Privacy Policy
Table of Contents
1. Data Controller
This Privacy Policy explains how STENVARD s.r.o. ("Conseto," "we," "us," or "our") collects, uses, discloses, and protects your personal data when you visit our websites (conseto.io, app.conseto.io, conseto.io/docs), use the Conseto mobile app for iOS and Android, use our Services, or otherwise interact with us.
Data Controller:
STENVARD s.r.o.
IČO: 57 713 880
Solivarská 14E, 080 05 Prešov, Slovak Republic
Data protection contact: privacy@conseto.io
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Slovak Data Protection Act (Zákon č. 18/2018 Z. z.), and other applicable data protection laws.
We have not designated a data protection officer under Article 37 GDPR. For any question about personal data, contact us at privacy@conseto.io.
Important distinction: This Privacy Policy covers how we handle your data as our customer. When you use Conseto to collect data from your website visitors, you are the data controller and we act as data processor under our Data Processing Agreement.
2. Data We Collect
2.1 Account Data (provided by you)
- Full name and email address
- Company name and website URL
- Password (stored as bcrypt hash, never in plaintext)
- Billing details (company name, company ID, VAT ID and address) that you enter in the app. We check the VAT ID in the European Commission's VIES system. We do not take card payments yet; we issue invoices in our internal invoicing system
- Communication preferences and settings
2.2 Usage Data (collected automatically)
- IP address and approximate geolocation (country/city level)
- Browser type, version, and operating system
- Pages visited within our dashboard and marketing site
- Feature usage, click patterns, and session duration
- Referral source and UTM parameters
- Device type and screen resolution
2.3 Analytics Data (processed on your behalf)
When you install the Conseto SDK on your website, we process the following data from your website visitors as your data processor:
- Pseudonymous visitor identifiers (session and visitor tokens)
- Page views, custom events, and e-commerce events
- Consent preferences and consent banner interactions
- IP address: we do not store it in the database; we store only a one-way fingerprint of it with a component that changes every calendar month, and the country, region, city, approximate coordinates, time zone and network provider derived from it. We determine the location on our own servers from an open IP location database; we do not send the IP address to anyone for this. IP location data: DB-IP (db-ip.com), licensed under CC BY 4.0
- User agent, device, browser, and screen information
- Referral source, UTM parameters, and landing pages
- Scroll depth, time on page, file downloads, outbound clicks
- Core Web Vitals (LCP, INP, CLS) and TTFB performance metrics
We do not use this visitor data for our own purposes. It is processed solely to provide the analytics Services to you.
2.4 Cookie and Consent Data
Through our consent management features, we process consent records including timestamp, consent choices, consent banner configuration, and browser information at the time of consent. This data serves as your compliance record.
2.5 AI Processing Data
The Ask feature answers your questions about your site's data with Claude, a language model by Anthropic, which Amazon Web Services (Amazon Bedrock) runs on our behalf in European Union regions. Requests are sent from the Paris region, and AWS may process them in another EU region; they do not leave the EU. We send the model your question, the earlier questions and answers of the same conversation, details of your project (its name, domain, goals, conversions, decisions, the latest diary entries, and the layout and consent rates of your consent banner), the screen you ask from, and the results of queries on your site's data. A query result may list individual visits or events. We mask email addresses in query results and in the earlier questions and answers, and query results never contain IP addresses. The question you are asking goes to the model as you wrote it, so please do not put details about people into a question when the answer does not need them. Data is sent to AWS, not directly to Anthropic: Anthropic does not receive your questions or answers, and neither AWS nor Anthropic uses them to train models.
Before your first question in the app, we ask for your consent. Without it, the app sends no question to the model. If you dictate a question, speech is turned into text by your browser's speech recognition; some browsers (for example Google Chrome) process it on their maker's servers.
If you connect your own AI assistant to your project through our MCP server, its questions to the ask tool are answered by the same model on Amazon Bedrock. We send the model the question and the results of queries on your site's data, with email addresses masked and without IP addresses; the earlier conversation, project details and the screen are not sent, and the question is not saved as a conversation. The answer and the queries it stands on go back to your assistant. The consent in the app does not apply to these questions, because you send them from your own AI client.
The legal document generator in the app writes a document for your website (for example a privacy policy or terms and conditions) with the same model on Amazon Bedrock. We send the model the type of document, the regions and language you choose and the details you enter: your company name, website and contact email and, if you add them, address, phone, data protection officer, cookie categories, third-party services, retention period and the features of your website. We store the generated document together with the request sent to the model in your project.
2.6 Saved Conversations and Decisions
The app saves your Ask conversations (questions, answers and the query results the answers stand on), so that you can come back to them and an answer is not lost when you close the app. Only you can see a conversation, and only while you have access to the project. We keep conversations no longer than your plan keeps analytics data, and all your conversations are deleted with your account. When a visitor of your site asks for erasure and you carry it out in Conseto, we also delete the saved conversations and decisions of that project that mention the visitor's identifier.
A decision you save from a conversation, or one you accept, complete or dismiss, belongs to the project: everyone with access to the project can see it. For a completed decision, we compare the metric it stands on over the seven days before and the seven days after it was completed. If you delete your account, the decisions in your own projects are deleted with those projects; decisions you saved in someone else's project stay with that project without saying who saved them.
2.7 Mobile App
The Conseto mobile app for iOS and Android shows the same dashboard as app.conseto.io. If you turn on phone notifications in the app, we store your device's notification token with your account, together with the platform (iOS or Android), the app version and the app's language, so that we can send you notifications in your language. Notifications are delivered through Apple (Apple Push Notification service, for iPhone and iPad) and Google (Firebase Cloud Messaging, for Android). They receive the device token, the title and text of each notification (for example, the number of new conversions on your site) and the screen of the app it opens, with your project's identifier. We delete the token when you turn notifications off or sign out of the app on that phone, and when you delete your account; a token that Apple or Google report as no longer valid is no longer used. We keep a record of whether each notification was delivered for 30 days.
If you turn on the app lock, Face ID, Touch ID or your fingerprint is checked by your phone's operating system. The app only learns whether the check succeeded, and no biometric data ever leaves your phone.
3. Legal Basis for Processing
We process your personal data under the following legal bases (GDPR Article 6):
| Legal Basis | Processing Activity |
|---|---|
| Contract Performance Art. 6(1)(b) | Account creation, service delivery, billing, support, API access, saved Ask conversations and decisions, questions through the MCP server, the legal document generator |
| Consent Art. 6(1)(a) | Marketing emails, non-essential cookies on conseto.io, newsletter, sending your Ask questions in the app and the related data to the AI model |
| Legitimate Interest Art. 6(1)(f) | Product improvement, security monitoring, fraud prevention, aggregate analytics of our own platform |
| Legal Obligation Art. 6(1)(c) | Tax records, regulatory compliance, responding to legal requests |
Where consent is the legal basis, you can withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal. For data about your site's visitors that appears in query results in Ask or through the MCP server, we act as your processor. We need your account data to conclude and perform the contract; without it, an account cannot be created. Our legitimate interest is operating the service securely and improving it. We make no automated decisions that would have legal effects on you or similarly significantly affect you.
4. How We Use Your Data
- Service Delivery: To provide, operate, maintain, and improve the Conseto platform, dashboard, APIs, and SDK
- Account Management: To create and manage your account, authenticate access, and invoice you
- Communications: To send service updates, security alerts, billing notifications, and support responses, and the phone notifications you turn on in the mobile app
- Product Improvement: To understand how customers use our platform, identify bugs, and prioritize features (using aggregated, anonymized data)
- Security: To detect and prevent fraud, abuse, and unauthorized access to the Services
- Compliance: To comply with legal obligations, respond to legal requests, and enforce our Terms
- Marketing: With your consent, to send product announcements, newsletters, and promotional content. You can unsubscribe at any time
- AI Features: To answer your questions in Ask (in the app, with your consent) and through our MCP server, and to write the legal documents you request, using the data described in section 2.5
We do not sell your personal data to third parties. We do not use your analytics data (visitor data) for our own advertising or profiling purposes.
5. Data Sharing and Sub-processors
We share personal data only with the recipients listed below. Sub-processors are bound by data processing agreements; recipients marked as an independent controller process data under their own terms.
5.1 Sub-processors and Other Recipients
| Recipient | Purpose | Location |
|---|---|---|
| Vercel Inc. | Website and dashboard hosting | EU (Frankfurt, fra1) |
| Fly.io | API gateway and audit engine hosting | EU (Frankfurt) |
| Supabase | PostgreSQL database | AWS eu-central-1 (Frankfurt) |
| Cloudflare | Encrypted database backups (R2 storage) and Turnstile bot protection on forms | Backups: EU (R2, EU jurisdiction); Turnstile: global network |
| Amazon Web Services (SES) | Transactional email delivery (verification, password reset, notifications) | EU region |
| Amazon Web Services (Bedrock) | AI models (Anthropic Claude) used for audits, for Ask (in the app and through the MCP server) and for the legal document generator: your questions, the conversation, project details, query results (email addresses masked) and the company details you enter for a document. Data from Ask and the generator is sent to AWS, not directly to Anthropic, and is not used to train models | EU regions (requests from Paris, eu-west-3) |
| Anthropic, PBC | Only for a website audit, when the audit engine has no access to Amazon Bedrock: a screenshot of the audited public page | USA |
| Apple (Apple Push Notification service) | Delivery of phone notifications to iPhone and iPad: the device token and the notification | Global (only if you turn on notifications) |
| Google (Firebase Cloud Messaging) | Delivery of phone notifications to Android phones: the device token and the notification | Global (only if you turn on notifications) |
| Kovrin, our internal invoicing system | Issuing and recording invoices (Vercel hosting and Supabase database) | EU (Frankfurt) |
| External accounting service | Bookkeeping, invoices | Slovak Republic |
| Revolut Business | Payment processing, only for card payments, which we do not offer yet | EU (Lithuania) |
| Search Console and GA4 API access, only for properties you connect yourself | Global (customer-controlled) | |
| Google (Google Analytics 4 on conseto.io) | Measuring visits to our website conseto.io (see section 9.2) | Global |
| Google (website icon service), independent controller | Showing your website's icon in the app: the device's IP address and the website's domain | Global |
| OpenStreetMap Foundation, independent controller | Map tiles in the traffic overview: the device's IP address | United Kingdom |
5.2 Other Disclosures
We may disclose personal data when required by law, to respond to valid legal process (subpoena, court order), to protect the rights and safety of Conseto or others, or in connection with a merger, acquisition, or sale of assets (with advance notice where feasible).
6. International Data Transfers
We store your account data and analytics data in the European Union: hosting (Vercel, Fly.io) and the database (Supabase, on AWS) are in Frankfurt, transactional email (AWS SES) is sent from an EU region, and AI processing (AWS Bedrock) runs in European Union regions, with requests sent from the Paris region. Some of our sub-processors (Vercel Inc., Fly.io, Supabase, Cloudflare, Inc. and Amazon Web Services) are companies based in the USA or with a parent company there and may access data from the USA as well, for example for support or operations; Cloudflare Turnstile processes the IP address and browser data in its global network. These transfers rely on Commission Decision (EU) 2023/1795 for companies certified under the EU-U.S. Data Privacy Framework and otherwise on the standard contractual clauses under Commission Implementing Decision (EU) 2021/914.
If you turn on phone notifications in the mobile app, the device token and each notification go to Apple (for iPhone and iPad) or Google (for Android), which deliver them through their own notification services and may process them outside the EU.
Where you connect your own Google Search Console or GA4 properties, the resulting data transfer is between you and Google under Google's own terms and is outside our sub-processor chain. Google (Google Analytics 4 on conseto.io and the website icon service) may process data outside the EU as well; the OpenStreetMap Foundation is based in the United Kingdom, for which the Commission has adopted an adequacy decision. For transfers outside the EEA we use appropriate safeguards, in particular:
- Standard Contractual Clauses (SCCs) adopted by the European Commission (2021/914)
- Transfer Impact Assessments where required
- Data minimization before transfer (in Ask, email addresses in query results and in the earlier questions and answers are masked before they reach the AI model, and query results never contain IP addresses)
- Adequacy decisions, including the EU-U.S. Data Privacy Framework, where applicable
You may request a copy of the relevant safeguards by contacting privacy@conseto.io.
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
| Data Type | Retention Period |
|---|---|
| Account data | Duration of account; deleted immediately when you delete your account (see below) |
| Analytics data (Free plan) | 30 days rolling |
| Analytics data (Starter plan) | 365 days rolling |
| Analytics data (Business plan) | 730 days rolling |
| Analytics data (Enterprise plan) | Unlimited (as agreed in contract) |
| Saved Ask conversations | No longer than your plan keeps analytics data (Free 30 days, Starter 365 days, Business 730 days, Enterprise until you delete your account); always deleted with your account |
| Record of your consent to AI in Ask (wording, language and time) | Until you delete your account |
| Device token for phone notifications | Until you turn notifications off, sign out of the app on that phone, or delete your account; delivery records 30 days |
| Consent records | Records where a visitor saw the banner or made a choice: 3 years; other records: as long as analytics data; Enterprise: until deleted. All are deleted immediately when you delete the project or your account |
| Billing records | 10 years (Slovak tax law requirement) |
| Security scan results | As long as the project exists; deleted immediately with the project or your account |
| Server logs | 90 days |
When you delete your account, we delete its personal data from our active systems immediately and for good, in a single step. Encrypted database backups still contain it until they are rotated out under our regular backup schedule. Invoices are kept, detached from your account, because tax law requires us to keep accounting records (see Billing records above). Records of what you did in projects owned by other people stay with those projects, without your email address.
8. Your Rights
Under GDPR and applicable law, you have the following rights regarding your personal data:
- Right of Access (Art. 15): Request a copy of the personal data we hold about you, including the purposes of processing and categories of data
- Right to Rectification (Art. 16): Request correction of inaccurate personal data or completion of incomplete data. You can also update most information directly in your account settings
- Right to Erasure (Art. 17): Request deletion of your personal data where there is no compelling reason for continued processing. You can delete your account yourself, immediately and for good, in the web dashboard or the mobile app under Settings, Preferences
- Right to Restriction (Art. 18): Request that we limit the processing of your data while a complaint or dispute is resolved
- Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format (JSON/CSV). Data export is available in your dashboard
- Right to Object (Art. 21): Object to processing based on legitimate interests. We will stop processing unless we have compelling legitimate grounds
- Right to Withdraw Consent (Art. 7): Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing. You can withdraw your consent to sending questions to AI in the app under Settings, Preferences; Ask then sends no further question until you agree again
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority. In the Slovak Republic, this is the Úrad na ochranu osobných údajov Slovenskej republiky at dataprotection.gov.sk
To exercise any of these rights, write to us at privacy@conseto.io. We will respond without undue delay and at the latest within one month; for complex requests we may extend this by two further months and will tell you in advance. We may request identity verification before processing your request to protect your data from unauthorized access.
10. Children's Privacy
The Services are intended for businesses and are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that information promptly. If you believe we have inadvertently collected data from a minor, please contact us at privacy@conseto.io.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or business operations. When we make material changes, we will:
- Notify you via email at least 30 days before the changes take effect
- Post a prominent notice in the dashboard
- Update the "Effective" date at the top of this page
We encourage you to review this Privacy Policy periodically. The previous version of October 3, 2026 is here.
12. Data Protection Contact
If you have questions about this Privacy Policy, want to exercise your rights, or have concerns about our data practices, please contact us:
Data protection
You also have the right to lodge a complaint with the Slovak Data Protection Authority (Úrad na ochranu osobných údajov SR) or the supervisory authority in your country of residence.