Enterprise consent management

CookieHub Enterprise adds single sign-on, DSAR management, API configuration and advanced consent reports to the platform, with dedicated account management, priority support and custom agreements. Consent data is stored and processed within the EEA, on Amazon Web Services.

Trusted and used by 30.000+ websites and companies worldwide.

monday.comSemrushDealfrontTixly

What Enterprise adds

Security and data protection

CookieHub is ISO 27001 certified, and SOC 2 compliance is in progress. As a data processor under Article 28 GDPR, CookieHub applies the same technical and organizational measures to every customer. Read the full security and data protection practices.

Hosted in the EU:

Application data, the consent log and encrypted backups are stored and processed within the EEA, on Amazon Web Services.

Delivered worldwide, stored in the EEA:

The CookieHub script is served from Bunny CDN and Amazon CloudFront close to each visitor, while the consent data itself stays in the EEA.

Pseudonymous visitor data:

CookieHub does not intentionally collect directly identifiable visitor data. Consent log entries keep an anonymized IP address and are deleted automatically after 12 months.

Documented processing:

A data processing agreement under Article 28 GDPR, a published list of sub-processors, and Standard Contractual Clauses where data leaves the EEA.

Enterprise FAQ

Yes. CookieHub is ISO 27001 certified, and SOC 2 compliance is in progress.

Within the EEA, on Amazon Web Services. Content delivery and network protection run worldwide, but the consent data stays in the EEA. Every provider and its country is listed under sub-processors.

Yes. The standard data processing agreement is part of the Terms of Service, and Enterprise customers can request a signed or customized version. Enterprise also supports custom master service agreements and service level agreements. One DPA term is the same for every customer: CookieHub's general authorization to engage sub-processors.

Google Workspace, Microsoft Entra ID, and any SAML 2.0 identity provider, such as Okta, Ping, ADFS or OneLogin. SSO is available on Enterprise plans; see the SSO documentation.

Consent log entries are kept for 12 months and then deleted automatically. The period is the same for every subscription. Deleted data remains in encrypted backups for at most 90 days.

Enterprise starts at 1,000,000 sessions a month. Book a demo or contact sales for a quote based on your traffic and requirements.

See CookieHub Enterprise in action

Book a 30-minute demo to walk through SSO, DSAR management, the API and reporting with our team, or send us your requirements below.

Talk to our sales team

Tell us about your sites, traffic and requirements, and we will get back to you.