Privacy Policy
Last updated: 2026-07-22 · The English version is authoritative.
This policy explains how REDLINE MANAGEMENT LTD (the "Controller"), operator of ConsentKit (consentkit.cc), processes personal data under the EU GDPR (2016/679) and the UK GDPR.
1. Data controller
REDLINE MANAGEMENT LTD (company number 15938927, registered in England & Wales; VAT GB475397543), registered address: 35 Goldfinch Drive, Sandy, SG19 2SA, United Kingdom. Website: https://consentkit.cc. Privacy contact: [email protected] (response within 30 days).
2. What data we process — on this website
This site runs our own ConsentKit banner with Google Consent Mode v2 in default-denied state: no analytics or marketing cookies are set before your consent.
Signup data: if you submit the signup form, we process the data you provide (company, name, e-mail, website domain, plan, message, interface language) solely to contact you about your ConsentKit setup and to provide the service.
3. What we process — as a processor for our clients
For client websites we operate a consent audit log (proof of consent under GDPR Art. 7): consent decision and categories, banner version, language, page URL, user agent and a salted SHA-256 hash of the IP address. Raw IP addresses are never stored. In this processing we act as a processor on behalf of the client (the controller of their own website); a data processing agreement (DPA) is available on request.
4. Purpose and legal basis
Providing the service (performance of contract), billing (legal obligation), service security and abuse prevention such as rate limiting (legitimate interest), and — with consent — analytics on this website (consent, via our own banner).
5. Processors and sub-processors
Hetzner Online GmbH (hosting, EU), Cloudflare (CDN/security), Tragly (server-side tag routing of consent signals), Stripe (payments/invoicing, once billing launches), Google (analytics on this site, only with consent). Each acts under its own privacy policy and a data processing agreement.
6. Retention
Consent-log records are retained for 3 years (GDPR proof-of-consent period) and then deleted automatically. Signup data is kept until the request is handled and, for clients, for the duration of the contract plus statutory retention (e.g. invoicing). Account and configuration data are deleted on contract end, except where retention is legally required.
7. Your rights
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Consent-log erasure requests are handled via your anonymous consent ID. Send requests to [email protected] — response within 30 days. You may also lodge a complaint with a supervisory authority (UK: ICO; in the EU, your local authority — e.g. NAIH in Hungary).
8. Cookies
Cookie use is described in the separate Cookie Policy.