Legal and security
Legal and security
Six documents, written to be read by the person who has to make a decision rather than drafted to survive a challenge.
The whole shelf
All six
Privacy notice
What we hold, why, for how long, and the distinction between the data we control and the data we only process for you.
Read itTerms of service
The agreement between us: what we owe you, what you owe us, and what happens if either of us stops.
Read itData processing agreement
The terms that apply because your customer records are yours and we handle them on your instructions.
Read itSub processors
Every other company that touches your data, kept current rather than reviewed annually.
Read itSecurity
How the isolation actually works, and a list of the things we do not have.
Read itAccessibility
What is enforced by a test on every build, and what has not been tested at all.
Read itThe terms of service are the contract. The data processing agreement is incorporated by them instead of standing alone, and where the two conflict on a data protection question the data processing agreement wins, which clause 14 of that agreement says in those words. The privacy notice describes rather than promises, and the security and accessibility pages describe how the product behaves today rather than warranting how it will behave in a year. Nothing else on this website forms part of the agreement, including this page. If a sentence here does not match what the document it summarises says, or does not match what Consonas actually does, that is a defect rather than a subtlety, and we would like to be told at legal@consonas.com.
Four reasons to be here
Depending on why you are here
You are about to sign up
The terms and the privacy notice. Between them they cover what we owe each other and what happens to your data, including the region you choose at signup, which is permanent from that moment. There is no United Kingdom region; organisations in the United Kingdom should choose the European Union.
Your organisation handles other people's data
Which is almost every organisation using a CRM. Add the data processing agreement, because your customer records are yours and we handle them on your instructions. You are the controller of those records and we are the processor, in the sense the Data Protection Act 2018 uses those words, which is why a request from an individual comes to you rather than to us.
Someone is doing supplier diligence
The security page and the sub processor list. Start with the section on the security page headed six things we do not have, because for a diligence reader that is the more useful half and most suppliers do not provide it.
You are checking whether the product will work for you
The accessibility page lists what is enforced by automated tests and, more usefully, what has not been tested at all. If you use assistive technology, that second list is the honest answer to whether this will work for you today.
For a diligence reader
The answers you are going to look for, in one place
Written so that someone assessing us can decide in five minutes rather than five weeks. Every one of these is stated at greater length in the document named.
What we do not hold
No SOC 2. No ISO 27001. No published penetration test. If your process requires any of those, we do not currently pass it, and no amount of correspondence will change that this quarter, and we will not sign a questionnaire asserting one either. That is the first thing on this page for a reason. There are no customer logos or testimonials either, which the customers page says in those words rather than leaving the absence to be noticed.
What is built and not yet enabled
Two protections are written, tested and not switched on in production, and the security page names both instead of describing them as though they were live. A supplier who tells you about the gap between built and enabled is telling you something about the rest of their claims as well.
How separation actually works
Each organisation has its own database inside its own isolated compute, rather than a share of one database with a condition on each query. A query written without a customer condition cannot return the wrong customer's data because there is nowhere for it to go. Behind that, each object refuses a request naming a different organisation, so a routing mistake produces a refusal rather than a disclosure. The reasoning behind one database per customer, including what it costs us, is written out at length.
What happens to data at the end
Thirty days of retention so a mistake can be undone, then deletion, then at most thirty further days for backups to age out. Deletion removes a database instead of marking rows, which is a materially stronger form of deletion and a consequence of the architecture rather than a policy.
Who at Consonas can read your records
Nobody, in the ordinary course. Access happens where you have asked for support that requires it, is limited to the people who need it, and is recorded. Your data does not train models, ours or anyone else's, and is never sold in any form.
What we commit to on notification
Twenty four hours from becoming aware of a breach affecting your data, with what we know at the time instead of a complete narrative later. Your own clock towards the Information Commissioner's Office starts when you know, which is the whole reason ours is shorter than the law asks of us. We will also tell you about incidents that did not become breaches where they affected your service.
That is a promise we make, not a thing our software does, and the two are worth keeping apart. What the software does is hold the clock: an incident is declared in the operator area with what is known and which organisations it touches, the moment is stamped, both deadlines are counted from it, and any organisation still owed a message after its twenty four hours appears on a list of what is overdue. The message itself is written by a person. Nothing here sends you an automatic letter about a breach, and nothing should.
Where the obligations sit by plan
They do not sit by plan. The audit trail, consent records, subject access tooling, two factor sign in and complete export are on every plan including the free one, permanently. The data processing agreement applies to free customers without being requested, which is why it is published here rather than sent on request.
A document written plainly gives less room to argue afterwards. The alternative protects us in a dispute that is unlikely and misleads you in a decision you are making now.
Which is a real cost of writing them this way, and one we think is worth paying.
Asked before signing
Asked about these documents
Are these negotiable?
Not for the standard plans, and that is normal for software sold at this price. For Enterprise, terms are part of the conversation. Audit rights are the usual sticking point, and clause 10 of the data processing agreement sets out what we offer in place of the clause your template contains. If a specific clause is a genuine blocker, write and tell us which one and why, because occasionally the answer is that we had not thought about it properly.
Will you tell me if these change?
For material changes to the terms or the privacy notice, yes, before they take effect, to the address that owns the organisation. For the sub processor list, yes, when we add one that touches customer data. What we will not do is change something significant and rely on a date at the top of a page as notice.
Where is the cookie policy?
There is not one, because this site sets no cookies. The application uses what it needs to keep you signed in and that is described in the privacy notice. A cookie policy for a site with no cookies is a document written to look thorough.
Is there an archive of previous versions?
No, and that is a gap rather than a position. Nothing here publishes what a document said last quarter. If the exact wording you agreed to matters to your file, save the page on the day you agree to it, which is the honest advice while there is no archive to point you at.
Ask about anything here
Including the questions where the answer is no. We would rather tell you now than at the end of a procurement process.
Three people, a thousand relationships, no card and no time limit.