← ConsentPath

Privacy policy

This policy explains how ConsentPath (“ConsentPath”, “we”, “us”) collects, uses, and protects personal data when you use the ConsentPath EIA application and website, and the rights available to you under the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, and the Swiss Federal Act on Data Protection (FADP).

Last updated: 11 June 2026

1. Who is responsible

ConsentPath is the controller for personal data described in this policy, except where stated otherwise in section 2. You can reach us about anything in this policy at [email protected].

2. Controller and processor roles

ConsentPath is a collaborative authoring tool for Environmental Impact Assessment reports, used by project teams and consultancies (“customers”). Two roles apply:

3. Personal data we collect

We collect this data directly from you, from your activity in the app, or from the person who invited you to a workspace (your name and email address).

4. Purposes and legal bases

We process personal data for the following purposes and on the following legal bases (the equivalent provisions of the UK GDPR apply in the UK; under the Swiss FADP we process data in line with the principles of lawfulness, proportionality, and purpose limitation):

PurposeData usedLegal basis
Creating and operating your account; authenticating youName, email address, session dataPerformance of a contract (Art. 6(1)(b) GDPR)
Providing the service: workspaces, collaborative authoring, review, comments, exportsAccount data, workspace content, collaboration metadataPerformance of a contract (Art. 6(1)(b) GDPR)
Sending service emails (sign-in codes, invitations, mentions, notifications)Email address, notification contextPerformance of a contract (Art. 6(1)(b) GDPR)
Securing the service, preventing abuse, debugging and auditingLog data, IP address, audit eventsLegitimate interests (Art. 6(1)(f) GDPR) — keeping the service secure and reliable
Improving the product (aggregated, internal usage analysis)Usage events tied to your accountLegitimate interests (Art. 6(1)(f) GDPR) — understanding how the product is used
Responding to enquiries you send usYour contact details and the content of your messageLegitimate interests (Art. 6(1)(f) GDPR) — answering your request
Complying with legal obligations (e.g. accounting, lawful requests)Billing records, contractual recordsLegal obligation (Art. 6(1)(c) GDPR)

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms; you may object at any time (see section 10). We do not sell personal data and we do not use it for third-party advertising.

5. AI-assisted features

Some features (for example importing a PDF into structured chapters, or drafting assistance) send the relevant document content to AI model providers via our AI gateway to generate a result. This content is processed to provide the feature you requested and is not used by us to train AI models. Our agreements with AI providers restrict use of the data to providing the service.

6. Cookies

We use only strictly necessary cookies: session cookies that keep you signed in and protect your session. They are essential for the service and therefore do not require consent under the ePrivacy rules. We do not use advertising, profiling, or third-party analytics cookies. You can delete cookies in your browser settings at any time; you will be signed out.

7. Recipients and sub-processors

We share personal data only with service providers who help us run ConsentPath, under data processing agreements that bind them to confidentiality and to processing only on our instructions:

ProviderPurposeLocation
Amazon Web Services (AWS)Cloud hosting of the applicationEU / UK regions; US parent company
Neon, Inc.Managed Postgres database (application data)EU region; US parent company
Cloudflare, Inc.File storage (uploaded documents and exports) and content deliveryGlobal edge network; US parent company
Tiptap GmbHReal-time collaborative document editing infrastructureGermany (EU)
ElectricSQLReal-time data synchronisation to your browserEU / US
Resend, Inc.Transactional email (sign-in codes, invitations, notifications)US
OpenRouter, Inc. and underlying AI model providers (e.g. Google)AI-assisted features (e.g. document import, drafting assistance)US / EU

We may also disclose personal data where required by law, to enforce our agreements, or as part of a corporate transaction (in which case this policy continues to apply to your data).

8. International transfers

Where personal data is transferred outside the European Economic Area, the United Kingdom, or Switzerland, we rely on an adequacy decision where one exists (including the EU–US, UK–US, and Swiss–US Data Privacy Frameworks for certified providers) or on the European Commission’s Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum and the amendments recognised by the Swiss Federal Data Protection and Information Commissioner (FDPIC), together with additional safeguards where appropriate. You can request a copy of the relevant safeguards via [email protected].

9. Retention

We keep personal data only as long as needed for the purposes above: account data for the life of your account and up to 30 days after deletion; workspace content for as long as the owning customer keeps the workspace (or as instructed by them); logs and audit events for up to 12 months unless needed longer for security investigations; and records we must keep by law for the applicable statutory period. Backups are rotated on a fixed schedule, after which deleted data ages out.

10. Security

We protect personal data with technical and organisational measures including encryption in transit, encryption at rest with our hosting providers, workspace-level access controls enforced in the database (row-level security), short-lived scoped access tokens, audit logging, and the principle of least privilege for staff access. No system is perfectly secure; if a breach affects your data we will notify you and the competent authority as required by law.

11. Your rights

Subject to the conditions in the GDPR, UK GDPR, and Swiss FADP, you have the right to:

To exercise any of these rights, email [email protected]. We respond within one month (extendable as permitted by law). Where ConsentPath acts as processor for workspace content, we will refer your request to the controller (the workspace owner) and assist them in responding.

You also have the right to lodge a complaint with a supervisory authority:

12. Automated decision-making

We do not carry out automated decision-making, including profiling, that produces legal effects or similarly significant effects on you.

13. Children

ConsentPath is a professional tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.

14. Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top shows the current version. For material changes we will give you reasonable advance notice, for example by email or an in-app notice.

15. Contact

Questions, requests, or concerns about this policy or your personal data: [email protected].