This translation is provided for information only and does not form part of the agreement. The DPA is concluded in Polish (§21(8) of the Terms of Service), and the binding version is available at cookieofficer.pl/dpa.
Preamble
This Data Processing Agreement ("DPA") forms an integral part of the CookieOfficer Terms of Service (the "Terms") and is concluded when an Account is created on the Website. It sets out the rules for the processing of personal data by the Processor on behalf of the Controller in connection with the provision of the Service.
The DPA is entered into between: the Controller - the entity that created an Account on the CookieOfficer Website and is indicated as the owner of the Account, and the Processor - Wojciech Bednarski DataWolves, ul. Fabryczna 3/9, 97-545 Wojciechów, Poland, NIP (Polish tax identification number) 7722307415, REGON 382702660.
In the event of a conflict between the DPA and the Terms, the DPA prevails in matters of personal data protection.
Corporate customers may execute the DPA as a separate signed document. To arrange this, write to kontakt@cookieofficer.pl.
§1. Definitions
- GDPR - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
- Personal Data - personal data within the meaning of Article 4(1) GDPR, entrusted to the Processor by the Controller in connection with the provision of the Service.
- Processing, Controller, Processor, Personal Data Breach - terms with the meaning given in Article 4 GDPR.
- Service - the CookieOfficer cookie management platform, comprising: the cookie and tracking technology scanner, the cookie declaration generator, the consent banner editor, and the consent log.
- Sub-processor - a further processor whose services the Processor uses in the Processing of Personal Data.
- Visitor - a natural person visiting the Controller's website on which the Service operates.
- Consent Log - the record, maintained within the Service, of Visitors' decisions concerning consent to cookies and related technologies.
§2. Subject matter, nature and purpose of processing
The Processor processes Personal Data solely for the purpose of providing the Service to the Controller, in accordance with the Terms and the Controller's documented instructions.
The nature and purpose of the processing, the categories of data and the categories of data subjects are set out in Annex 1.
The processing continues for the term of the Terms, extended by the periods indicated in §11.
The Controller represents that it is entitled to entrust the Personal Data and that it has a legal basis for processing it, in particular for displaying a consent banner and maintaining a Consent Log on the domains it designates.
§3. The Controller's instructions
The Processor processes Personal Data only on the Controller's documented instructions, including as regards transfers of data to a third country, unless required to do so by Union or Member State law. In that case the Processor informs the Controller of that obligation before the processing begins, unless the law prohibits this.
The following are considered documented instructions:
- the Terms,
- this DPA,
- the configuration made by the Controller in the Service panel,
- instructions given in writing or by email from an address associated with the Account.
The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions (Article 28(3), second sentence, GDPR).
3.1. Instruction concerning aggregated and anonymised data
The Controller instructs the Processor to aggregate and irreversibly anonymise Personal Data for the purposes of:
- developing, testing and improving the Service,
- producing aggregate statistics on the prevalence of tracking technologies and cookie management platforms,
- detecting abuse and ensuring the security of the Service.
Anonymisation takes place before the data is used for the indicated purposes and is irreversible. Once carried out, the data no longer constitutes personal data and is not subject to the GDPR or to this DPA. The Processor does not use Personal Data in identifiable form for any of the purposes indicated in this clause.
The Controller may withdraw this instruction at any time by sending a statement to: kontakt@cookieofficer.pl.
§4. The Processor's obligations
The Processor undertakes to:
- process Personal Data only within the scope and for the purpose set out in the DPA;
- ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under a statutory obligation of secrecy (Article 28(3)(b) GDPR);
- implement the technical and organisational measures referred to in §5;
- comply with the conditions for engaging Sub-processors set out in §6;
- provide the Controller with the assistance referred to in §7 and §8;
- delete or return Personal Data in accordance with §11;
- make information available to the Controller and allow for audits in accordance with §12;
- maintain a record of categories of processing activities carried out on behalf of the Controller (Article 30(2) GDPR).
§5. Security of processing
The Processor implements technical and organisational measures appropriate to the risk, as referred to in Article 32 GDPR. The current list of measures is set out in Annex 2.
The Processor may change the security measures, provided this does not reduce the level of protection of Personal Data.
The Processor records the values of Visitors' cookies and browser storage entries only as a sample fragment, so that the cookie declaration can show the format of the data. A value that looks like an identifier, a token or an email address is masked. In the Consent Log the Processor does not store Visitors' full IP addresses, only their truncated form. This is a contractual undertaking, not merely a technical description.
§6. Sub-processors
The Controller grants the Processor general authorisation to engage Sub-processors (Article 28(2), second sentence, GDPR).
The current list of Sub-processors constitutes Annex 3 to the DPA.
The Processor gives notice of an intended change of Sub-processor, the addition of a new one or the replacement of an existing one, at least 30 days before that entity begins processing. Notice is given by email to the address associated with the Controller's Account and by updating Annex 3.
The Controller may raise a reasoned objection to a new Sub-processor within 30 days of receiving the notice. The parties will attempt in good faith to agree on a solution. If no solution is agreed within 30 days of the objection, the Controller has the right to terminate the Terms in respect of the services affected by the objection.
The Processor imposes on each Sub-processor, by contract, data protection obligations equivalent to those in this DPA and remains fully liable to the Controller for that Sub-processor's performance of its obligations (Article 28(4) GDPR).
The Processor discloses that its transactional email provider uses its own further subcontractors established in the United States, including providers of artificial intelligence services. The list is published by that provider. Email addresses and the content of system messages sent to the users of the Controller's Account pass through that chain. The Controller acknowledges this on entering into the DPA.
§7. Assistance with data subject rights
The Processor, taking into account the nature of the processing, assists the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to requests from data subjects (Chapter III GDPR).
The Service provides the Controller with tools in the panel that allow it, on its own, to:
- look up a consent record by its consent identifier,
- export the Consent Log.
On the Free plan, where export is not available in the panel, the Processor performs it at the Controller's request, at no additional charge. The retention period for records follows from the plan and cannot be configured by the Controller (§10).
If a data subject contacts the Processor directly, the Processor does not respond on the merits but promptly forwards the request to the Controller, provided it is able to identify the relevant Controller, and informs the requesting person that it has done so.
The assistance referred to above is provided at no additional charge within the scope of the features available in the panel. For activities going beyond the features available in the panel, the Processor may charge a reasonable fee. It informs the Controller of its amount before performing the activity.
§8. Data breaches, DPIA and consultations
The Processor notifies the Controller of a confirmed Personal Data Breach without undue delay (Article 33(2) GDPR).
The notification contains at least:
- a description of the nature of the breach,
- the categories and approximate number of data subjects and records concerned,
- the likely consequences,
- the measures taken or proposed,
- contact details for further information.
If it is not possible to provide all the information at the same time, the Processor provides it in phases.
The Processor does not notify the supervisory authority or data subjects on the Controller's behalf, unless the Controller expressly authorises it to do so. The obligations under Articles 33 and 34 GDPR rest with the Controller.
The Processor assists the Controller in complying with the obligations set out in Articles 32 to 36 GDPR, including in carrying out a data protection impact assessment (DPIA) and prior consultations, to the extent corresponding to the nature of the processing and the information available to the Processor.
§9. Transfers of data outside the EEA
The Processor stores the Consent Log and scan results within the territory of the Republic of Poland. Traffic to the Service passes through the CDN network indicated in Annex 3, including outside the EEA. Encrypted backups of that data are entrusted to a company established in the United States, with the storage location set to the European Union. That entrustment constitutes a transfer within the meaning of Chapter V GDPR and relies on Standard Contractual Clauses.
The other components of the Service, in particular the customer panel, authentication, the account database and transactional email, run with providers that transfer data to third countries. The list and the transfer bases are set out in Annex 3.
Every transfer outside the EEA relies on:
- a European Commission decision finding an adequate level of protection (Article 45 GDPR), including the Data Privacy Framework (DPF) programme,
- or Standard Contractual Clauses (SCC, Article 46(2)(c) GDPR), supplemented by additional measures identified in a transfer impact assessment.
Transfers in which the Processor acts as a processor and the recipient as a further processor are governed by Module Three of the Standard Contractual Clauses.
If a transfer basis ceases to apply or is invalidated, the Processor will promptly implement an alternative mechanism or, if that is not possible, cease the transfer and inform the Controller.
§10. Consent Log, specific provisions
The Consent Log serves to demonstrate that consent was collected correctly (Articles 5(2) and 7(1) GDPR). The Controller is the controller of the data in the Consent Log; the Processor maintains it on the Controller's instructions.
The retention period for a consent record follows from the plan purchased from the Processor:
- Free plan - 3 months
- Basic plan - 12 months
- Pro plan - 36 months
- Enterprise plan - 60 months
The Controller, as the party deciding on the purposes of the processing, is responsible for choosing a plan matched to the purpose for which it collects consent.
If a Visitor changes their decision, including withdrawing consent, a new record with the current decision is written alongside the original record: timestamp, scope and domain. Consent Log records are append-only and are not modified once written, so the original record remains in the log as evidence of the earlier decision.
Both records are retained for the period following from the plan, counted separately for each of them from the date it was written. The Processor does not retain consent records indefinitely.
The scope of the data recorded in the Consent Log is set out in Annex 1.
§11. Deletion or return of data
After the provision of the Service ends, the Processor, depending on the Controller's decision, returns or deletes the Personal Data and deletes existing copies, unless Union or Member State law requires their further storage (Article 28(3)(g) GDPR).
The Controller has 30 days from the end of the provision of the Service to obtain a copy of the data, including the Consent Log. Within that period the Processor provides a copy at the Controller's request, at no additional charge. The Controller may also carry out the export itself in the panel before the provision of the Service ends.
After the period referred to above, the Processor deletes the Personal Data within a further 30 days. Data disappears from backups as the backup itself expires, after 6 months at the latest, and after a backup is restored the Processor again deletes from it the data previously erased.
Consent Log records are deleted within the periods set out in §10, counted separately for each record from the date it was written. This applies also to the period after the provision of the Service has ended, because a consent record is evidence the Controller relies on before a supervisory authority.
At the Controller's request, the Processor issues written confirmation of the deletion of the data.
§12. Audits and information
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations under Article 28 GDPR (Article 28(3)(h) GDPR).
The Processor fulfils this obligation in the first instance by making available the documentation of its security measures and by answering the Controller's security questionnaire, within 30 days of the request.
If that information proves insufficient, the Controller has the right to an audit or inspection, including by an authorised external auditor, on the following conditions:
- notice of at least 30 days,
- no more than once per calendar year (unless the audit follows a Personal Data Breach or is requested by a supervisory authority),
- during business hours,
- without disrupting the Processor's operations,
- with confidentiality preserved and without access to the data of the Processor's other customers.
The costs of the audit are borne by the Controller, unless the audit reveals a material breach of the Processor's obligations, in which case the costs are borne by the Processor.
§13. Provisions concerning the California CCPA
To the extent the Processor processes personal information of consumers subject to the California CCPA as amended by the CPRA, the Controller acts in the role of a business and the Processor in the role of a service provider.
The Processor certifies that it:
- does not sell or share that personal information;
- does not retain, use or disclose it for any purpose other than performing the services specified in the contract, or outside the direct business relationship with the Controller;
- does not combine it with personal information received from other sources, except as permitted by the CCPA;
- understands the above restrictions and undertakes to comply with them;
- undertakes to comply with the obligations the CCPA imposes on a service provider;
- grants the Controller the right to take reasonable steps to stop and remediate unauthorised use of the data;
- will promptly notify the Controller if it determines that it can no longer meet them.
§14. Liability
The liability of the Parties arising from this DPA is governed by §14 of the Terms, subject to the exceptions indicated below.
The limitations of liability do not apply to:
- liability towards data subjects under Article 82 GDPR,
- administrative fines imposed on a Party through its sole fault,
- damage caused intentionally.
The limit set out in §14 of the Terms applies jointly to claims under the Terms and under this DPA and is not cumulative.
§15. Final provisions
The DPA takes effect when the Account is created and remains in force for the term of the Terms.
The Processor may amend the DPA where this is required by changes in the law, case law or the guidance of supervisory authorities, or by changes in the Service. It gives at least 30 days' notice of a material change; the Controller then has the right to terminate the Terms.
The DPA is governed by Polish law. Disputes are resolved by the court having jurisdiction in accordance with the Terms.
If any provision of the DPA proves invalid, the remaining provisions remain in force and the Parties will replace it with a provision closest to its economic purpose.
Annex 1. Description of processing
A. Categories of data subjects
The entrustment covers the data of Visitors to the Controller's websites on which the CookieOfficer consent banner operates.
The data of the users of the Controller's Account (employees, contractors, team members) is processed by the Processor as an independent controller, not on the basis of this entrustment. That processing is described in the Privacy Policy.
B. Categories of personal data
Consent Log
The Consent Log comprises the following data: the pseudonymous consent identifier stored in the Visitor's browser, the timestamp of the decision, the scope of consent (categories accepted and rejected), the banner version and language, the cookie declaration version, how consent was expressed, browser information (the User-Agent header), the truncated IP address and country, and the domain on which the consent was collected.
Records in the Visitor's browser
The CMP engine stores only the following information in the Visitor's browser. None of it contains the Visitor's first and last name or email address.
| Record | Type | What it contains | How long |
|---|---|---|---|
co_consent | cookie on the Controller's domain | the scope and time of the decision, the pseudonymous consent identifier, the Project identifier, a Global Privacy Control signal flag | the period set by the Controller, 365 days by default |
__coQ | browser storage on the Controller's domain | a queue of consent proofs that could not be sent, up to five entries, each with the host, language and full decision | 30 days |
co-geo-<id> | browser storage on the Controller's domain | the Visitor's country code, determined on the server side | 24 hours |
co-cfg-<id> with two auxiliary keys | browser storage on the Controller's domain | a copy of the banner configuration, without any Visitor data | until the configuration changes |
co-bulk-<id> | browser storage on the Processor's domain | written only when consent sharing within a domain group is enabled | 30 days |
Cookie scanner
The cookie scanner comprises the following data: the name, domain and path of the detected tracking technology, its type, lifetime, attributes (HttpOnly, Secure, SameSite), how it was set together with the address of the script that set it, the consent phase, the category and vendor, and a masked fragment of a sample value.
Service configuration
The Service configuration comprises the following data: the banner configuration and the Controller's list of domains.
First and last name, business email address, role in the organisation, activity logs in the panel and sign-in history together with the IP address and browser information relate to the users of the Account. The Processor processes them as an independent controller, outside the entrustment, on the terms described in the Privacy Policy.
The Processor does not process the following data: Visitors' full IP addresses in the Consent Log, Visitors' first and last names or email addresses, special categories of data under Article 9 GDPR, or data under Article 10 GDPR. The scope of the cookie values and browser storage entries the Processor does record is set out in §5.
C. Nature and purpose of processing
The processing comprises collecting, recording, storing, organising, consulting and making the data available to the Controller in the panel, as well as deleting it. The purpose of the processing is detecting tracking technologies on the designated domains, generating cookie declarations, displaying a consent banner and recording Visitors' decisions.
D. Duration of processing
The data is processed for the term of the Terms, extended by the periods set out in §11 of the DPA. The Consent Log is processed in accordance with §10 of the DPA.
Annex 2. Technical and organisational measures (Article 32 GDPR)
This list reflects the factual position as at the date the DPA takes effect. Changes to the security measures are governed by §5 of the DPA.
Pseudonymisation and minimisation
The Processor applies the following pseudonymisation and minimisation measures:
- It records the values of Visitors' cookies and browser storage entries only as a sample fragment, so that the cookie declaration can show the format of the data. A value that looks like an identifier, a token or an email address is masked.
- In the Consent Log it does not store Visitors' full IP addresses, only their truncated form. An address stored in that form remains personal data and is subject to this DPA.
- It uses a pseudonymous consent identifier that is not linked to the Visitor's identity. If the Controller enables consent sharing within a domain group, the same identifier is carried across the domains of that group, so that the Visitor does not have to answer the banner separately on each of them. Outside such a group, identifiers are not linked to one another.
- It does not store full payment card details.
Confidentiality and integrity
The Processor applies the following measures ensuring the confidentiality and integrity of the data:
- All connections to the Service and to the CMP engine are encrypted using TLS 1.2 or later.
- User passwords are stored only as cryptographic hashes. Authentication is provided by Firebase Auth, and the Processor has no access to passwords in plain text.
- The production and test environments are separated from each other, and production data is not used in testing.
- All persons with access to the data are bound by confidentiality obligations.
Location and availability
The Processor provides the following data location and availability measures:
- The Consent Log and scan results are stored within the territory of the Republic of Poland, subject to the conditions and reservations described in §9 of the DPA.
- Encrypted backups are stored with a provider whose data storage location is in the European Union. Data disappears from a backup as the backup itself expires, after 6 months at the latest (§11 of the DPA).
- The Service is protected against volumetric attacks at the CDN/WAF layer.
Accountability
The Processor ensures the accountability of data processing by:
- Maintaining a record of categories of processing activities (Article 30(2) GDPR).
- Implementing a personal data breach handling procedure.
The Processor implements and documents the technical and organisational measures described above. It makes the documentation available to the Controller on the terms set out in §12 of the DPA.
Annex 3. List of Sub-processors
As at the date the DPA takes effect. The Processor gives notice of changes to the list on the terms set out in §6 of the DPA.
- Sub-processor: OVH sp. z o.o., ul. Swobodna 1, 50-088 Wrocław, Poland, KRS 0000220286
- Scope: hosting of the CMP engine, the Consent Log, scan results, the enquiry register, the contact mailbox
- Processing location: Warsaw, Poland
- Transfer basis: no transfer
- Sub-processor: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Scope: hosting of the panel, authentication, account database
- Processing location: Ireland; transfer to Google LLC in the USA
- Transfer basis: adequacy decision (Data Privacy Framework, DPF), with Standard Contractual Clauses (SCC, Article 46(2)(c) GDPR) as a fallback
- Sub-processor: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA
- Scope: CDN, DNS, WAF, encrypted backups with the storage location in the European Union. The IP addresses of persons visiting the Controller's websites pass through the CDN network
- Processing location: USA
- Transfer basis: Standard Contractual Clauses (SCC, Article 46(2)(c) GDPR)
- Sub-processor: Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA
- Scope: transactional email
- Processing location: USA
- Transfer basis: Standard Contractual Clauses (SCC, Article 46(2)(c) GDPR)
- Sub-processor: Stripe Payments Europe, Limited, One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland, CRO 513174
- Scope: payment processing on the Processor's instructions
- Processing location: Ireland; transfer to Stripe, LLC in the USA
- Transfer basis: adequacy decision (Data Privacy Framework, DPF), with Standard Contractual Clauses (SCC, Article 46(2)(c) GDPR) as a fallback
Note: In respect of part of the processing, Stripe acts as an independent controller (fraud prevention, AML/KYC obligations). To that extent it is not a Sub-processor and is not subject to this DPA.