Legal and security
Privacy notice
Written to be read. The most important thing on this page is the distinction between the data we control and the data we merely process on your behalf, because almost everything else follows from it.
Two capacities
Two kinds of personal data, with different rules
Consonas holds personal data in two very different capacities, and confusing them is the source of most of the confusion in privacy notices generally.
The records inside your organisation. The people and organisations you work with, their details, the history of your dealings, the notes your team writes. You decide what goes in there, why, and for how long. In data protection terms you are the controller and we are the processor, in the sense the Data Protection Act 2018 gives those two words. We act on your instructions. We do not decide what is collected and we do not use it for anything of our own.
Your own account and organisation details. Your email address, your role, your billing. Not your name: there is no name on the account, as the list above says, because nothing we do with it needs one. We decide what to hold and why, so we are the controller for this. It is a small amount of data and it is the only personal data we control.
The practical consequence matters. If someone wants to know what data you hold about them in Consonas, that request goes to you rather than to us, and we help you answer it. If you want to know what we hold about you as our customer, that request comes to us.
Controller by row
Five kinds of data and who controls each
This table is the practical version of the paragraph above.
| The data | Who decides what happens to it | What that means |
|---|---|---|
| The records inside your organisation | You. You are the controller and we are the processor. | We act on your instructions, we do not decide what is collected, and we do not use it for anything of our own. |
| Your own account details | Us, for the purpose of running the service. | We are the controller for this, and it is the only personal data we control rather than process. |
| Someone using your customer portal | You. They are one of your customers. | Their request about their own data goes to you, and we help you answer it. |
| Somebody who emails us at hello | Us. | We keep it to answer you, and delete it when it is no longer needed for that. |
| Analytics about how you use the product | Nobody. We do not collect it. | There is no analytics script, no session recording and no behavioural tracking in the product or on this site. |
The complete list
Everything, and why
This is the complete list rather than a summary of it.
- Your account
- Your email address, a password hash which is not reversible, whether the address has been verified, and the record of when you last signed in. There is no name on it, because nothing here needs one. Held to let you sign in and to tell you about your account.
- Your organisation
- Its name, its region, its plan, who belongs to it and what role each person has. Held to run the service and to bill for it.
- Your customer records
- Everything you put into your organisation about the people and organisations you work with. We are the processor for this and you are the controller. We do not decide what is in it and we do not use it.
- Billing records
- Amounts, dates and invoices, when the paid plans open. Kept for as long as tax law requires, which in the United Kingdom is six years. These contain no customer records.
- Operational logs
- That a request happened, which organisation it belonged to, which route it hit, whether it succeeded and how long it took. Not the contents of your records, not request bodies, not tokens.
- Correspondence
- If you write to us, we keep the correspondence so we can answer you and so we have a record of what was said. Deleted when it is no longer needed for that.
Your customer records are not used to train anything, not pooled into an aggregate product, and not sold, shared or licensed. The only processing is what is needed to run the service for you and what you ask for.
Which is a legal position instead of a promise, and it is the reason the rest of this page is short.
No script, no pixel
What this site and this product do not do
This website ships no JavaScript
Not a small amount. None. There is no analytics script, no advertising pixel, no tag manager, no heat mapping, no session recording and no third party host contacted when you load a page. Every asset comes from our own origin.
There is no cookie banner because there are no tracking cookies to ask you about. A banner on a site that sets no cookies is theatre, and a banner where rejecting takes more clicks than accepting is worse than theatre.
The application records what it needs to work
That you signed in and from roughly where, so we can tell you if somebody else does. That a request happened, which organisation it belonged to, whether it succeeded and how long it took. The audit trail of changes made inside your organisation, which exists for your benefit and which you can read.
It does not record what you looked at, how long you spent on a screen, where your mouse went, or anything else that would constitute behavioural analytics. There is no third party analytics provider with access to any of it.
Logs deliberately contain very little
No record contents. No request bodies. No message contents. No tokens, passwords or session identifiers.
The reason to be strict is that logs are the least protected copy of anything. They are read by more people, kept in more places and forgotten about more often than a database is. A system that logs generously has quietly created a second, worse copy of its customers' data. What a log line actually holds is itemised on the security page.
Three things do leave, and they are named here rather than inferred
None of the three is a supplier processing on our behalf, which is why the sub processor page describes them in its transfers section instead of listing them in its table. They still leave, so they are written down.
A VAT number, when somebody in your organisation asks the product to check one, goes to HMRC and comes back with the name and the address that registration is held in. A company number goes to Companies House and comes back with that company's public record. Neither request carries your organisation's name, the record the number sits on, or who asked.
And every password anybody sets here is checked against the public register of breached passwords. What is sent is the first five characters of a hash of it, which means the password never leaves and the service cannot work out which one it was asked about. That check is why a password already exposed in somebody else's breach is refused here, and we would rather make the request than let one through.
Access and erasure
Exercising them, and who to ask
If you are our customer
Write to privacy@consonas.com. You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, object to processing, or ask for it in a portable form. For the last of those, the export in the product already does it and you do not need to ask.
You will get an answer from a person. If we cannot do something you have asked for, we will say why rather than not replying.
If a Consonas customer holds your data
Your request goes to them rather than to us. They decided what to collect and why, they are the controller, and we cannot lawfully act on their records without their instruction.
If you do not know who holds your data, or you have written to them and had no reply, write to us anyway. We will tell you who to ask, and we will remind them of their obligation. What we will not do is hand over or delete their records on your say so, because doing that would be a breach in the other direction.
What they answer with is the subject access tooling, which is on every plan including the free one. Where the request reached us first, we forward it and remind them that their month ran from the day you first asked rather than from the day it arrived at the right inbox. If nobody replies we chase once, tell you that we have chased, and say again that a supervisory authority takes complaints without our permission or theirs.
Complaining
If you are unhappy with how we have handled something, tell us first and we will try to put it right. You also have the right to complain to a supervisory authority. In the United Kingdom that is the Information Commissioner's Office, which takes complaints directly, and you do not need our permission or our agreement to do it.
Retention clocks
How long things stay
Your customer records
For as long as your organisation exists, because they are yours and we are not in a position to decide otherwise. Deleting a record in the product moves it out of the working views and keeps it recoverable, because the most common reason something is deleted is that someone meant to delete a different one.
There is one way an organisation stops existing without anybody asking it to, and it applies to free organisations only. If nobody has signed in for six months we write to the members, again at seven and again at eight, and if the twelfth month passes with still nobody signing in the organisation is closed, which starts the same thirty day clock described below. A paying organisation is never subject to this, however little it is used, and an organisation nobody has ever signed into is left alone rather than deleted on its first day.
Erasure is a separate, deliberate action that removes a person from every place they appear: the record, the connections, the notes, the audiences, the message history, the consent records and the files. What survives is the audit trail's statement that an erasure happened and who performed it, without the content, which is the shape the law expects.
When an organisation is closed
Closing is a two step action. You are told what will be removed and told to export first, because the deletion at the end of it is one we cannot undo for you.
Thirty days sit between the second step and the deletion, and the screen that closes the organisation gives you the date. In that time the organisation is shut to everybody, and its owner alone may take the export, look at the plan and reopen it. The period exists because closing the wrong organisation is a mistake people make, and it is the same thirty days however the closing started, including a free organisation that has gone twelve months without a sign in.
What there is not is a quiet retention period we do not tell you about. Thirty days is the number here, in the terms and in the data processing agreement, and when it is up the data is deleted and the backups it appears in age out within a further thirty days.
Everything else
Billing records for six years, because tax law requires it. That is a commitment we make rather than a rule any code enforces, and one with nothing to enforce yet, since the paid plans have not opened and there are no billing records. They will contain amounts, dates and your organisation, and no customer records. Correspondence until it is no longer needed to answer you. Operational logs for seven days, for diagnosing faults.
Seven days is worth saying plainly rather than calling it a short period, and worth saying where it comes from. It is how long our hosting platform keeps the logs a running service writes, and we have not shortened it or arranged to keep a copy for longer. So it is the ceiling as much as the policy: after seven days those logs are gone whether or not anybody wanted them, which is also why a fault reported three weeks later is harder for us to explain than one reported the same afternoon.
When the tidy version fails
Six requests that do not fit the paragraphs above
Everything above assumes one person, one organisation and one clear controller. Most of the difficult cases are difficult because one of those three assumptions is false.
The same person is in two organisations, and only one of them erases
Two of our customers can hold records about the same person without either knowing about the other. If one of them erases that person, the other's records are untouched, and that is correct instead of a shortcoming. They are two controllers who decided separately to hold something, for separate reasons, and one of them cannot instruct the other through us.
It has a consequence a person exercising a right needs to understand: the request has to go to each organisation that holds them, and there is no single place to send it once. We cannot search across organisations on anybody's behalf, and it is worth being precise about why. It is not a policy we could relax if a request were sympathetic enough. Each organisation's records sit in a database of its own, and there is no query that spans them, so the thing being asked for does not exist to be granted.
Somebody is both a colleague and a record
A person can appear twice in the same organisation in two entirely different capacities. They can have an account, because they work there and sign in. They can also appear in the records, because a colleague noted a conversation with them, or because they were a customer before they were a colleague.
Those two are held by different people for different reasons and they come apart when somebody leaves. Removing a person from an organisation ends their access. It does not remove what the organisation holds about them, and it should not, because the second thing was never held for the purpose of letting them in. If what they want is the record gone as well, that is a separate request to the organisation, answered by the organisation, and the audit trail keeps the fact that it happened without the content.
The person asking cannot prove they are the person
The risk in an access request is not usually refusing a genuine one. It is answering a false one, because handing somebody's file to a stranger who asked confidently is a breach that arrives dressed as good service, and it is the failure mode a controller should worry about most.
The proportionate answer is to ask for enough to be confident and no more. Asking for a passport scan to confirm an email address is not caution, it is collecting a document you now have to hold, protect and delete, in order to answer a request about holding less. Where the request comes to us about our own customers, we answer through the channel we already have with them instead of creating an identity record for the occasion.
The erasure is right and the six year rule still applies
Erasure is not absolute, and a notice that implies otherwise is setting a reader up for a disappointment. Where another law requires something to be kept, it is kept. Our own instance of this is billing: if you have paid us, the invoice stays for six years because tax law says so, and it stays even if you ask us to remove everything else.
What we can do is be exact about what that leaves. A billing record holds an amount, a date, an organisation and the details on the invoice. It holds no customer records. So the correct answer to a broad erasure request from one of our customers is that everything goes except the accounting entries, that we will say which ones those are, and that they will age out on their own schedule instead of being kept indefinitely under an excuse.
The request arrives after the organisation has closed
This is the bill for the deletion policy described above, and it is worth naming rather than discovering. When an organisation is closed the records go, and there is no quiet copy retained against a later request. If somebody then writes asking what that organisation held about them, the honest answer is that we cannot tell them, because there is nothing left to look in.
The alternative design keeps a copy for a while so that late requests can be answered. It also means the sentence saying your data is deleted would be false for as long as the copy exists, and we would rather be unable to answer one late question than untrue in a sentence that many more people read.
A public authority asks us instead of asking you
For the records inside your organisation we are the wrong recipient. We do not decide what is in them, we hold them on your instruction, and a demand for them is a demand against you. Our answer is to say so and to direct the request to you, and to tell you that it happened, unless we are legally prevented from telling you, in which case we will say as much as the law leaves us able to say and no less.
We will not treat a polite request from an authority as though it were an order. There is a difference between a legal demand and someone asking to see whether it works, and a supplier that cannot tell the two apart is not a safe place for your records.
Yours to decide
The decisions we are not allowed to make for you
Being the processor is not only a limit on what we may do with your records. It is a limit on what we may decide, and these are the decisions it leaves with you.
| The decision | One way | The other way |
|---|---|---|
| Which region your organisation is created in | The European Union. Your organisation's database is physically there, no transfer arises for your stored records, and a reader in the United Kingdom is in the closest place to home that we offer. | The United States. Sensible if your people and the people you work with are there. It means the support access described on the sub processors page is a transfer. It is also the only choice on this list you cannot revisit, because the region is fixed when the organisation is created. |
| Whether two factor sign in is required of everyone | Required. One more step at each sign in, and the most common route into a system of this kind closes. It is on every plan including the free one, permanently, and it is requirable for a whole organisation. | Optional. Some people will turn it on and some will not, and the ones who do not are the ones who will be phished. You are trading a little convenience for a few against the account you would least like taken. |
| Whether you write retention rules | Written. A rule says what kind of record, how long after what, and whether to remove it or to strip the person out of it, so your own policy is applied by the product rather than by someone remembering to. | Not written. Nothing leaves on its own. That is defensible for an organisation in its first year and it gets less defensible every year after, because the answer to why do you still hold this stops being that you only started last spring. |
| Whether the people you work with get a portal of their own | They do. A person can see the dealings you have chosen to show them without writing to anyone, which answers a fair share of access requests before they are made. It is a separate trust boundary and the security page treats it as one. | They do not. Fewer surfaces to secure and fewer things to explain to your own auditor. Every question then arrives as an email to somebody in your team who has to answer it by hand. |
| What your team is allowed to type into a note | Governed. You decide what belongs in free text, you say so, and you say it more than once. It is the only control that works, because no product can prevent a sentence being typed. | Ungoverned. Free text will eventually hold something someone would not have been willing to put in a field, and it will be found by the same search that finds everything else. This is the decision on this list that no supplier can take for you, and the one most often left unmade. |
Why we will not choose the safer option on your behalf
For at least three of those, we have an opinion, and in each case we think one column is better than the other. We still will not apply it to your organisation, because a processor that decides how long your records are kept, or who may see what, has stopped being a processor and has started deciding the purpose. That would change our obligations, and yours, without either of us having agreed to it.
What we do instead is make the choice visible, put the cost of each side next to it, and set the starting position where the harm from getting it wrong is smallest. That is why obligations such as the audit trail, the consent records, the subject access tooling, two factor sign in and the complete export are on every plan including the free one and always will be. Those are not decisions we think anyone should be making on the basis of price.
The one you cannot revisit
The region is fixed when the organisation is created. Not fixed as a policy that could be waived for a good enough reason, but fixed because the database was created in that jurisdiction and moving it would mean creating a different organisation and importing into it.
There are two regions, the European Union and the United States. There is no United Kingdom region, and organisations in the United Kingdom should choose the European Union. We would rather write that plainly on every page where it matters than let someone find out after they have put a year of records into a choice they cannot change. Where a transfer can still arise, and what covers it, is set out on the sub processors page.
The one no one makes deliberately
The last row of the table is the one that goes unmade. Every organisation decides what may be typed into a note, and most decide it by accident, one sentence at a time, in the direction of whatever the busiest person on the team finds convenient.
We cannot prevent it and neither can anybody else selling you software. Free text takes whatever is typed. What the product can do is make what was typed findable when somebody asks, and deletable when they are entitled to have it gone, which is why the subject access tooling searches free text and does not restrict itself to the tidy fields. The rest is a conversation with your own team, repeated more often than feels necessary.
Weasel words
What these terms mean here, and what they usually hide
Privacy notices have a vocabulary, and a good part of it exists to sound like a commitment without being one. These are the words on this page and the words we have refused, with what each one is doing.
- Personal data
- Wider than most readers arrive expecting. A work email address is personal data. A name typed into a note is personal data. An address recorded in a log is personal data about whoever was at that address. The practical consequence is that a customer record system does not have a personal data part, it is one throughout, and a policy that treats a single field as the sensitive one has already missed most of it.
- Controller and processor
- The one who decides is the controller and the one who acts on the decision is the processor. Readers often assume processor is the bigger role because it sounds like the one doing the work. For the records inside your organisation you decide and we act, which is why almost every question about them ends with you rather than with us.
- Deleting, the bin, and erasing
- Three things the product keeps apart on purpose. Deleting puts a record in the bin, where it behaves as gone and can be restored for thirty days. After that it goes for good. Erasing a person is the separate, deliberate action that removes them from every place they appear. A notice that used one word for all three would be shorter and would tell you less about what actually happens.
- Anonymised
- A word that does a great deal of quiet work in other people's notices. Stripping the person out of a record is a real operation and that is what we call it. Whether what remains is anonymous in the legal sense depends on what is left and on what else exists to compare it against, which is a judgement about your data rather than a property a supplier can certify from the outside.
- May share with trusted partners
- A sentence that permits anything while sounding careful. May covers every case including none of them. Trusted is the supplier's own opinion of itself. Partners is not a list. Where someone processes data on our behalf we name them on the sub processors page. At the time of writing it holds two names, and only one of them is processing anything yet.
- Including but not limited to
- A list that bounds nothing, which is exactly why it is popular: an unbounded list can never turn out to have been wrong. Wherever this page gives a list, the list is the list.
- We take your privacy seriously
- Carries no obligation and cannot be breached, which is the other reason a sentence becomes popular. Nothing follows from it. The sentences worth checking us against are the ones that would be false if we did a particular thing, and this page is written to contain as many of those as we can stand behind.
- Industry standard security
- Names nothing, and can be said with equal confidence by a supplier who has thought hard about this and one who has not. The security page names what is actually used and, more usefully, the six things we do not have.
- Subject access request
- The right is a right of access, and people arrive calling it a SAR, a GDPR request or simply a data request. The important thing is not the name. It is that a complete export of your organisation is not the answer to one: what is wanted is one person's slice, and sending the whole export would be a second breach against everyone else who appears in it.
- Legitimate interests
- A genuine lawful basis in the law and a shrug in practice. For the small amount of data we control, meaning your account and organisation details, we rely on the contract with you and on our own interest in keeping the service secure. For what sits inside your records the basis is yours to choose and to write down, and no supplier can choose it on your behalf however convenient that would be for both of us.
The test we apply to a sentence in this notice is whether it could be broken. If there is no action we could take tomorrow that would make it false, it is decoration, and it has been cut. That test removes a surprising amount of what a privacy notice usually contains, and what remains is shorter, plainer and considerably easier to hold us to.
It also explains a shape you may have noticed. This page names costs, refusals and the things we cannot do, at greater length than it names reassurances. That is not modesty. A reassurance is cheap to write and impossible to check, while a stated limit is the one kind of sentence a reader can verify by trying it.
Asked about your data
Asked about privacy
Do you use our customer records for anything?
No. Not to train models, not to build an aggregate product, not to sell, not to share, and not to analyse for our own purposes. The only processing is what is needed to run the service for you and what you ask for. That is what being a processor instead of a controller means, and it is a legal position rather than a promise.
Does this website track me?
No. The site you are reading ships no JavaScript at all. There is no analytics script, no advertising pixel, no tag manager, no cookie banner because there are no tracking cookies to consent to, and no third party host is contacted when you load a page. Every asset comes from our own origin.
Does the application track me?
It records what it needs to work: that you signed in, that a request happened, and the audit trail of changes you made inside your own organisation, which exists for your benefit and is readable by you. There is no behavioural analytics, no session recording, and no third party analytics provider.
Where is data held?
In the European Union or the United States, chosen by each organisation when it is created and fixed from then on including for us. UK organisations should choose the European Union. Our control plane, which holds accounts and organisation records rather than your customer records, is operated by the same provider.
How long do you keep things?
Customer records for as long as your organisation exists, because they are yours. Billing records for six years, as tax law requires. Correspondence until it is no longer needed to answer you. Operational logs for seven days, which is how long our hosting platform keeps them and which we have neither shortened nor extended. Closing your organisation removes your records thirty days later, which is why the interface tells you to export first. A free organisation nobody has signed into for twelve months is closed on the same terms, after three warnings; a paying one never is.
What are my rights, and how do I use them?
If you are one of our customers, write to privacy@consonas.com and we will answer. If you are somebody whose data one of our customers holds in Consonas, your request goes to them rather than to us, because they are the controller and we cannot lawfully act on their data without them. If you are unsure who to write to, write to us and we will tell you.
Do you use cookies?
The application uses what it needs to keep you signed in. This marketing site sets no cookies at all, which is why there is no banner asking you about them. A cookie banner on a site with no cookies is theatre, and one that makes rejecting harder than accepting is worse than theatre.
Who can see our data at Consonas?
Nobody, without opening your organisation through the product, which requires a stated reason, a second approver, and an entry in your own audit trail that you can read without asking us. There is no console onto a customer database and no standing access.
Somebody in procurement has asked me to prove Consonas is compliant. What can I send them?
The data processing agreement with both annexes, the security page, and the sub processors page, all of which are public so they can be read without asking us and without a form. What you cannot send them is a certification, because we hold neither SOC 2 nor ISO 27001 and there is no published penetration test. We say that here as well as on those pages, because finding it out at the end of an evaluation wastes more of your time than ours.
Is an address in your logs personal data?
Treat it as such, because it can identify whoever was at that address, and we treat it as such ourselves. It is recorded so that a sign in from somewhere unexpected can be shown to the account holder, and it is kept for seven days for diagnosing faults, which is our hosting platform's retention for the logs a running service writes. The contents of the request it belonged to are not recorded alongside it.
What happens to our data if Consonas is acquired or closes?
A privacy notice usually mentions a business transfer in a subordinate clause and moves on. Plainly: if the company changed hands, the data would go with it, and the processing agreement would go with it too, because it binds whoever holds the data rather than whoever signed it. We would tell account holders before it happened rather than afterwards, and a complete export is available at any time on every plan without asking us, which is the part that makes the rest of this answer worth anything.
Ask us anything about this
A person reads that address. If we cannot do something you ask for, we will tell you why rather than not replying.
Three people, a thousand relationships, no card and no time limit.