy will be amended under section 23 before the change takes effect.
One honest qualification. The statement above concerns the data the App itself records. Like any service reached over the internet, the App is served by a hosting provider whose ordinary access logs do contain the requesting IP address. That is described separately and in full in section 10, so that nothing here can be read as a broader claim than we can keep.
10. Server access logs
Our hosting provider keeps ordinary access logs for every request reaching the App, in the same way as any web server. Each entry contains the request time, the method and path, the response status and duration, the requesting IP address and the browser user-agent string.
These logs are generated by the hosting infrastructure, not by the App’s own code. They are used only to keep the Service secure, available and debuggable. They are not linked to Consent Records, are not used to identify Visitors, are not used for analytics, statistics, advertising or profiling, and are not disclosed to anyone outside the sub-processors listed in section 16, one of which generates and holds them.
Retention: 7 days, after which they expire automatically at the hosting provider. The legal basis is Article 6(1)(f) GDPR, our legitimate interest in the security and availability of the Service.
11. The consent state sent to Google
When a Visitor makes a choice, and for the default state that applies before any choice, the App transmits the consent state only to Google Consent Mode v2: granted or denied, per category, across all seven signals, namely ad_storage, ad_user_data, ad_personalization, analytics_storage, functionality_storage, personalization_storage and security_storage.
We transmit to Google no identifier and no personal data: no consent identifier, no page path, no region code, no store domain, no name, no email address, no IP address — nothing beyond the granted or denied state per category.
What Google does afterwards, and any processing Google performs in connection with the Merchant’s own Google tags, products or accounts, is governed by the Merchant’s own agreements with Google. We are not a party to those agreements and have no control over that processing.
12. The consent state sent to the store platform
The App also transmits the Visitor’s choice to the Store Platform’s customer privacy interface, so that the platform and any other app or tag relying on it can honour that choice. This transmission consists of the consent state. The Store Platform’s own processing of that signal is governed by its own terms and privacy documentation.
13. Aggregated statistics
The App shows each Merchant statistics about that Merchant’s own store only: banner impressions, response rate, acceptance rate, and a breakdown by region. They are derived from the Consent Records of that store and are presented as counts and rates, not as records about identifiable individuals.
We do not build, publish or sell cross-merchant benchmarks, industry reports or any other aggregated product derived from Merchants’ data.
14. Retention periods
| Data | Kept for | Then |
|---|---|---|
| Consent Records | 12 months from the event | Deleted |
| Session (including the access token) | Until the App is uninstalled | Deleted |
| Server access logs | 7 days | Expire at the hosting provider |
On expiry. Deleted Consent Records are no longer available in the register, in CSV exports or in statistics. A Merchant who needs to keep evidence of consent for longer than 12 months must export the register before expiry; once records are deleted we cannot restore them.
On uninstall. The session is deleted and the App ceases to have any access to the store. The banner configuration is held as an application-owned metafield on the store platform and is removed there when the installation ends. The App also responds to the Store Platform’s shop data erasure notification, described in section 15.
Backups. Our hosting provider takes routine database backups for disaster recovery. Data deleted under this section may therefore persist in those backups for a short period until the backups themselves expire in the ordinary rotation. Such backups are not used for any other purpose and are not accessible to anyone outside the sub-processors listed in section 16.
15. Mandatory platform notifications
The App responds to the Store Platform’s mandatory compliance notifications: the customer data requestnotification, the customer data erasure notification, and the shop data erasure notification sent after uninstall.
Merchants should note the practical consequence of section 9: because the App holds no name, email address, telephone number, IP address in its register, order data, customer account or device identifier, a customer data request or customer erasure notification will generally find no identifying customer data in the App to return or to erase.
16. Sub-processors and location of the data
| Sub-processor | Role | Location of processing |
|---|---|---|
| Railway | Hosting and database | European Union region |
| The store platform provider | The platform on which the App runs | As governed by the store platform’s own terms and privacy documentation |
The database in which Consent Records, store settings and sessions are stored is hosted in a European Union region.
Apart from these sub-processors, we disclose data to no one. There is no advertising network, no data broker, no analytics vendor, no email provider and no artificial-intelligence vendor in our processing chain for the App. We remain responsible to Merchants for the processing carried out by our sub-processors in providing the Service.
17. International transfers
Hosting and the database are located in a European Union region. We do not transfer Visitor Data or Merchant Data outside the European Economic Area for any purpose of our own.
Two points fall outside our control and require attention:
- The Store Platform. The App runs on the store platform. Any processing or transfer carried out by the store platform as part of operating its platform is governed by the store platform’s own terms, privacy documentation and data processing addendum, to which the Merchant is a party.
- Google. As stated in section 11, we transmit only the granted or denied consent state, with no identifier and no personal data. Any further processing or transfer by Google is governed by the Merchant’s own agreements with Google.
If we ever intend to process data outside the European Economic Area, this Policy will be amended under section 23 before that change takes effect, and the transfer mechanism relied on will be stated.
18. Rights and how to exercise them
Subject to the conditions and exceptions in the GDPR, data subjects have the right of access (Article 15), to rectification (Article 16), to erasure (Article 17), to restriction of processing (Article 18), to data portability (Article 20), to object to processing based on legitimate interests (Article 21), to withdraw consent at any time where processing is based on consent (Article 7(3)), and to lodge a complaint with a supervisory authority (Article 77).
If you are a visitor of a store
Address your request to the Merchant operating that store, not to us. The Merchant is the controller of Visitor Data and its contact details are published in that store’s own privacy policy and legal pages. Where a Merchant forwards us such a request as its processor, we assist the Merchant in responding under Article 28(3)(e) GDPR. We do not respond directly to Visitors about a Merchant’s store data, because we are not entitled to do so.
A practical limit, stated plainly
Because the register holds no name, email address, telephone number, IP address, order data, customer account or device identifier, we have no means of identifying which Consent Record, if any, relates to a given individual. The consent identifier is a random pseudonym generated by the Store Platform and we hold no key linking it to a person. In relation to Consent Records we are therefore generally unable to identify the data subject within the meaning of Article 11 GDPR, and the rights of access, rectification, erasure, restriction and portability may be impossible to exercise against the record itself. A Visitor who can supply the exact consent identifier may ask the Merchant to have the corresponding record located. In any event, all Consent Records are deleted after 12 months.
Changing your choice as a visitor
A Visitor who wishes to change a previous choice can do so through the consent banner, or through the floating consent control that the App leaves on the page when the Merchant has enabled it. Changing the choice creates a new Consent Record reflecting the new state.
If you are a merchant
For the Merchant Data for which we are controller, send your request by email to contact@transilvaniamarketing.ro. We respond under Article 12(3) GDPR, without undue delay and in any event within one month of receipt, extendable by two further months where necessary, in which case we will tell you of the extension and the reasons for it within the first month.
Where we have reasonable doubts about the identity of the person making a request, we may ask for additional information needed to confirm it, under Article 12(6) GDPR, and will not use that information for any other purpose. We charge no fee, except where Article 12(5) GDPR permits it for manifestly unfounded or excessive requests.
19. Security measures
- Encrypted communication. All traffic to and from the App uses HTTPS/TLS.
- Restricted database access. Access to the database is limited.
- No directly identifying data in the register. The consent register is designed to contain no name, email address, telephone number or IP address, which materially reduces the impact of any incident affecting it.
Data minimisation is itself the most important protective measure here: data that is not held cannot be compromised. The exclusions in section 9 are a design choice, not a configuration option.
No transmission over the internet and no storage system can be guaranteed to be absolutely secure. We do not claim absolute security; we claim the measures set out above.
20. Personal data breaches
Where we act as processor (Visitor Data), if we become aware of a personal data breach we will notify the affected Merchant without undue delay under Article 33(2) GDPR, with the information reasonably available to us, so that the Merchant can assess its own obligations towards its supervisory authority (Article 33(1) GDPR, within 72 hours where feasible) and towards affected data subjects (Article 34 GDPR).
Where we act as controller (Merchant Data), we will assess the breach and, where it is likely to result in a risk to the rights and freedoms of natural persons, notify the competent supervisory authority under Article 33(1) GDPR and, where the risk is high, the affected individuals under Article 34 GDPR.
Notifications are sent by email to the address associated with the Merchant’s installation and published on our website.
21. Children and minors
The App is a business tool, intended for merchants operating online stores, and is not directed at children.
The App does not knowingly process data of children and collects none of the elements by which a child could be identified. It has no means of determining a Visitor’s age, and performs no age verification, no age inference and no age-based targeting.
Where a Merchant’s store is directed at children, it is for the Merchant, as controller, to assess the applicable rules on the consent of minors, including Article 8 GDPR and the national age threshold in the relevant Member State.
22. No automated decision-making or profiling
The App carries out no profiling within the meaning of Article 4(4) GDPR, and no automated decision-making producing legal effects or similarly significantly affecting a data subject within the meaning of Article 22 GDPR.
The App does not score, segment, rank, categorise or predict anything about an individual. Recording the yes-or-no state of three consent categories is the execution of the Visitor’s own choice; it is not an inference about the Visitor.
23. Changes to this Policy
We may amend this Policy, for example to reflect a change in the App’s functionality, in our sub-processors, in the location of the data, or in applicable law. Each version carries a version number and a last-updated date, shown at the top of this page.
Where an amendment materially affects the processing of personal data — in particular any change to the data categories in sections 6 or 7, to the exclusions in section 9, to the retention periods in section 14, to the sub-processors in section 16 or to the location of the data in section 17 — the amended Policy will be published before the change takes effect.
Continued use of the App after the effective date of an amended version constitutes acceptance of that version by the Merchant. A Merchant who does not accept an amendment may uninstall the App, in which case the deletion described in section 14 applies.
24. Contact
TRANSYLVANIA MARKETING LTD SRL
Str. Crișanei 2, 550012 Sibiu, România
CUI 43230933
Visitors of a store should first read section 18: their request must be addressed to the Merchant operating that store.
25. Competent supervisory authority
We are established in Romania. Our supervisory authority is:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania
+40 318 059 211 · +40 318 059 212
Under Article 77 GDPR a data subject may also lodge a complaint with the supervisory authority of the Member State of their habitual residence, place of work or place of the alleged infringement. Nothing in this Policy restricts the right to an effective judicial remedy under Articles 78 and 79 GDPR.
End of Policy · version 1.2