Provider, scope, and business use
These Terms apply only to entrepreneurs acting in a commercial or independent professional capacity, legal entities under public law, and public-law special funds. Consumers may not create or purchase a 1Consent account.
The service provider and your contracting party for the software service is:
1Consent UG (haftungsbeschränkt)
Ernst-Vogler-Weg 9
83607 Holzkirchen, Germany
Commercial register: Amtsgericht München, HRB 315682
Represented by Artur Przemyslaw Wachelka
By creating an account, accepting an order, starting a paid checkout, or using the service, the customer agrees to these Terms on behalf of the organization it represents. If the customer does not agree, it must not use the service.
Contract formation and order of documents
- Website and dashboard descriptions are invitations to place an order, not binding offers, unless expressly stated otherwise.
- A contract for a Free account is formed when 1Consent activates the account or begins providing the service after registration.
- A paid order is placed through Stripe-hosted checkout and accepted when checkout confirms the transaction or 1Consent activates the paid entitlement, whichever occurs first.
- The person acting for the customer represents that they have authority to bind that organization.
If documents conflict, the following order applies: a signed order or negotiated agreement; the processor terms in Section 11 for data-protection matters; these Terms; then product documentation. Stripe/Link's checkout and payment terms separately govern the payment transaction where Stripe/Link acts as merchant of record.
English and German versions are intended to have the same meaning. If they conflict, the German version controls to the extent permitted by law.
The service
1Consent provides hosted software and infrastructure for configuring, publishing, and operating consent and privacy-choice experiences.
- CMP runtime, APIs, framework-aware consent experiences, and storage of configured consent evidence;
- dashboard configuration, themes, translations, service catalogs, deployment stages, roles, and audit functions;
- website scanning and classification evidence for customer review;
- plan-dependent aggregate consent and session analytics, exports, and operational reports; and
- optional AI-assisted theme, suggestion, and translation features.
Current plan limits and feature descriptions shown at order time form part of the service description. Features can differ by plan, environment, framework, and release stage.
Customer compliance responsibilities
The customer determines the purpose and legal configuration of its CMP deployment and must:
- identify and comply with the privacy, ePrivacy, advertising, consumer, accessibility, and sector rules that apply to each property and audience;
- review framework suggestions and configure lawful purposes, legal bases, regions, choice design, retention, and withdrawal behavior before publication;
- provide accurate privacy, cookie, vendor, and transfer information to end users and keep it current;
- verify every service, vendor, cookie, tag, and script, including server-side processing that a browser scan cannot observe;
- give lawful instructions, obtain required rights and consents, and respond to data-subject or consumer requests;
- test its implementation and preserve any additional evidence its risk assessment or law requires.
1Consent, its scans, templates, catalog, framework suggestions, and AI output are technical tools and general information. They are not legal advice, certification, an audit opinion, or a guarantee that the customer is compliant.
Accounts, organizations, and security
Accounts are personal to authorized users and organization access is controlled by assigned roles. The customer is responsible for activity under its organization except to the extent caused by 1Consent.
- Provide accurate, current registration, organization, domain, and billing information.
- Protect credentials, use appropriate authentication controls, and do not share individual accounts.
- Authorize only personnel who need access and promptly remove users whose authority ends.
- Notify 1Consent promptly of suspected unauthorized access, compromised credentials, or misuse.
Plans, evaluation, usage, and delivery
Free, Starter, Pro, add-ons, included usage, overage units, retention periods, and prices are those displayed in the order flow when the customer subscribes. Plan entitlements apply at organization level unless stated otherwise.
Evaluation period
A new account may receive 30 days of Starter-tier evaluation features without a payment card. Unless the customer starts a paid plan, the account returns to Free at the end of the evaluation. Evaluation access may be limited or withdrawn for abuse and does not create a promise of future availability.
Digital delivery
The service is delivered electronically. Free and evaluation access starts after account activation. Paid features normally activate after successful checkout and verified billing confirmation; technical or fraud review can delay activation.
Where a paid plan includes metered overages, usage is measured as described in the pricing information. Reaching an included page-impression allowance does not block the CMP. Disputed usage must be raised within 30 days after the related invoice or statement.
Payment, merchant of record, taxes, and renewal
Paid self-service transactions use Stripe Managed Payments. The Stripe or Link entity identified at checkout acts as merchant of record and contractual seller for that checkout transaction; 1Consent remains responsible for delivering and supporting the software service.
- Checkout, accepted payment methods, currency conversion, receipts, invoices, payment support, disputes, and order management are handled through Stripe/Link under the terms shown there.
- Stripe/Link calculates, collects, files, and remits covered indirect taxes. The customer remains responsible for taxes, withholding, and reporting not covered by the merchant-of-record transaction.
- Paid plans renew monthly until canceled. The recurring price, usage charges, and next billing date are shown before confirmation and in the billing interface.
- If payment fails or becomes overdue, 1Consent may limit paid features after any stated grace period while keeping the consent-serving path available where technically and legally appropriate.
- Plan or add-on changes can be prorated as shown before confirmation. Price changes apply no earlier than the next renewal after at least 30 days' notice unless the customer expressly accepts an earlier change.
The customer must keep its billing details current and review Stripe/Link receipts and order information.
Cancellation, plan changes, and refunds
The customer may cancel a paid subscription through the Link or billing portal. Unless checkout says otherwise, cancellation takes effect at the end of the current paid billing period and paid access continues until then. A downgrade can remove features, capacity, or retained data after reasonable export opportunity.
Fees are non-refundable and no credits are due for partial periods, unused capacity, or customer configuration errors, except where mandatory law requires a remedy, a duplicate or incorrect charge occurred, or 1Consent agrees to a remedy for material service nonconformity.
Customers may also request transaction support from Link. Stripe may issue a refund at its discretion within 60 days of a Managed Payments transaction. A refund does not create an ongoing entitlement to use paid features.
Acceptable use
The customer and its users must not use the service to:
- violate law, third-party rights, or binding industry rules;
- probe, bypass, disrupt, overload, or compromise security, rate limits, tenant isolation, or service integrity;
- distribute malware, spam, deceptive interfaces, or content that is unlawful, infringing, or abusive;
- intentionally submit special-category, highly sensitive, payment-card, authentication-secret, or regulated health data unless expressly supported and agreed in writing;
- resell, sublicense, timeshare, or provide the service bureau-style unless an order expressly permits it;
- reverse engineer or extract non-public source code, models, catalogs, or underlying components except to the extent a mandatory law cannot be waived; or
- misrepresent that 1Consent, a scan, or a generated configuration is a legal certification or regulator approval.
Customer data and feedback
As between the parties, the customer retains its rights in data, content, configuration, assets, and instructions it submits to the service ('Customer Data').
The customer grants 1Consent and its subprocessors a non-exclusive, worldwide license during the contract to host, copy, transmit, transform, display, and otherwise process Customer Data only as necessary to provide, secure, maintain, and support the service and comply with law.
1Consent may create and use statistics that have been irreversibly anonymized so that neither the customer nor an individual is reasonably identifiable. Pseudonymous data is not treated as anonymous under this clause.
If the customer voluntarily provides feedback, it grants 1Consent a perpetual, irrevocable, royalty-free right to use it without identifying the customer or disclosing Customer Data.
Data Processing Addendum (Article 28 GDPR)
This Section is the parties' data processing agreement and applies automatically where 1Consent processes personal data in Customer Data on the customer's behalf. It is intended to satisfy Article 28 GDPR and corresponding processor-contract requirements.
Roles and instructions
The customer is controller or processor, as applicable, and 1Consent is processor or subprocessor. These Terms, the customer's lawful configuration and use of the service, and documented support instructions are the customer's complete instructions. 1Consent processes personal data only to provide, secure, and support the service, unless Union or Member State law requires otherwise.
1Consent obligations
- Process personal data only on documented instructions and for the contract term.
- Ensure authorized personnel are bound by confidentiality and receive access only as needed.
- Maintain appropriate technical and organizational security under Article 32, taking account of risk, state of the art, implementation cost, and processing context.
- Taking account of the processing, assist with data-subject requests, security, breach duties, DPIAs, and supervisory consultation through product functions and reasonable additional support.
- Notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Data and provide information reasonably available for the customer's assessment and notice duties.
- At the customer's choice and subject to law, return or delete personal data at the end of service, including through the retrieval and deletion process in Section 16.
- Provide information reasonably necessary to demonstrate compliance. Audits require reasonable notice, confidentiality, scope proportionate to risk, and normally occur no more than once per year unless an incident or authority justifies more.
- Inform the customer if an instruction appears to infringe applicable data-protection law and suspend that instruction where necessary.
Customer obligations
The customer ensures that its instructions and processing are lawful; gives required notices; has a valid legal basis; minimizes data; configures appropriate retention and access; does not submit unsupported sensitive data; and, if it is a processor, has authority from the relevant controller to appoint 1Consent and its subprocessors.
Subprocessors
The customer gives general written authorization for the subprocessors listed in the Privacy Policy. 1Consent imposes data-protection obligations no less protective than this Section to the extent applicable and remains responsible for each subprocessor's performance of those obligations.
1Consent will give at least 30 days' notice through email, the account, or an updated subprocessor notice before a new subprocessor begins material processing. The customer may object within 14 days on reasonable data-protection grounds. The parties will seek a practical solution; if none is available, the customer may stop the affected feature or terminate the affected service without an early-termination charge.
Restricted transfers
1Consent uses an adequacy decision, the EU-US Data Privacy Framework for certified recipients, the 2021 EU Standard Contractual Clauses, the UK addendum, or another valid safeguard for restricted transfers. Where the customer is processor, 1Consent ensures the relevant processor-to-processor module and supplementary measures apply in the subprocessor chain.
Processing details
- Subject matter: hosted consent-management, configuration, evidence, scanning, analytics, support, security, and related infrastructure.
- Duration: the contract term plus the retrieval, deletion, backup, and legally required retention periods described in the Privacy Policy and Section 16.
- Nature and purpose: collection, recording, organization, storage, adaptation, retrieval, consultation, transmission, aggregation, support, security, deletion, and other operations needed to provide the service on instructions.
- Data subjects: customer personnel and invitees; visitors and users of customer properties; people appearing on customer-selected public scan targets; and individuals whose details the customer submits in support or configuration.
- Data types: identifiers and pseudonymous IDs; consent choices and evidence; device, country, event, and usage data; customer content, configuration, and scan evidence; support data; and any other personal data the customer lawfully submits.
- Sensitive data: not intended. The customer must not intentionally submit special-category or highly sensitive data unless expressly supported and agreed in writing with appropriate safeguards.
Technical and organizational measures
Measures include encryption in transit and at rest where supported; tenant and environment separation; role-based and least-privilege access; authentication and secrets controls; secure development and change review; logging, monitoring, vulnerability and incident management; resilient hosting and backups; data minimization, pseudonymous consent identifiers, defined retention, and deletion workflows; and regular review of provider security. Measures may evolve without reducing the overall protection appropriate to risk.
Intellectual property and AI output
1Consent and its licensors retain all rights in the service, software, APIs, designs, documentation, service catalog, models, templates, and improvements. No rights are granted except those expressly stated.
During the contract, 1Consent grants the customer a limited, non-exclusive, non-transferable, revocable right to access and use the service internally for its business and deploy authorized CMP assets on its own or managed properties, subject to the plan and these Terms.
AI-assisted features
The customer decides whether to use AI features and must review every output before use. Outputs can be inaccurate, non-unique, or unsuitable and are not legal advice. Subject to third-party rights and applicable law, the customer may use saved output as part of Customer Data. The customer is responsible for its prompts, inputs, review, and publication.
Confidentiality
Each party will protect the other's non-public business, technical, security, and commercial information with at least reasonable care, use it only to perform or exercise rights under the contract, and disclose it only to personnel, providers, or advisers who need it and are bound to protect it.
Confidential information excludes information lawfully public without breach, already known without duty, independently developed, or lawfully received from another source. A legally compelled recipient may disclose the minimum required and, where permitted, give prior notice.
Availability, support, and service changes
1Consent aims to provide a reliable service but does not promise uninterrupted or error-free availability unless a signed order includes a service level agreement. Planned maintenance, emergency work, internet dependencies, customer systems, and third-party providers can affect service.
1Consent may update the service for security, law, interoperability, performance, or product development. It will not materially reduce the core paid functionality during a prepaid period without a reasonable substitute, migration path, or pro-rata remedy, except where required for security or law.
Preview, beta, evaluation, and experimental features are provided for testing, may change or end, and should not be used for critical production processing unless expressly approved.
Suspension and termination
The customer may stop using Free at any time and may cancel paid service as described in Section 8. Termination does not erase amounts already due.
1Consent may suspend affected access where reasonably necessary for a security threat, unlawful use, material breach, overdue payment, provider restriction, or risk to the service or others. Where practicable, it will give notice and an opportunity to cure and limit the suspension to what is necessary.
Either party may terminate for a material breach not cured within 30 days after written notice, or immediately if cure is impossible, insolvency law permits, or continued performance would be unlawful. 1Consent may end Free service on 30 days' notice.
On termination, licenses and access end except during an agreed transition or retrieval period. Accrued payment, confidentiality, IP, liability, processor deletion, switching, and provisions intended to survive remain effective.
Switching and data portability under the EU Data Act
1Consent does not charge a switching fee. Normal service fees remain payable through the applicable notice and transition period, and agreed custom professional services remain chargeable.
- The customer may request a switch to another provider, port to on-premises infrastructure, or erase exportable data by emailing the contact below and identifying the destination or authorized migration provider.
- The switching process starts without undue delay after a notice period chosen by the customer, which will never exceed two months. A monthly self-service customer may choose the end of its current billing period.
- The mandatory transition period is no more than 30 calendar days. 1Consent will provide reasonable assistance, maintain continuity and security, and disclose known continuity risks within its control.
- If 30 days is technically infeasible, 1Consent will explain why within 14 working days and specify an alternative period not exceeding seven months. The customer may extend the transition once by a period it considers more appropriate.
- Exportable data remains retrievable for at least 30 calendar days after the transition period, unless the parties agree to a later date.
- After successful switching and expiry of the retrieval or later agreed period, 1Consent will fully erase exportable data and digital assets generated by or directly relating to the customer, subject to mandatory law, processor instructions, protected backups, and data that has been irreversibly anonymized.
Exportable and excluded data
Exportable data includes account and organization records; projects, apps, domains, framework and deployment configuration; authored content and translations; themes and customer assets; service collections; available scan results and evidence; audit records; consent evidence and analytics the customer is entitled to receive; and other input or output data generated through the customer's use that can be ported without compromising others' rights or security.
Excluded categories are 1Consent source code and binaries; proprietary models, catalogs, algorithms, and internal service telemetry; fraud, abuse, and security signals; credentials and secrets; other customers' data; and internal configuration or metadata whose disclosure would create a security risk or expose trade secrets. Exclusions will not be used to hinder or delay switching.
Methods, formats, and limitations
Depending on the data and available product function, export is provided through a dashboard download, documented API, structured CSV or JSON, original file format, or support-assisted secure transfer. 1Consent will supply available schemas and reasonable technical information. It does not promise functional equivalence in a destination SaaS or undertake transformation or third-party import work unless agreed.
Infrastructure jurisdictions and non-personal EU data
Core providers operate infrastructure in Germany or other EEA locations, the United States, the United Kingdom, and global Cloudflare edge locations. Exact processing depends on the feature, visitor location, and selected provider region.
To resist unlawful international governmental access to non-personal EU-held data, 1Consent uses contractual confidentiality and challenge duties, provider due diligence, access controls, encryption, minimization, tenant separation, government-request review, and lawful transfer mechanisms. More current provider and jurisdiction information is available in the Privacy Policy and on request.
Warranties and disclaimers
Each party warrants that it has authority to enter the contract. 1Consent warrants that it will provide paid service with reasonable care and skill and substantially in accordance with the current service description.
Subject to that express warranty, the service, scans, catalog entries, AI output, and Free, evaluation, or beta features are provided as available. 1Consent does not warrant that every tracker or processing activity will be detected, that every configuration is lawful, that output is complete or error-free, or that the service meets a customer's unstated requirements.
Mandatory statutory warranties and remedies remain unaffected.
Liability and indemnity
- Liability is unlimited for intent and gross negligence; injury to life, body, or health; fraudulent concealment; an expressly assumed guarantee; liability under the German Product Liability Act; and any other liability that cannot lawfully be limited.
- For slight negligence, 1Consent is liable only for breach of an essential contractual duty whose performance enables the contract and on which the customer normally relies. Liability is limited to the foreseeable loss typical for this type of contract.
- Otherwise, liability for slight negligence is excluded. To the extent permitted by law, neither party is liable for indirect or consequential loss, loss of profit, or loss of anticipated savings that was not foreseeable as typical loss.
- For customer-caused or avoidable data loss, recoverable loss is limited to the reasonable restoration effort that would have been required with appropriate customer exports and backups. This does not limit 1Consent's processor or security duties.
- These limitations also apply to representatives, employees, and agents and to contractual, tort, and other claims. Statutory burden-of-proof rules are not changed.
Customer responsibility for third-party claims
To the extent caused by the customer's culpable unlawful Customer Data, configuration, instructions, or use in breach of these Terms, the customer will reimburse reasonable losses and defense costs from a third-party claim. 1Consent must notify the customer promptly, allow reasonable participation in the defense, and not settle an admitted customer obligation without consent. This does not apply to the extent 1Consent caused the claim.
Changes to these Terms
1Consent may change these Terms for future contracts at any time. For an existing continuing contract, material changes require at least 30 days' notice and a reasonable explanation. A change may address law, security, provider requirements, abuse prevention, or service development and must not unreasonably disturb the contractual balance.
A change that is legally required or necessary to address an urgent security threat may take effect sooner; notice will be given as soon as reasonably possible.
If a notified material change substantially disadvantages the customer, the customer may reject it and terminate the affected service before it takes effect. Continued use after the effective date constitutes acceptance where legally permitted.
Governing law and courts
German law applies, excluding conflict-of-law rules that would select another law.
If the customer is a merchant, legal entity under public law, public-law special fund, or has no general place of jurisdiction in Germany, the exclusive place of jurisdiction is Munich, Germany. 1Consent may also sue at the customer's general place of jurisdiction.
The UN Convention on Contracts for the International Sale of Goods does not apply.
General terms
- The customer may not assign the contract without 1Consent's prior consent, not to be unreasonably withheld for a bona fide corporate reorganization. 1Consent may assign to an affiliate or successor to the relevant business if customer protection is not materially reduced.
- Neither party is liable for delay caused by events beyond reasonable control, except payment duties. The affected party will mitigate and communicate material impact.
- Contract notices may be sent to the account email, through the dashboard, or to the legal contact below. The customer must keep its contact details current.
- A failure to enforce a right is not a waiver.
- If a provision is invalid, statutory law replaces it; the remainder stays effective. The parties will use a valid term that most closely reflects the lawful commercial purpose.
- The documents identified in Section 2 are the entire agreement for the service and replace prior statements on the same subject. Individual negotiated terms remain effective.
Legal contact
Send contract, cancellation, switching, subprocessor-objection, or legal notices to:
[email protected]