Trust · Consent & GDPR

Consent that stops the tags.

Design the banner, decide what counts as essential, apply the right behaviour for each visitor's region — and crucially, enforce it. Decline a category and the matching capture genuinely never loads. Every choice is sealed into a tamper-evident ledger, and it all ships through the widget already on your site.

Auto by regionPer-category enforcementGPC & DNT honouredTamper-evident ledger
Analytics declined → blocked
Choice sealed into the ledger ✓
Live Choose · enforce · prove. We value your privacy Essentiallocked Analytics Marketing Save choice Reject GATE Analytics Marketing CONSENT RECEIPT Sealed ✓ Essentialgranted Analyticsgranted Marketingdeclined RegionEU · opt-in Hash9f3a…1b Tamper-evident · searchable · ready for the auditor.
Consent, done properly

A banner that actually enforces.

20+banner designs in the studio
Per-categoryenforced at the source
1–730days shared across group domains
HMACtamper-evident consent ledger
The difference

Not a banner — real enforcement.

A consent layer should stop technology, not decorate it. OpsIQ turns the visitor choice into a live operating rule: category off means capture off, tags dormant, receipts sealed, and the proof ready.

Enforcement gate

Decline a category and nothing runs.

Analytics, marketing and custom tags only wake when their category is granted. Refuse a category and matching capture is never loaded, never queued, never fired in the background.

Category offTracker never loads
Consent Mode v2Google receives the right signal
Receipt sealedEvery change lands in the ledger
visitor session
Your privacy choices
Essential
Analytics
Marketing
analytics_granted
marketing_blocked
Gate
GA4allowed
Ads pixelstopped
Ledgersealed
Consent selection studio

Design the exact choice your visitors see.

Inspired by the studio workflow: select a consent modal, edit its look, preview it at real size, then publish the behavior behind it.

Live preview — exactly what visitors see
Your categories

You decide what counts as essential.

Define the categories, write the visitor language, and mark what your business truly needs to function. Essential stays always-on; everything else remains a real visitor choice.

EssentialLogin, cart, security
Locked
AnalyticsGA4, heatmaps, journey stats
Visitor choice
MarketingAd pixels and retargeting
Visitor choice
PersonalisationRecommendations and preferences
Custom category
AI scanner14 cookies found · purposes drafted · categories mapped
Delivered & shared

One choice. One script.

No second snippet, no tag-manager wrestling. The banner is delivered through the same OpsIQ widget that runs your chat — so it boots before anything else, applies the visitor's region, and gates capture from the very first page-view. Run several domains under one workspace and a decision made on one carries across the rest of the group for the window you set, so visitors aren't re-prompted on every property — and your consent record stays consistent everywhere.

One script — the widget you already installed carries the banner too, geo-aware on boot.
Group-domain sharing — one choice carries across your sites for 1–730 days; a re-consent interval re-asks returning visitors.
Policy versioning — change the policy and everyone is re-prompted automatically.
Geo-awareright mode on boot
1 tagchat + consent
shop.com CHOICE MADE help.comconsent applied app.comconsent applied blog.comconsent applied
One tagchat + consent in one boot
1–730 daysshared across group domains
Geo-awareEU opt-in · US opt-out · GPC + DNT
Built for the auditor

Honest about what this is.

OpsIQ gives you the controls, records and documents to operate a defensible consent programme. It does not replace counsel or certify compliance; it makes the operational proof clean, searchable and ready.

GDPR / UK GDPRGranular opt-in
CCPA / CPRADo Not Sell / Share
Records & DPALedger + printable DPA
Proof vault controls active
Not legal advice
01
Controls you can operate

Region modes, category wording, withdrawal, GPC handling and re-consent intervals stay configurable inside the product.

02
Records you can produce

Every grant and revoke is sealed into the consent ledger, with exports that support DSAR and audit requests.

03
Clear boundaries

A tool cannot certify your compliance. OpsIQ gives your legal and operations teams the evidence trail they need.

Full feature list

Everything in Consent & GDPR.

Every capability, grouped. ★ marks a stand-out.

FeatureWhat it does
Design studio
20+ premium design layouts ★13 bars, 11 cards, 5 sheets and 5+ modals — genuinely distinct structures, not recolours.
Design palettes & colour system12+ named palettes give every layout a coherent, visually-distinct starting look.
Colour studio: solid / gradient / transparent ★Per-element colour modes with multi-stop gradients, angle control and live updates.
Typography controlPick the font stack and set heading, message and label sizes and colours.
Effects & visual finishesGlassmorphism, shadow, blur and opacity with automatic light/dark adaptation.
Motion & entrance animations10 entrance animations plus button variants and hover colours.
Brand logo uploadPut your logo on the banner and the preferences panels — upload or link.
Saved style presets NEWSave colours, typography, effects and motion as a reusable preset and apply it anywhere.
Position & layout control10 placements for card layouts plus width control.
Corner radius controlFrom sharp to fully rounded to match your brand shape.
Persistent reopen tabA floating "Cookie settings" tab so visitors can change or withdraw consent anytime.
Live preview (desktop & mobile)WYSIWYG at real device sizes, with animations replaying as you tweak.
Categories & enforcement
Admin-defined cookie categories ★Your own categories and wording — you decide what is essential.
Per-category enforcement ★Refuse a category and the matching capture genuinely stops at the source.
Auto-block third-party scripts ★Tag any script to stay dormant until its category is granted, then activate instantly.
AI cookie scanner & categorisation ★AI crawls your site, detects every cookie, categorises it and writes its purpose.
Cookie declaration tableA plain-language audit table of what you track, shown inside preferences.
Law & compliance
Auto-by-region (geo-aware) ★EU/UK opt-in, US opt-out with "Do Not Sell", a banner for the rest of the world.
Global Privacy Control (GPC) honour ★Treat a GPC signal as a valid opt-out, no banner needed.
Do-Not-Track (DNT) honour ★Treat a browser DNT signal as an opt-out automatically.
Do Not Sell or Share (CCPA) ★A CCPA/CPRA control for US visitors in opt-out mode.
Group-domain consent sharing ★One choice carries across your group domains for 1–730 days.
Re-consent intervalRe-ask returning visitors after N days for stricter regimes.
Policy versioning & auto-re-promptBump the policy version and everyone is re-prompted automatically.
Google Consent Mode v2 ★Emits the right gtag signals so GA4 and Google Ads obey consent natively.
IAB TCF v2.2 framework supportOptional __tcfapi surface and TC string for programmatic ads.
Content & localization
Multi-language with AI translation ★AI translates your wording into 30+ languages with browser auto-detect.
Editable button & link textSet every label and place policy links inline or below.
Additional custom linksAdd Terms, Imprint or other links with your own labels.
Consent choice durationHow long a choice is remembered — 1–730 days, default 180.
Show-after delay NEWHold the banner back by a set delay so page content paints first.
Compliance & audit
Consent ledger (tamper-evident) ★HMAC-chained hashes make a searchable, un-rewritable proof of every grant and revoke.
Admin access log ★Every view, edit, export and erasure recorded with a reason tag.
Data residency declarationDeclare EU / US / UK / APAC / other for your DPA.
Activity retention policySet an auto-delete window, or 0 to keep forever.
Consent Mode visitor capture NEWChoose Capture-all, Balanced, PII-only or Strict — even within a granted category.
Controller & DPO detailsName, address and DPO details that flow into the DPA.
Printable DPA template ★Auto-filled GDPR, UK GDPR and CCPA addendum, ready to print to PDF.
Data subject rights
DSAR export ★Export a contact's full archive as JSON — profile, activity, consent and access.
DSAR erasure ★Soft-delete and redact now, hard-delete after 30 days, with an audit trail.
Action Gateway for DSAREvery DSAR operation is role-checked and access-logged.
Analytics & insight
Consent analytics dashboard ★Live accept rates by category and domain, with a funnel and KPI cards.
AI consent analysis NEWAI reads your KPIs and writes the insights plus the next steps to take.
Delivery
Single-script delivery (via widget) ★The same opsiq.js that runs your chat carries the banner too — no second snippet.
Geo-aware bootDetect the visitor region on boot and apply the right law mode and language.
Master enable / disable toggleShow or hide the banner for all visitors immediately.
FAQ

Consent, answered.

Everything teams ask before they switch enforcement on — what "enforce" really means, region behaviour, group domains and the proof an auditor needs.

Most consent tools render a banner and assume scripts behave. OpsIQ wires the visitor's choice into the platform's own consent layer: with a category declined, the matching capture is never loaded — it doesn't fire "just once" and isn't merely hidden. Your own third-party tags can be marked to stay dormant until their category is granted, and Google Consent Mode v2 signals are emitted so GA4 and Google Ads obey natively.
No. The banner is delivered through the same OpsIQ widget that already powers your chat. One tag carries both, so consent is applied from the first page-view without a second snippet or tag-manager setup.
Yes. You define your own categories and wording, and you choose what is essential for your business. Essential stays always-on and can't be switched off by visitors; everything else is genuinely their choice. Nothing is forced on by OpsIQ.
Auto-by-geo gives EU/UK visitors opt-in (nothing non-essential runs until they accept) and US visitors opt-out with a "Do Not Sell or Share" control. Browser Global Privacy Control (GPC) and Do-Not-Track (DNT) signals are honoured whichever mode you pick. You can also force opt-in or opt-out everywhere.
If you enable group-domain sharing, a decision made on one of your workspace's domains carries to the others for the number of days you set (1–730), so visitors aren't re-prompted on every property. A re-consent interval can re-ask returning visitors after N days, and changing your policy version re-prompts everyone automatically.
The consent ledger is a searchable, tamper-evident record of every grant and revoke by contact, channel, action and date — each entry HMAC-chained to the one before it. Alongside it sit an admin access log, residency & retention settings, and a printable DPA that fills in your controller, DPO, residency and retention values automatically.
Yes. DSAR export and erasure are built in and run through the Action Gateway, so the operations are role-checked and logged. You can find the person, prove their consent state, hand them a copy, and erase on request.
Usually not. Google ads already obey Consent Mode v2 and every other tag is handled by auto-blocking — no CMP ID required. TCF is only for sites running IAB-framework programmatic ads; if you need it, OpsIQ can expose a __tcfapi surface and a per-visitor TC string.