Data Processing Agreement

Laatst bijgewerkt: August 23, 2026

This agreement forms part of the Terms of Service and applies automatically to every customer. A countersigned copy is available on request.

1. Parties and scope

This Data Processing Agreement ("DPA") is entered into between the customer ("Controller") and Armin Zaribaf, Libero professionista, VAT IT16634531004, Viale Giacomo Aicardi 8, 00177 Roma (RM), Italia ("Processor"), and forms part of the Terms of Service. It governs the Processor’s processing of personal data on the Controller’s behalf under Article 28 of Regulation (EU) 2016/679 ("GDPR"). Where the Controller and Processor conflict, this DPA prevails in respect of personal data.

2. Subject matter, duration, nature and purpose

The Processor provides a consent management platform: it serves a consent banner on the Controller’s websites, records the consent decisions of the Controller’s website visitors, and makes those records available to the Controller as evidence of consent. Processing lasts for the term of the Controller’s subscription and the retention period described in clause 8.

3. Categories of data subject and personal data

Data subjects are visitors to the Controller’s websites. For each consent event the Processor records: a pseudonymous consent identifier, the consent decision per purpose, the country and region derived from the visitor’s IP address, the website domain, a redacted referrer, any IAB TCF string, and the time of the event.

The Processor does not store visitors’ IP addresses or user-agent strings. The IP address is used transiently to derive an approximate country and to apply rate limiting, and is then discarded. No special categories of data under Article 9 GDPR are processed.

4. Processor obligations

  • Process personal data only on the Controller’s documented instructions, including as to international transfers, unless required otherwise by Union or Member State law.
  • Ensure that persons authorised to process the data are bound by confidentiality.
  • Implement the technical and organisational measures described in clause 6.
  • Taking into account the nature of the processing and the information available to it, assist the Controller by appropriate technical and organisational measures in responding to data subject requests, and with its obligations under Articles 32 to 36 GDPR. The Controller can fulfil most such requests itself using the export and deletion tools in the dashboard; where assistance goes beyond those tools, the Processor may charge its then-current professional-services rates.
  • Make available the information necessary to demonstrate compliance and allow for audits as described in clause 9.

5. Sub-processors

The Controller gives general authorisation for the Processor to engage sub-processors. The current list is published at /subprocessors. The Processor will update that page at least thirty (30) days before a new sub-processor begins processing; Controllers may subscribe to change notifications there. The Controller may object within that period on reasonable, documented data-protection grounds. If the parties cannot resolve the objection, the Controller’s sole and exclusive remedy is to terminate the affected service on written notice, with a pro-rata refund of prepaid fees for the unused term. Failure to object within the notice period is deemed approval. Each sub-processor is bound by data protection obligations no less protective than those in this DPA.

6. Security measures

  • Encryption of personal data in transit (TLS) and at rest.
  • Role-based access control, with permissions scoped per team and per banner, and least-privilege separation between support and operator roles.
  • Data minimisation by design: visitor IP addresses and user-agent strings are never persisted.
  • Audit logging of administrative actions, retained under a defined retention policy.
  • Backups with restoration testing, and monitored error reporting.

7. Personal data breaches

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s personal data, and will provide the information then reasonably available to it so that the Controller can meet its own obligations under Articles 33 and 34 GDPR. Information may be provided in stages as the investigation progresses. Notification is not an acknowledgement of fault or liability.

8. Retention, return and deletion

Consent records are retained for the period configured by the Controller, in order to serve as evidence of consent under Article 7(1) GDPR. Controllers can export their consent records at any time from the dashboard, and are responsible for doing so before termination. On termination the Processor will, at the Controller’s written request made within thirty (30) days, return or delete the personal data, and absent such a request may delete it. Copies held in routine encrypted backups are deleted on the ordinary backup rotation cycle rather than on demand, and remain subject to this DPA until then. The Processor may retain data where Union or Member State law requires it.

9. Audits

The Processor will make available the information necessary to demonstrate compliance with this DPA. The Controller’s audit right is satisfied in the first instance by the Processor’s written responses to a reasonable security questionnaire and by any third-party reports or certifications the Processor holds. An on-site or hands-on audit may be conducted only where those materials are genuinely insufficient or where a supervisory authority requires it, on at least thirty (30) days’ written notice, no more than once in any twelve-month period, during business hours, without disrupting the Processor’s operations, by the Controller or an independent auditor who is not a competitor of the Processor and who is bound by confidentiality. The Controller bears its own and the Processor’s reasonable costs of any such audit.

10. International transfers

Personal data is hosted in the European Union. Where a sub-processor listed at /subprocessors processes data outside the EEA, the transfer is made under the European Commission’s Standard Contractual Clauses or another valid transfer mechanism, together with any supplementary measures required.

11. Controller responsibilities

The Controller decides what personal data is collected through the Service and why. The Controller warrants that it has a valid legal basis for that processing, that its instructions — including its banner, category and regional configuration — comply with applicable data protection law, and that it has provided any notices and obtained any consents its own use requires.

The Service is a tool for recording and signalling consent. It does not constitute legal advice, and the Processor does not warrant that any particular configuration makes the Controller compliant with the GDPR, ePrivacy or any other law. The Controller is responsible for verifying that its configuration meets its own obligations.

The Controller will indemnify the Processor against claims, fines and costs arising from the Controller’s instructions, its configuration of the Service, or its failure to obtain a valid legal basis.

12. Liability

Each party’s total liability arising out of or in connection with this DPA is subject to the exclusions and the aggregate liability cap set out in the Terms of Service, and the parties’ liability under this DPA and the Terms of Service is counted together towards that single cap rather than separately. Nothing in this clause limits liability that cannot be limited by law, including a data subject’s rights under Article 82 GDPR.

See the Terms of Service for the applicable cap.

13. Contact

Data protection enquiries: [email protected] · Legal: [email protected]