Skip to content
Legal

Privacy Policy

Effective: October 3, 2026
STENVARD s.r.o.

This is the previous version of the Privacy Policy, effective from October 3, 2026 to October 5, 2026. Read the current version.

1. Data Controller

This Privacy Policy explains how STENVARD s.r.o. ("Conseto," "we," "us," or "our") collects, uses, discloses, and protects your personal data when you visit our websites (conseto.io, app.conseto.io, conseto.io/docs), use the Conseto mobile app for iOS and Android, use our Services, or otherwise interact with us.

Data Controller:

STENVARD s.r.o.

IČO: 57 713 880

Solivarská 14E, 080 05 Prešov, Slovak Republic

DPO Contact: privacy@conseto.io

We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Slovak Data Protection Act (Zákon č. 18/2018 Z. z.), and other applicable data protection laws.

Important distinction: This Privacy Policy covers how we handle your data as our customer. When you use Conseto to collect data from your website visitors, you are the data controller and we act as data processor under our Data Processing Agreement.

2. Data We Collect

2.1 Account Data (provided by you)

  • Full name and email address
  • Company name and website URL
  • Password (stored as bcrypt hash, never in plaintext)
  • Billing information (processed by Revolut; we do not store full card details)
  • Communication preferences and settings

2.2 Usage Data (collected automatically)

  • IP address and approximate geolocation (country/city level)
  • Browser type, version, and operating system
  • Pages visited within our dashboard and marketing site
  • Feature usage, click patterns, and session duration
  • Referral source and UTM parameters
  • Device type and screen resolution

2.3 Analytics Data (processed on your behalf)

When you install the Conseto SDK on your website, we process the following data from your website visitors as your data processor:

  • Pseudonymous visitor identifiers (session and visitor tokens)
  • Page views, custom events, and e-commerce events
  • Consent preferences and consent banner interactions
  • IP addresses (can be configured for anonymization)
  • User agent, device, browser, and screen information
  • Referral source, UTM parameters, and landing pages
  • Scroll depth, time on page, file downloads, outbound clicks
  • Core Web Vitals (LCP, FID, CLS) performance metrics

We do not use this visitor data for our own purposes. It is processed solely to provide the analytics Services to you.

2.4 Cookie and Consent Data

Through our consent management features, we process consent records including timestamp, consent choices, consent banner configuration, and browser information at the time of consent. This data serves as your compliance record.

2.5 AI Processing Data

The Ask feature answers your questions about your site's data with Claude, a language model by Anthropic, which Amazon Web Services (Amazon Bedrock) runs on our behalf in European Union regions. Requests are sent from the Paris region, and AWS may process them in another EU region; they do not leave the EU. We send the model your question, the earlier questions and answers of the same conversation, details of your project (its name, domain, goals, conversions, decisions, the latest diary entries, and the layout and consent rates of your consent banner), the screen you ask from, and the results of queries on your site's data. A query result may list individual visits or events. We mask email addresses in query results and in the earlier questions and answers, and query results never contain IP addresses. The question you are asking goes to the model as you wrote it, so please do not put details about people into a question when the answer does not need them. Data is sent to AWS, not directly to Anthropic: Anthropic does not receive your questions or answers, and neither AWS nor Anthropic uses them to train models.

Before your first question in the app, we ask for your consent. Without it, the app sends no question to the model.

If you connect your own AI assistant to your project through our MCP server, its questions to the ask tool are answered by the same model on Amazon Bedrock. We send the model the question and the results of queries on your site's data, with email addresses masked and without IP addresses; the earlier conversation, project details and the screen are not sent, and the question is not saved as a conversation. The answer and the queries it stands on go back to your assistant. The consent in the app does not apply to these questions, because you send them from your own AI client.

The legal document generator in the app writes a document for your website (for example a privacy policy or terms and conditions) with the same model on Amazon Bedrock. We send the model the type of document, the regions and language you choose and the details you enter: your company name, website and contact email and, if you add them, address, phone, data protection officer, cookie categories, third-party services, retention period and the features of your website. We store the generated document together with the request sent to the model in your project.

2.6 Saved Conversations and Decisions

The app saves your Ask conversations (questions, answers and the query results the answers stand on), so that you can come back to them and an answer is not lost when you close the app. Only you can see a conversation, and only while you have access to the project. We keep conversations no longer than your plan keeps analytics data, and all your conversations are deleted with your account. When a visitor of your site asks for erasure and you carry it out in Conseto, we also delete the saved conversations and decisions of that project that mention the visitor's identifier.

A decision you save from a conversation, or one you accept, complete or dismiss, belongs to the project: everyone with access to the project can see it. For a completed decision, we compare the metric it stands on over the seven days before and the seven days after it was completed. If you delete your account, the decisions in your own projects are deleted with those projects; decisions you saved in someone else's project stay with that project without saying who saved them.

2.7 Mobile App

The Conseto mobile app for iOS and Android shows the same dashboard as app.conseto.io. If you turn on phone notifications in the app, we store your device's notification token with your account, together with the platform (iOS or Android), the app version and the app's language, so that we can send you notifications in your language. Notifications are delivered through Apple (Apple Push Notification service, for iPhone and iPad) and Google (Firebase Cloud Messaging, for Android). They receive the device token, the title and text of each notification (for example, the number of new conversions on your site) and the screen of the app it opens, with your project's identifier. We delete the token when you turn notifications off or sign out of the app on that phone, and when you delete your account; a token that Apple or Google report as no longer valid is no longer used. We keep a record of whether each notification was delivered for 30 days.

If you turn on the app lock, Face ID, Touch ID or your fingerprint is checked by your phone's operating system. The app only learns whether the check succeeded, and no biometric data ever leaves your phone.

4. How We Use Your Data

  • Service Delivery: To provide, operate, maintain, and improve the Conseto platform, dashboard, APIs, and SDK
  • Account Management: To create and manage your account, authenticate access, and process payments
  • Communications: To send service updates, security alerts, billing notifications, and support responses, and the phone notifications you turn on in the mobile app
  • Product Improvement: To understand how customers use our platform, identify bugs, and prioritize features (using aggregated, anonymized data)
  • Security: To detect and prevent fraud, abuse, and unauthorized access to the Services
  • Compliance: To comply with legal obligations, respond to legal requests, and enforce our Terms
  • Marketing: With your consent, to send product announcements, newsletters, and promotional content. You can unsubscribe at any time
  • AI Features: To answer your questions in Ask (in the app, with your consent) and through our MCP server, and to write the legal documents you request, using the data described in section 2.5

We do not sell your personal data to third parties. We do not use your analytics data (visitor data) for our own advertising or profiling purposes.

5. Data Sharing and Sub-processors

We share personal data only with the following categories of recipients, each bound by data processing agreements:

5.1 Sub-processors

Sub-processorPurposeLocation
Vercel Inc.Website and dashboard hostingEU (Frankfurt, fra1)
Fly.ioAPI gateway and audit engine hostingEU (Frankfurt)
SupabasePostgreSQL databaseAWS eu-central-1 (Frankfurt)
CloudflareEncrypted database backups (R2 storage, EU jurisdiction) and Turnstile bot protection on formsEU (jurisdiction)
Amazon Web Services (SES)Transactional email delivery (verification, password reset, notifications)EU (Stockholm, eu-north-1)
Amazon Web Services (Bedrock)AI models (Anthropic Claude) used for audits, for Ask (in the app and through the MCP server) and for the legal document generator: your questions, the conversation, project details, query results (email addresses masked) and the company details you enter for a document. Data is sent to AWS, not directly to Anthropic, and is not used to train modelsEU regions (requests from Paris, eu-west-3)
Apple (Apple Push Notification service)Delivery of phone notifications to iPhone and iPad: the device token and the notificationGlobal (only if you turn on notifications)
Google (Firebase Cloud Messaging)Delivery of phone notifications to Android phones: the device token and the notificationGlobal (only if you turn on notifications)
Revolut BusinessPayment processingEU (Lithuania)
GoogleSearch Console and GA4 API access, only for properties you connect yourselfGlobal (customer-controlled)

5.2 Other Disclosures

We may disclose personal data when required by law, to respond to valid legal process (subpoena, court order), to protect the rights and safety of Conseto or others, or in connection with a merger, acquisition, or sale of assets (with advance notice where feasible).

6. International Data Transfers

Our infrastructure is located in the European Union: hosting (Vercel, Fly.io) and the database (Supabase, on AWS) in Frankfurt, transactional email (AWS SES) in Stockholm, and AI processing (AWS Bedrock) in European Union regions, with requests sent from the Paris region. Your account data and analytics data are stored within the EU.

If you turn on phone notifications in the mobile app, the device token and each notification go to Apple (for iPhone and iPad) or Google (for Android), which deliver them through their own notification services and may process them outside the EU.

Where you connect your own Google Search Console or GA4 properties, the resulting data transfer is between you and Google under Google's own terms and is outside our sub-processor chain. Should any other transfer outside the EEA become necessary, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission (2021/914)
  • Transfer Impact Assessments where required
  • Data minimization before transfer (in Ask, email addresses in query results and in the earlier questions and answers are masked before they reach the AI model, and query results never contain IP addresses)
  • Adequacy decisions where applicable

You may request a copy of the relevant safeguards by contacting privacy@conseto.io.

7. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:

Data TypeRetention Period
Account dataDuration of account; deleted immediately when you delete your account (see below)
Analytics data (Free plan)30 days rolling
Analytics data (Starter plan)365 days rolling
Analytics data (Business plan)730 days rolling
Analytics data (Enterprise plan)Unlimited (as agreed in contract)
Saved Ask conversationsNo longer than your plan keeps analytics data (Free 30 days, Starter 365 days, Business 730 days, Enterprise until you delete your account); always deleted with your account
Record of your consent to AI in Ask (wording, language and time)Until you delete your account
Device token for phone notificationsUntil you turn notifications off, sign out of the app on that phone, or delete your account; delivery records 30 days
Consent recordsRecords where a visitor saw the banner or made a choice: 3 years; other records: as long as analytics data; Enterprise: until deleted. All are deleted immediately when you delete the project or your account
Billing records10 years (Slovak tax law requirement)
Security scan resultsAs long as the project exists; deleted immediately with the project or your account
Server logs90 days

When you delete your account, we delete its personal data from our active systems immediately and for good, in a single step. Encrypted database backups still contain it until they are rotated out under our regular backup schedule. Invoices are kept, detached from your account, because tax law requires us to keep accounting records (see Billing records above). Records of what you did in projects owned by other people stay with those projects, without your email address.

8. Your Rights

Under GDPR and applicable law, you have the following rights regarding your personal data:

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you, including the purposes of processing and categories of data
  • Right to Rectification (Art. 16): Request correction of inaccurate personal data or completion of incomplete data. You can also update most information directly in your account settings
  • Right to Erasure (Art. 17): Request deletion of your personal data where there is no compelling reason for continued processing. You can delete your account yourself, immediately and for good, in the web dashboard or the mobile app under Settings, Preferences
  • Right to Restriction (Art. 18): Request that we limit the processing of your data while a complaint or dispute is resolved
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format (JSON/CSV). Data export is available in your dashboard
  • Right to Object (Art. 21): Object to processing based on legitimate interests. We will stop processing unless we have compelling legitimate grounds
  • Right to Withdraw Consent (Art. 7): Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing. You can withdraw your consent to sending questions to AI in the app under Settings, Preferences; Ask then sends no further question until you agree again
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority. In the Slovak Republic, this is the Úrad na ochranu osobných údajov Slovenskej republiky at dataprotection.gov.sk

To exercise any of these rights, contact our Data Protection Officer at privacy@conseto.io. We will respond within 30 days. We may request identity verification before processing your request to protect your data from unauthorized access.

9. Cookies on Conseto Websites

We use cookies and similar technologies on our own websites (conseto.io, app.conseto.io):

9.1 Essential Cookies

  • conseto_auth: Authentication token for dashboard (7 days)
  • conseto_session: Session identification (30 minutes)
  • conseto_consent: Stores your consent preferences (1 year)
  • __cf_bm: Cloudflare bot management (30 minutes)

9.2 Analytics Cookies

  • conseto_visitor: Anonymous visitor identifier (1 year, with consent)

We use our own Conseto platform for analytics on our websites. For detailed information, see our Cookie Policy.

9.3 Cookieless Tracking Option

The Conseto SDK supports a cookieless tracking mode that uses session-based fingerprinting without setting persistent cookies. This can be configured by our customers for their websites where cookie consent is not obtained.

10. Children's Privacy

The Services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that information promptly. If you believe we have inadvertently collected data from a minor, please contact us at privacy@conseto.io.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or business operations. When we make material changes, we will:

  • Notify you via email at least 30 days before the changes take effect
  • Post a prominent notice in the dashboard
  • Update the "Effective" date at the top of this page

We encourage you to review this Privacy Policy periodically. Your continued use of the Services after the effective date of changes constitutes acceptance.

12. Contact Our Data Protection Officer

If you have questions about this Privacy Policy, want to exercise your rights, or have concerns about our data practices, please contact us:

Data Protection Officer

support@conseto.io(general support)
STENVARD s.r.o., Solivarská 14E, 080 05 Prešov, Slovak Republic

You also have the right to lodge a complaint with the Slovak Data Protection Authority (Úrad na ochranu osobných údajov SR) or the supervisory authority in your country of residence.