Security and data protection practices
How CookieHub handles personal data as a processor: what it processes, how it protects it, and where it is stored.
CookieHub processes personal data on behalf of its customers to provide and operate the consent management platform: recording and storing consent signals, managing customer accounts and configured services, delivering service-related communications and providing support. CookieHub is the data processor; the customer is the data controller. The data processing agreement sets out the terms under Article 28 GDPR.
CookieHub does not intentionally collect directly identifiable personal information about your website's visitors. What it holds about them is pseudonymous: the data needed to demonstrate a visitor's consent choices, as GDPR Article 7(1) requires, and only when the consent log is enabled for your domain.
Personal data processed
The categories of data subjects and personal data are set out in Annex 1 of the DPA:
| Category | Data subjects | Personal data |
|---|---|---|
| Website visitor data (pseudonymous) | Visitors to the customer's website | Consent token, anonymized IP address, URL at the time of consent, country code, user agent, date and time of consent |
| Customer account and contact data | Dashboard users and customer contact persons | Name, email address, account credentials (hashed), service configuration data, communication records, billing-related contact information |
No special categories of personal data are intentionally processed. Customers are responsible for ensuring that special category data is not transmitted to the service unless lawful and appropriate safeguards are in place.
The IP address in a consent log entry is stored with its last segment removed; see Anonymization of IP addresses. The consent cookie and the other items CookieHub stores in the visitor's browser are described in Cookies and storage used by CookieHub.
Personal data is retained for the duration of the service agreement and in accordance with documented retention settings; consent log entries are kept for 12 months. See Data retention.
Security and data protection practices
CookieHub implements appropriate technical and organisational measures in accordance with Article 32 GDPR. The practices are aligned with generally recognised information security standards, including ISO/IEC 27001 principles, and are applied uniformly across all customers. They include:
- Encryption in transit (TLS)
- Encryption at rest where applicable
- Role-based access control
- Infrastructure monitoring
- Patch and vulnerability management
- Segregated environments
- Redundant hosting architecture
Primary application data, consent log data and encrypted backups are processed and stored in Germany, within the EEA. Where the data centres are, and which providers run them, is in Server locations and Sub-processors.
No customer-specific security controls or certifications are provided unless expressly agreed in writing.
HIPAA
CookieHub is not HIPAA certified. It does not store health-related data: what it holds about visitors is the pseudonymous consent data described above, and it follows the data protection practices listed here for all of it. Its hosting provider, Amazon Web Services, is HIPAA compliant.
International transfers
Some service providers operate outside the European Economic Area. Where personal data is transferred outside the EEA, appropriate safeguards under Chapter V GDPR, including Standard Contractual Clauses where applicable, are implemented. The providers and their countries are listed under Sub-processors.
Related pages
- Data processing agreement: the terms, the download, and what CookieHub commits to.
- Server locations and Sub-processors: where data is stored and who runs the infrastructure.
- Anonymization of IP addresses and Data retention.
- Cookies and storage used by CookieHub: what CookieHub itself sets in the visitor's browser.
- Consent log: browsing and exporting the consent records of your domain.