Consent management that fits your site's scale, not a one-size-fits-all script.
Privacy law isn't one rule. GDPR governs the EU, individual US states set their own disclosure requirements, and the right consent solution depends entirely on how big and how global your site actually is. We help you choose it, then we implement it.
Why this is more complicated than it looks
Two very different rulebooks, and most sites are subject to both.
If your visitors come from more than one region (and almost every site's do), you're very likely working under more than one privacy regime at once.
European Union: GDPR
GDPR requires a documented, accessible process for visitors to request that their personal information be deleted, and proof that the request was honored.
United States: State by state
There's no single federal answer in the US. Instead, disclosure requirements vary by state. What's required for a California visitor may not apply to a visitor in Texas.
How we work
Consultancy first. Implementation second.
We don't sell a single tool to every client. We scope what your site actually needs, then build it.
Consultancy
We look at your traffic volume, where your visitors come from, what data you actually collect, and how much legal exposure that creates. A small portfolio site doesn't need the same solution as a global publication with millions of visitors.
Solution selection
Based on that scope, we recommend the right-sized platform, from a lightweight banner tool to a full enterprise consent management system.
Implementation
We configure consent banners, cookie categorization, and data-subject request workflows so they match your actual obligations in each jurisdiction your visitors come from.
Ongoing management
Regulations and your site both change. We keep the configuration current as new scripts, cookies, and rules get added.
Sized to match your site, not the other way around.
We don't push one platform on every client. We scope your traffic, your regions, and your risk, then recommend the tier that actually fits.
Essentials
Best for small portfolio & brochure sites
A lightweight, subscription-based consent tool for sites with straightforward compliance needs and limited traffic.
- Cookie consent banner
- Baseline GDPR compliance
- Single-region configuration
Growth
Best for growing business sites
A mid-tier consent management platform for sites that need more configurability without full enterprise complexity.
- Multi-region consent rules
- Configurable cookie categories
- Moderate-traffic support
Enterprise
Best for high-traffic & global sites
The most comprehensive tier we implement, and the choice our law firm partners recommend for high-traffic or global sites. It indexes every script and cookie on your site, then lets you define exactly what consent should look like, and what data gets captured, for each jurisdiction your visitors come from.
- Full script & cookie indexing
- Jurisdiction-by-jurisdiction rules
- Audit-ready consent records
Compliance FAQ
Questions we get from clients and their counsel.
If any of your site's visitors are in the EU, GDPR can apply to you regardless of where your company is based.
GDPR centers on a documented process for visitors to request their data be deleted. US state laws instead focus on specific disclosures, and those requirements vary state by state.
No. We scope the right-sized tier first. Our enterprise tier is what we recommend for high-traffic or global sites, but smaller sites are often better served by a lighter tool.
Yes. We regularly partner with law firms on exactly this question, and can coordinate directly with your counsel on requirements and documentation.
Not sure what your compliance exposure actually is?
Tell us about your site and where your visitors come from, and we'll tell you what you actually need.