Skip to main content

Privacy Policy

Last updated: 26th June 2026

1. Who We Are

Obscurity Ltd is an analytics governance practice based in Dublin, Ireland. We help regulated organisations govern analytics and marketing tracking so measurement stays reliable and audit-ready. Obscurity Ltd is not required to designate a Data Protection Officer under Article 37 GDPR. For data protection queries, contact contact@consentmark.com.

  • Company Registration No: 622475
  • Email: contact@consentmark.com

Our role is set per activity, not per relationship. Obscurity Ltd is the controller of your account and billing records, of our platform audit log, and of any scan we run on our own initiative. Where we run the hosted Monitor for your organisation, or work inside your own GA4, Google Tag Manager or BigQuery, we act as your processor for that data under a Data Processing Agreement, available on request. Our test browser is not one of your visitors, so we set no cookies and collect no visitor identifiers, and where your own tags place personal data in a request URL we record it, treat it as personal data, and hold it for the period the agreement states.

2. What Data We Collect

We collect minimal data on this website. Visitors who decline consent experience no analytics tracking. Strictly necessary cookies (such as the cc_cookie consent cookie) may be set without consent as permitted under the ePrivacy Directive, as they are required for the website to function.

When consent is granted:

Consent is managed by our own self-hosted consent banner. There is no third-party consent provider, and no personal data is shared for consent management. When a visitor grants consent:

  • Google Tag Manager (GTM) loads in the browser and activates analytics tags.
  • Page views and navigation data are collected by Google Analytics 4 (GA4) via client-side JavaScript.
  • GA4 applies automatic IP anonymisation. No raw IP addresses are stored by Google Analytics.
  • GTM loads with all consent signals denied by default. Analytics tags within GTM only activate after consent is granted via our consent banner.

Google Calendar:

If you book an appointment, your name and email are processed by Google Workspace. Google Ireland Ltd is the data controller for EEA users.

Free Governance Scanner:

If you use our free governance scanner, we collect your email address to deliver the scan results. If you opt in to marketing communications via the scanner form, we may also send analytics governance insights and service updates. This data is processed on the basis of consent (you submit the form voluntarily, and marketing communications require a separate opt-in). Your address is deleted with the scan result it was used for, after thirteen months. Where you opted in to marketing, it is kept until you unsubscribe, and deleted after that. Scanner infrastructure is hosted on AWS (Dublin, EU).

Retention

Public scan results are kept for 395 days and then deleted. Results linked to an account are kept for 395 days and then deleted. Usage events are kept for 2 years. Consent proofs are kept for 6 years. The audit log is kept for 6 years. Data is deleted within 30 days of a request, confirmed in writing. Evidence records held under Object Lock are the exception: they cannot be deleted until their retention period ends, and we tell you the date. On termination, evidence is returned in an open format within 90 days, or deleted at your choice. Deletion is confirmed in writing.

3. Scanning Third-Party Websites

The scanner loads a publicly accessible page in a headless browser running in AWS eu-west-1 (Dublin), interacts with whatever consent banner the page presents, and records what the page sends to the browser. This section covers that processing. It is separate from the data we collect about you as a visitor to this website.

What the scan captures:

  • The full URL of every network request the page makes, including query strings, and the request and response headers.
  • Cookies and browser storage the page writes, including their values.
  • Screenshots of the page as it rendered.
  • A derived record: which analytics and advertising vendors were identified, the consent state at the moment each request fired, and the resulting grade.

The browser is synthetic. It is not a real visitor, it enters no personal data, and it holds no account on the scanned site. Any identifier that appears in a captured request is one the scanned site generated for that synthetic session.

Lawful basis: legitimate interests, Article 6(1)(f). The interest is in producing an independent, timestamped observation of what a publicly accessible website ships to a browser, which is the service. The observation is of a site's configuration rather than of an individual, and the scan carries no login and no personal data of the scanned organisation's own visitors.

Retention. The raw capture - full request URLs, headers, cookie values and screenshots - is deleted after thirteen months, whether or not the result is linked to an account. That figure is enforced in two places: the S3 lifecycle rule on the scanner artefact store, and the scan-evidence sweep in our retention job. The derived record - vendors identified, consent state, grade - is kept for 2,190 days, because it is the record of what an already-published grade was based on. Where a scan is preserved as a signed evidence bundle, the raw capture is held under S3 Object Lock and expires at 1,096 days. A legal hold suspends every one of these sweeps until it is lifted.

If you operate a scanned site and want to dispute a finding or ask for a result to be taken down, the route and who reads it are on the security page.

4. How We Use Your Data

  • To understand how visitors use our website (aggregated analytics only)
  • To respond to enquiries via email
  • To schedule appointments
  • To deliver governance scan results to the email address you provide
  • Analytics: consent (Article 6(1)(a))
  • Enquiries: legitimate interest (Article 6(1)(f))
  • Appointments: contract performance (Article 6(1)(b))
  • Governance scanner: consent (Article 6(1)(a)) - scan results delivery and, where separately opted in, marketing communications

6. Third-Party Processors

This Website

ProcessorPurposeHQData Location
AWS Amplify (Amazon)Website hosting / CDNUS (eu-west-1 region)EU
Google Tag ManagerTag management (consented)US (Google Ireland Ltd for EEA)US infrastructure
Google Analytics 4Website analytics (consented)US (Google Ireland Ltd for EEA)US infrastructure

The ConsentMark Platform

We tell you before a sub-processor changes, and set no notice period. You may object on reasonable data protection grounds, and terminate without penalty if the objection cannot be resolved.

VendorWhat they doWhere the data sits
Amazon Web Services EMEA SARLHosting: compute, database, object storage, content delivery, authentication, and the transactional email our alerts are sent through.Ireland (eu-west-1)
Google Workspace (Google Ireland Ltd)Our email and calendar: correspondence with you and the reports we send you.EU (Google Ireland Ltd for EEA users)
GitHub Enterprise CloudSource code and continuous integration. No customer data.US, standard contractual clauses
Functional Software, Inc. (Sentry)Application error monitoring: stack traces and error metadata.EU (Sentry EU region)
Stripe Payments Europe LtdSubscription billing and payment processing: your billing and payment details.Ireland (EU)
XeroInvoicing: your billing contact details.EU (Ireland region)
PagerDutyIncident paging for our on-call: alarm names only.US, standard contractual clauses
Amazon Web Services (Amazon Bedrock)Automated classification of third-party tags the signature registry does not recognise. Inference runs inside the EU under the existing AWS relationship and no separate vendor is engaged.EU only, through the EU inference profile invoked from eu-west-1
AnthropicOur own development toolchain: test failures and code under review. Classification of tag and script content runs through Amazon Bedrock in the EU, and would reach this vendor only when that feature is switched on for your account. Zero-retention.US, standard contractual clauses
OpenAIOur own development toolchain: code generation and review passes. Classification of tag and script content runs through Amazon Bedrock in the EU, and would reach this vendor only when that feature is switched on for your account. Zero-retention.US, standard contractual clauses

A third-party tag we do not recognise may be classified automatically through Amazon Bedrock, invoked from Ireland and routed within the EU. Before any page-derived data is sent for classification, personal data and secrets in URLs, cookies, headers and script source are removed.

7. Data Transfers

GA4 data is processed by Google LLC, which is certified under the EU-US Data Privacy Framework (DPF). We acknowledge that transfer mechanisms may change and will update this policy accordingly. GA4 event data is retained for 2 months and user data is retained for 14 months. We minimise data collection by gating all analytics behind consent - no tracking occurs without explicit visitor approval.

8. Your Rights

Under the General Data Protection Regulation (GDPR), you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate personal data
  • Request erasure of your personal data
  • Restrict processing of your personal data
  • Data portability
  • Object to processing of your personal data
  • Withdraw consent at any time via the cookie consent banner

You also have the right to lodge a complaint with the Data Protection Commission (Ireland).

9. Cookies

We use a self-hosted consent banner to manage cookie consent. A strictly necessary cookie (cc_cookie, storing your consent decision) is set without consent as permitted under the ePrivacy Directive. Without consent, no analytics or marketing cookies are set and no tracking occurs. With consent, analytics cookies are set by Google Tag Manager and Google Analytics.

Cookie Categories

CategoryCookie NameProviderPurposeExpiryType
Necessarycc_cookieObscurity Ltd (first-party)Stores your cookie consent decision and a random consent identifier6 monthsHTTP cookie
Analytics_gaGoogle Analytics 4Registers a unique ID used to generate statistical data on site usage2 yearsHTTP cookie
Analytics_ga_*Google Analytics 4Used by GA4 to maintain session state2 yearsHTTP cookie

10. Changes to This Policy

We may update this policy from time to time. The "last updated" date at the top of this page reflects the most recent revision.

11. Contact

If you have questions about this privacy policy or how we handle your data, please contact us:

  • Email: contact@consentmark.com
  • For data protection enquiries: contact@consentmark.com
  • Address: Obscurity Ltd, 71 Lower Baggot Street, Dublin 2, D02 P593, Ireland