LEGAL INFORMATION

Infrastructure and jurisdictions

Version: 1.0, updated 31 August 2026

This translation is provided for information only. The binding version is the Polish one, available at cookieofficer.pl/infrastruktura.

This page fulfils the obligation under Article 28 of Regulation (EU) 2023/2854 (the Data Act). We describe the infrastructure on which the CookieOfficer services run, the law to which that infrastructure is subject and the measures we apply to counter unlawful access to data by third-country authorities. We update this page whenever the list of providers changes.


Where the services run and the law to which they are subject

ProviderRoleProcessing locationJurisdiction
OVH sp. z o.o., WrocławHosting of the CMP engine, the Consent Log, scan results, the enquiry register, the contact mailboxWarsaw, PolandPolish law and European Union law
Google Ireland Limited, DublinHosting of the customer panel, authentication, account databaseIreland, with transfer to Google LLC in the USAIrish and EU law; the parent company is subject to United States law
Cloudflare, Inc., San FranciscoCDN, DNS, WAF, encrypted backups with the storage location in the European UnionUSA, backups stored in the EUUnited States law
Plus Five Five, Inc. (Resend), San FranciscoTransactional emailUSAUnited States law
Stripe Payments Europe, Limited, DublinPayment processingIreland, with transfer to Stripe, LLC in the USAIrish and EU law; the affiliated company is subject to United States law

The Consent Log and scan results are stored within the territory of the Republic of Poland. Some of the providers listed above are subject to United States law, which means that the laws of that country on the disclosure of data to public authorities may, in principle, apply to those providers; we describe the measures that limit this risk below.


Measures against access by third-country authorities

We apply technical, organisational and contractual measures that limit the risk of unlawful access to data, including non-personal data, by third-country authorities. We store the most important data, that is, the Consent Log and scan results, in Poland, with a provider subject to Polish and EU law. All connections to the services are encrypted using TLS 1.2 or later, and backups are encrypted, with the storage location in the European Union. We and the providers subject to the law of third countries are bound by Standard Contractual Clauses, supplemented by additional measures resulting from the transfer impact assessment we have carried out. These providers publish transparency reports and declare that they assess the lawfulness of every request from a public authority, challenge requests that are excessive or unfounded, and inform their customer of a request unless the law prohibits this. Where a request for the disclosure of data is addressed directly to us, we comply with it only if it has a basis in Union law or Polish law and only to the extent necessary, and we inform the Customer whose data the request concerns, unless the law prohibits such notification. We also limit the scope of the data we store: we do not store full IP addresses in the Consent Log, and we record cookie values only as masked sample fragments.


Related documents

The list of processors of personal data, together with the transfer bases, is set out in Annex 3 to the Data Processing Agreement (DPA). The rules for processing personal data are described in the Privacy Policy. The rules for using the Service are set out in the Terms, §17(10) of which indicates the address of the Polish version of this page.


Updates to this page

The date of the last update is given below the title of this page. We update this page together with every change to Annex 3 to the Data Processing Agreement, in the same release. The obligation to keep this information up to date arises from §17(10) of the Terms.