CookieHub Docs

Security and data protection practices

How CookieHub handles personal data as a processor: what it processes, how it protects it, and where it is stored.

CookieHub processes personal data on behalf of its customers to provide and operate the consent management platform: recording and storing consent signals, managing customer accounts and configured services, delivering service-related communications and providing support. CookieHub is the data processor; the customer is the data controller. The data processing agreement sets out the terms under Article 28 GDPR.

CookieHub does not intentionally collect directly identifiable personal information about your website's visitors. What it holds about them is pseudonymous: the data needed to demonstrate a visitor's consent choices, as GDPR Article 7(1) requires, and only when the consent log is enabled for your domain.

Personal data processed

The categories of data subjects and personal data are set out in Annex 1 of the DPA:

CategoryData subjectsPersonal data
Website visitor data (pseudonymous)Visitors to the customer's websiteConsent token, anonymized IP address, URL at the time of consent, country code, user agent, date and time of consent
Customer account and contact dataDashboard users and customer contact personsName, email address, account credentials (hashed), service configuration data, communication records, billing-related contact information

No special categories of personal data are intentionally processed. Customers are responsible for ensuring that special category data is not transmitted to the service unless lawful and appropriate safeguards are in place.

The IP address in a consent log entry is stored with its last segment removed; see Anonymization of IP addresses. The consent cookie and the other items CookieHub stores in the visitor's browser are described in Cookies and storage used by CookieHub.

Personal data is retained for the duration of the service agreement and in accordance with documented retention settings; consent log entries are kept for 12 months. See Data retention.

Security and data protection practices

CookieHub implements appropriate technical and organisational measures in accordance with Article 32 GDPR. The practices are aligned with generally recognised information security standards, including ISO/IEC 27001 principles, and are applied uniformly across all customers. They include:

  • Encryption in transit (TLS)
  • Encryption at rest where applicable
  • Role-based access control
  • Infrastructure monitoring
  • Patch and vulnerability management
  • Segregated environments
  • Redundant hosting architecture

Primary application data, consent log data and encrypted backups are processed and stored in Germany, within the EEA. Where the data centres are, and which providers run them, is in Server locations and Sub-processors.

No customer-specific security controls or certifications are provided unless expressly agreed in writing.

HIPAA

CookieHub is not HIPAA certified. It does not store health-related data: what it holds about visitors is the pseudonymous consent data described above, and it follows the data protection practices listed here for all of it. Its hosting provider, Amazon Web Services, is HIPAA compliant.

International transfers

Some service providers operate outside the European Economic Area. Where personal data is transferred outside the EEA, appropriate safeguards under Chapter V GDPR, including Standard Contractual Clauses where applicable, are implemented. The providers and their countries are listed under Sub-processors.

On this page