Privacy Policy
Last updated: 26th June 2026
1. Who We Are
Obscurity Ltd is an analytics governance practice based in Dublin, Ireland. We help regulated organisations govern analytics and marketing tracking so measurement stays reliable and audit-ready. Obscurity Ltd is not required to designate a Data Protection Officer under Article 37 GDPR. For data protection queries, contact contact@consentmark.com.
- Company Registration No: 622475
- Email: contact@consentmark.com
Our role is set per activity, not per relationship. Obscurity Ltd is the controller of your account and billing records, of our platform audit log, and of any scan we run on our own initiative. Where we run the hosted Monitor for your organisation, or work inside your own GA4, Google Tag Manager or BigQuery, we act as your processor for that data under a Data Processing Agreement, available on request. Our test browser is not one of your visitors, so we set no cookies and collect no visitor identifiers, and where your own tags place personal data in a request URL we record it, treat it as personal data, and hold it for the period the agreement states.
2. What Data We Collect
We collect minimal data on this website. Visitors who decline consent experience no analytics tracking. Strictly necessary cookies (such as the cc_cookie consent cookie) may be set without consent as permitted under the ePrivacy Directive, as they are required for the website to function.
When consent is granted:
Consent is managed by our own self-hosted consent banner. There is no third-party consent provider, and no personal data is shared for consent management. When a visitor grants consent:
- Google Tag Manager (GTM) loads in the browser and activates analytics tags.
- Page views and navigation data are collected by Google Analytics 4 (GA4) via client-side JavaScript.
- GA4 applies automatic IP anonymisation. No raw IP addresses are stored by Google Analytics.
- GTM loads with all consent signals denied by default. Analytics tags within GTM only activate after consent is granted via our consent banner.
Google Calendar:
If you book an appointment, your name and email are processed by Google Workspace. Google Ireland Ltd is the data controller for EEA users.
Free Governance Scanner:
If you use our free governance scanner, we collect your email address to deliver the scan results. If you opt in to marketing communications via the scanner form, we may also send analytics governance insights and service updates. This data is processed on the basis of consent (you submit the form voluntarily, and marketing communications require a separate opt-in). Your address is deleted with the scan result it was used for, after thirteen months. Where you opted in to marketing, it is kept until you unsubscribe, and deleted after that. Scanner infrastructure is hosted on AWS (Dublin, EU).
Retention
Public scan results are kept for 395 days and then deleted. Results linked to an account are kept for 395 days and then deleted. Usage events are kept for 2 years. Consent proofs are kept for 6 years. The audit log is kept for 6 years. Data is deleted within 30 days of a request, confirmed in writing. Evidence records held under Object Lock are the exception: they cannot be deleted until their retention period ends, and we tell you the date. On termination, evidence is returned in an open format within 90 days, or deleted at your choice. Deletion is confirmed in writing.
3. Scanning Third-Party Websites
The scanner loads a publicly accessible page in a headless browser running in AWS eu-west-1 (Dublin), interacts with whatever consent banner the page presents, and records what the page sends to the browser. This section covers that processing. It is separate from the data we collect about you as a visitor to this website.
What the scan captures:
- The full URL of every network request the page makes, including query strings, and the request and response headers.
- Cookies and browser storage the page writes, including their values.
- Screenshots of the page as it rendered.
- A derived record: which analytics and advertising vendors were identified, the consent state at the moment each request fired, and the resulting grade.
The browser is synthetic. It is not a real visitor, it enters no personal data, and it holds no account on the scanned site. Any identifier that appears in a captured request is one the scanned site generated for that synthetic session.
Lawful basis: legitimate interests, Article 6(1)(f). The interest is in producing an independent, timestamped observation of what a publicly accessible website ships to a browser, which is the service. The observation is of a site's configuration rather than of an individual, and the scan carries no login and no personal data of the scanned organisation's own visitors.
Retention. The raw capture - full request URLs, headers, cookie values and screenshots - is deleted after thirteen months, whether or not the result is linked to an account. That figure is enforced in two places: the S3 lifecycle rule on the scanner artefact store, and the scan-evidence sweep in our retention job. The derived record - vendors identified, consent state, grade - is kept for 2,190 days, because it is the record of what an already-published grade was based on. Where a scan is preserved as a signed evidence bundle, the raw capture is held under S3 Object Lock and expires at 1,096 days. A legal hold suspends every one of these sweeps until it is lifted.
If you operate a scanned site and want to dispute a finding or ask for a result to be taken down, the route and who reads it are on the security page.
4. How We Use Your Data
- To understand how visitors use our website (aggregated analytics only)
- To respond to enquiries via email
- To schedule appointments
- To deliver governance scan results to the email address you provide
5. Legal Basis (GDPR Article 6)
- Analytics: consent (Article 6(1)(a))
- Enquiries: legitimate interest (Article 6(1)(f))
- Appointments: contract performance (Article 6(1)(b))
- Governance scanner: consent (Article 6(1)(a)) - scan results delivery and, where separately opted in, marketing communications
6. Third-Party Processors
This Website
| Processor | Purpose | HQ | Data Location |
|---|---|---|---|
| AWS Amplify (Amazon) | Website hosting / CDN | US (eu-west-1 region) | EU |
| Google Tag Manager | Tag management (consented) | US (Google Ireland Ltd for EEA) | US infrastructure |
| Google Analytics 4 | Website analytics (consented) | US (Google Ireland Ltd for EEA) | US infrastructure |
The ConsentMark Platform
We tell you before a sub-processor changes, and set no notice period. You may object on reasonable data protection grounds, and terminate without penalty if the objection cannot be resolved.
| Vendor | What they do | Where the data sits |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting: compute, database, object storage, content delivery, authentication, and the transactional email our alerts are sent through. | Ireland (eu-west-1) |
| Google Workspace (Google Ireland Ltd) | Our email and calendar: correspondence with you and the reports we send you. | EU (Google Ireland Ltd for EEA users) |
| GitHub Enterprise Cloud | Source code and continuous integration. No customer data. | US, standard contractual clauses |
| Functional Software, Inc. (Sentry) | Application error monitoring: stack traces and error metadata. | EU (Sentry EU region) |
| Stripe Payments Europe Ltd | Subscription billing and payment processing: your billing and payment details. | Ireland (EU) |
| Xero | Invoicing: your billing contact details. | EU (Ireland region) |
| PagerDuty | Incident paging for our on-call: alarm names only. | US, standard contractual clauses |
| Amazon Web Services (Amazon Bedrock) | Automated classification of third-party tags the signature registry does not recognise. Inference runs inside the EU under the existing AWS relationship and no separate vendor is engaged. | EU only, through the EU inference profile invoked from eu-west-1 |
| Anthropic | Our own development toolchain: test failures and code under review. Classification of tag and script content runs through Amazon Bedrock in the EU, and would reach this vendor only when that feature is switched on for your account. Zero-retention. | US, standard contractual clauses |
| OpenAI | Our own development toolchain: code generation and review passes. Classification of tag and script content runs through Amazon Bedrock in the EU, and would reach this vendor only when that feature is switched on for your account. Zero-retention. | US, standard contractual clauses |
A third-party tag we do not recognise may be classified automatically through Amazon Bedrock, invoked from Ireland and routed within the EU. Before any page-derived data is sent for classification, personal data and secrets in URLs, cookies, headers and script source are removed.
7. Data Transfers
GA4 data is processed by Google LLC, which is certified under the EU-US Data Privacy Framework (DPF). We acknowledge that transfer mechanisms may change and will update this policy accordingly. GA4 event data is retained for 2 months and user data is retained for 14 months. We minimise data collection by gating all analytics behind consent - no tracking occurs without explicit visitor approval.
8. Your Rights
Under the General Data Protection Regulation (GDPR), you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate personal data
- Request erasure of your personal data
- Restrict processing of your personal data
- Data portability
- Object to processing of your personal data
- Withdraw consent at any time via the cookie consent banner
You also have the right to lodge a complaint with the Data Protection Commission (Ireland).
9. Cookies
We use a self-hosted consent banner to manage cookie consent. A strictly necessary cookie (cc_cookie, storing your consent decision) is set without consent as permitted under the ePrivacy Directive. Without consent, no analytics or marketing cookies are set and no tracking occurs. With consent, analytics cookies are set by Google Tag Manager and Google Analytics.
Cookie Categories
| Category | Cookie Name | Provider | Purpose | Expiry | Type |
|---|---|---|---|---|---|
| Necessary | cc_cookie | Obscurity Ltd (first-party) | Stores your cookie consent decision and a random consent identifier | 6 months | HTTP cookie |
| Analytics | _ga | Google Analytics 4 | Registers a unique ID used to generate statistical data on site usage | 2 years | HTTP cookie |
| Analytics | _ga_* | Google Analytics 4 | Used by GA4 to maintain session state | 2 years | HTTP cookie |
10. Changes to This Policy
We may update this policy from time to time. The "last updated" date at the top of this page reflects the most recent revision.
11. Contact
If you have questions about this privacy policy or how we handle your data, please contact us:
- Email: contact@consentmark.com
- For data protection enquiries: contact@consentmark.com
- Address: Obscurity Ltd, 71 Lower Baggot Street, Dublin 2, D02 P593, Ireland