Privacy Policy
Last updated: 26 June 2026
1. Who We Are
Obscurity Ltd is an analytics governance consultancy based in Dublin, Ireland. We help regulated organisations govern analytics and marketing tracking so measurement stays reliable and audit-ready. Obscurity Ltd is not required to designate a Data Protection Officer under Article 37 GDPR. For data protection queries, contact contact@consentmark.com.
- Company Registration No: 622475
- Email: contact@consentmark.com
2. What Data We Collect
We collect minimal data on this website. Visitors who decline consent experience no analytics tracking. Strictly necessary cookies (such as the cc_cookie consent cookie) may be set without consent as permitted under the ePrivacy Directive, as they are required for the website to function.
When consent is granted:
Consent is managed by our own self-hosted consent banner. There is no third-party consent provider, and no personal data is shared for consent management. When a visitor grants consent:
- Google Tag Manager (GTM) loads in the browser and activates analytics tags.
- Page views and navigation data are collected by Google Analytics 4 (GA4) via client-side JavaScript.
- GA4 applies automatic IP anonymisation. No raw IP addresses are stored by Google Analytics.
- GTM loads with all consent signals denied by default. Analytics tags within GTM only activate after consent is granted via our consent banner.
Google Calendar:
If you book an appointment, your name and email are processed by Google Workspace. Google Ireland Ltd is the data controller for EEA users.
Free Governance Scanner:
If you use our free governance scanner, we collect your email address to deliver the scan results. If you opt in to marketing communications via the scanner form, we may also send analytics governance insights and service updates. This data is processed on the basis of consent (you submit the form voluntarily; marketing communications require separate opt-in). Email addresses collected via the scanner are retained for 12 months and then deleted. Scanner infrastructure is hosted on AWS (Dublin, EU).
3. Scanning Third-Party Websites
The scanner loads a publicly accessible page in a headless browser running in AWS eu-west-1 (Dublin), interacts with whatever consent banner the page presents, and records what the page sends to the browser. This section covers that processing. It is separate from the data we collect about you as a visitor to this website.
What the scan captures:
- The full URL of every network request the page makes, including query strings, and the request and response headers.
- Cookies and browser storage the page writes, including their values.
- Screenshots of the page as it rendered.
- A derived record: which analytics and advertising vendors were identified, the consent state at the moment each request fired, and the resulting grade.
The browser is synthetic. It is not a real visitor, it enters no personal data, and it holds no account on the scanned site. Any identifier that appears in a captured request is one the scanned site generated for that synthetic session.
Lawful basis: legitimate interests, Article 6(1)(f). The interest is in producing an independent, timestamped observation of what a publicly accessible website ships to a browser, which is the service. The observation is of a site's configuration rather than of an individual, and the scan carries no login and no personal data of the scanned organisation's own visitors.
Retention. The raw capture - full request URLs, headers, cookie values and screenshots - is deleted after 90 days. That figure is enforced in two places: the S3 lifecycle rule on the scanner artefact store, and the scan-evidence sweep in our retention job. The derived record - vendors identified, consent state, grade - is kept for 2,190 days, because it is the record of what an already-published grade was based on. Where a scan is preserved as a signed evidence bundle, the raw capture is held under S3 Object Lock and expires at 1,096 days. A legal hold suspends every one of these sweeps until it is lifted.
If you operate a scanned site and want to dispute a finding or ask for a result to be taken down, write to contact@consentmark.com. We can withdraw an individual result from public view, and we hold a global switch that withdraws all of them.
4. How We Use Your Data
- To understand how visitors use our website (aggregated analytics only)
- To respond to enquiries via email
- To schedule appointments
- To deliver governance scan results to the email address you provide
5. Legal Basis (GDPR Article 6)
- Analytics: consent (Article 6(1)(a))
- Enquiries: legitimate interest (Article 6(1)(f))
- Appointments: contract performance (Article 6(1)(b))
- Governance scanner: consent (Article 6(1)(a)) - scan results delivery and, where separately opted in, marketing communications
6. Third-Party Processors
| Processor | Purpose | HQ | Data Location |
|---|---|---|---|
| AWS Amplify (Amazon) | Website hosting / CDN | US (eu-west-1 region) | EU |
| Google Tag Manager | Tag management (consented) | US (Google Ireland Ltd for EEA) | US infrastructure |
| Google Analytics 4 | Website analytics (consented) | US (Google Ireland Ltd for EEA) | US infrastructure |
| Google Workspace | Email, calendar scheduling | US (Google Ireland Ltd for EEA) | EEA |
| Amazon Web Services | Scanner API and dashboard hosting infrastructure | US (AWS EMEA SARL for EEA) | EU (Dublin) |
| Amazon SES | Scanner result email delivery | US (AWS EMEA SARL for EEA) | EU (Dublin) |
| AWS Bedrock (Amazon, sub-processor) | LLM-assisted classification of unknown scripts observed in scans | US (AWS EMEA SARL for EEA) | EU only via EU cross-region inference profile (invoked from eu-west-1; routes within EU regions); model invocation logging disabled (zero retention) |
7. Data Transfers
GA4 data is processed by Google LLC, which is certified under the EU-US Data Privacy Framework (DPF). We acknowledge that transfer mechanisms may change and will update this policy accordingly. GA4 event data is retained for 2 months and user data is retained for 14 months. We minimise data collection by gating all analytics behind consent - no tracking occurs without explicit visitor approval. GA4 applies automatic IP anonymisation so no raw IP addresses are stored.
8. Your Rights
Under the General Data Protection Regulation (GDPR), you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate personal data
- Request erasure of your personal data
- Restrict processing of your personal data
- Data portability
- Object to processing of your personal data
- Withdraw consent at any time via the cookie consent banner
You also have the right to lodge a complaint with the Data Protection Commission (Ireland).
9. Cookies
We use a self-hosted consent banner to manage cookie consent. A strictly necessary cookie (cc_cookie, storing your consent decision) is set without consent as permitted under the ePrivacy Directive. Without consent, no analytics or marketing cookies are set and no tracking occurs. With consent, analytics cookies are set by Google Tag Manager and Google Analytics.
Cookie Categories
| Category | Cookie Name | Provider | Purpose | Expiry | Type |
|---|---|---|---|---|---|
| Necessary | cc_cookie | Obscurity Ltd (first-party) | Stores your cookie consent decision and a random consent identifier | 6 months | HTTP cookie |
| Analytics | _ga | Google Analytics 4 | Registers a unique ID used to generate statistical data on site usage | 2 years | HTTP cookie |
| Analytics | _ga_* | Google Analytics 4 | Used by GA4 to maintain session state | 2 years | HTTP cookie |
10. Changes to This Policy
We may update this policy from time to time. The "last updated" date at the top of this page reflects the most recent revision.
11. Contact
If you have questions about this privacy policy or how we handle your data, please contact us:
- Email: contact@consentmark.com
- For data protection enquiries: contact@consentmark.com
- Address: Obscurity Ltd, Dublin, Ireland