Manage business consents and agreements
| Aspect | Organization-Level Consent | User-Level Consent |
|---|---|---|
| Scope | Applies to entire organization | Applies to individual user |
| Who Accepts | Legal representative (ADMIN_USER) | Individual user |
| Required For | Organization activation | User account activation |
| Examples | Business T&Cs, DPA, Corporate Privacy Policy | Employee/Director personal data consent |
| Legal Binding | Company is bound | Individual is bound |
ef4a8be6-602b-4b26-b81d-afa7d6d835fdtenant_cloudvaultapplication/jsontrue to accept the consente2f3a4b5-c6d7-48e9-0f1a-2b3c4d5e6f7a2026-01-13T10:04:10.579Ztruetrue| Field | Individual | Organization |
|---|---|---|
accepted | Required | Required |
acceptedBy | Not required | Required (User ID) |
acceptedDate | Not required | Required (ISO 8601 timestamp) |
| Consent Type | Endpoint | Status |
|---|---|---|
| Terms and Conditions | /consents/terms | Required |
| Privacy Policy | /consents/privacy | Required |
| Data Processing | /consents/data-processing | Required |
| Metadata Field | Description | Purpose |
|---|---|---|
| IP Address | Client IP from X-Forwarded-For header | GDPR compliance, fraud prevention |
| User Agent | Browser/device info from User-Agent header | Device tracking, audit trail |
| Acceptance Method | How consent was granted (e.g., “web_portal”, “api”) | Legal proof of consent |
| Accepted By | User ID of person accepting | Legal representative identification |
| Timestamp | Exact time of acceptance (ISO 8601) | Legal binding moment |
| Document Version | Version of T&C/Privacy Policy accepted | Track which terms were agreed to |
| Document URL | Link to the document accepted | Legal reference |
| Language | Language of the document | Multi-lingual compliance |
| Digital Signature | Optional cryptographic signature | Enhanced legal proof |
| Aspect | Individual Customer (B2C) | Organization Customer (B2B) |
|---|---|---|
| Consents | Personal T&C, Privacy Policy, Data Processing | Business T&C, Corporate Privacy Policy, Data Processing Agreement |
| Who Accepts | Individual user themselves | Legal representative (ADMIN_USER) |
| Scope | Personal data only | Company data + employee personal data |
| Legal Entity | Individual person | Legal business entity |
| Required Docs | Standard consumer docs | Business agreements, DPA |
| Revocation | User can revoke anytime | Requires authorized signatory |
| Activation Dependency | All 3 consents required | All 3 consents required |
| Version | Date | Changes |
|---|---|---|
| v1.0 | 2026-01-13 | Enhanced organization consents documentation |