LEGAL DOCUMENT

CookieOfficer Terms of Service

Version: 1.0, effective from the date of publication

This translation is provided for information only and does not form part of the Agreement. The Agreement is concluded in Polish (§21(8)), and the binding version is available at cookieofficer.pl/regulamin.


§1. General provisions

  1. These Terms set out the rules for the provision of services by electronic means on the CookieOfficer platform.
  2. The Service Provider is Wojciech Bednarski, conducting business under the name DataWolves, with its principal place of business at ul. Fabryczna 3/9, 97-545 Wojciechów, Poland, NIP (Polish tax identification number): 7722307415, REGON: 382702660 (hereinafter: the Service Provider).
  3. The Service Provider can be contacted by email at kontakt@cookieofficer.pl or by phone at +48 515 166 748.
  4. The following annexes are attached to these Terms and form an integral part of them: the Data Processing Agreement (DPA), available at cookieofficer.pl/dpa, the Privacy Policy, available at cookieofficer.pl/polityka-prywatnosci, and the Price List, available at cookieofficer.pl/cennik.
  5. In the event of a conflict between the provisions of these Terms and the Data Processing Agreement (DPA), the provisions of the DPA prevail in matters concerning the protection of personal data.

§2. Definitions

TermMeaning
ServiceThe CookieOfficer cookie management platform, a comprehensive tool comprising a cookie and tracking technology scanner, a cookie declaration generator, a consent banner editor, the Consent Log and the customer panel
CustomerAn entrepreneur that has concluded the Agreement with the Service Provider
AccountThe Customer's individual, password-protected profile on the Website
AgreementThe agreement for the provision of the Service, concluded on the terms set out in these Terms
WebsiteThe websites available at cookieofficer.pl and cookieofficer.com, together with their subdomains and the customer panel
CMP EngineA script embedded on the Customer's website that displays the consent banner and records Visitors' decisions
DomainThe address of a website added by the Customer to the Account
ProjectThe configuration of the Service for a main Domain and any additional Domains, together with the related Consent Log and scan history
VisitorA person using the Customer's website
Consent LogThe record of Visitors' decisions concerning consent to cookies
PageviewEach visit to an address of the Customer's website on which the CMP Engine has started, including a route change in a single-page application and a return to the page from the browser's cache. Pageviews are counted together for the whole Project, regardless of whether the banner was displayed (it is not shown on pages excluded by the Customer, to a Visitor who has valid consent, or outside the region in which the Customer requires consent)
Not counted as PageviewsTraffic from recognised bots and crawlers, pages preloaded by the browser in advance, embeddings of the page in frames, and traffic from the test alias
Subpage LimitThe maximum number of subpages that the scanner can process on a single Domain in a Limit Period
Billing PeriodThe period for which the fee is charged, monthly or yearly, as chosen by the Customer
Limit PeriodThe period in which the use of limits is counted: for the Pageview limit, consecutive monthly windows counted from the day on which the Project became subject to a plan with a limit, and for the Subpage Limit, a calendar month. The Limit Period is independent of the Billing Period, also with a yearly payment cycle
Trial PeriodA free period for testing the Service on the terms set out in §5(3) of these Terms
Free PlanThe plan designated in the Price List as Free
Price ListAn annex to these Terms setting out the plans, features, limits and fees, available at the address indicated in §1(4)
DPAAn annex to these Terms, the Data Processing Agreement, available at the address indicated in §1(4)
Privacy PolicyAn annex to these Terms, available at the address indicated in §1(4)

§3. Who may use the Service

  1. These Terms do not apply to consumers. The Service is intended for entities that order it in direct connection with their business or professional activity, where the agreement is of a professional nature for them.
  2. By creating an Account, the Customer represents that it meets the condition set out in clause 1.
  3. If, after the Agreement has been concluded, it turns out that the Customer has the status of an entrepreneur with consumer rights within the meaning of Article 385⁵ of the Polish Civil Code, the Service Provider may terminate the Agreement with immediate effect and refund the fee for the unused period. This does not exclude the Service Provider's other claims, in particular those related to making the untrue representation referred to in clause 2.
  4. Only a person who is at least 18 years old and is authorised to represent the entity creating the Account may be a Customer.

§4. Conclusion of the Agreement and the Account

  1. The Agreement is concluded when the Account is created and these Terms, together with their annexes, are accepted.
  2. Accepting these Terms is equivalent to concluding the data processing agreement (DPA). Under that agreement, the Customer acts as the data controller and the Service Provider as the processor.
  3. The Service Provider records the fact and the exact time of acceptance of these Terms and their annexes, storing the Customer's email address, the list of documents presented and their versions. This data is kept as proof that the Agreement was concluded.
  4. The Customer undertakes to provide true and up-to-date data. If the data changes, the Customer must update it in the customer panel.
  5. The Customer is responsible for keeping its login details confidential and for all actions taken on its Account. If unauthorised access is suspected, the Customer must inform the Service Provider without delay.
  6. The Customer may add team users to its Account, within the limit set for the selected plan. The Customer is responsible for the actions of those users as for its own.

§5. Scope of the Service, plans and limits

  1. The scope of the available features and the applicable limits are set out in the Price List. The limits include in particular: the number of supported Domains, the number of views (Pageviews) in a Limit Period, the number of team users, the frequency of automatic scans, the Subpage Limit and the ability to export data.
  2. The Domain limit applies to the whole Account, not to a single Project. The Subpage Limit is granted separately for each Domain and depends on the measured size of the website.
  3. Trial Period. A new Customer is entitled to a 14-day free Trial Period on the Pro plan. Rules of the Trial Period:
    • the Trial Period does not require payment card details and does not end with an automatic charge;
    • the Trial Period starts when the email address is confirmed and lasts for the following 14 days, until midnight of the fourteenth day, Warsaw time;
    • the Trial Period is available once per Account and once per email address, even if the Account is deleted and created again;
    • during the Trial Period, one Project and one Domain are available, because the Domain limit during that time follows from the Free Plan;
    • after the Trial Period ends, the Project returns to the Free Plan and the Account remains active. The CMP Engine remains available for only one Domain, which is the main Domain of the oldest Project in the Account, provided that its measured size is within the limit for the Free Plan set out in the Price List. If the size of the Domain has not been measured, the Domain continues to be supported. In all other cases, the CMP Engine ceases to be available until a paid plan is purchased.
  4. The Free Plan may be restricted or withdrawn on 30 days' notice.
  5. Unused limits do not carry over to the next Limit Period and are not refundable.
  6. Exceeding the Pageview limit. The Customer can check the current use of the limit in the customer panel. The Service Provider additionally sends email notifications when use approaches the limit and when the limit is exceeded. These notifications are for information only and do not release the Customer from the obligation to monitor use, to choose an appropriate plan matched to the traffic on its website and to keep its payment details up to date. If the Customer does not switch to a plan with a higher limit by the end of the day on which the Service Provider sent the notification that the limit had been exceeded, the CMP Engine ceases to be available for the Customer's Domains. This means that the consent banner stops being displayed, and with it the blocking of scripts before consent is obtained stops working. The Customer acknowledges that this is a consequence of exceeding the purchased limit and that from that moment full responsibility for ensuring compliance on the Customer's websites rests solely with the Customer. The Service Provider restores access to the CMP Engine without delay once the Customer switches to a plan with a higher limit.
  7. Exceeding the Subpage Limit suspends manual scans and scans requested via the API. Automatic scans continue to be performed and are counted against the current Subpage Limit. Regardless of the individual Subpage Limit granted to the Customer, the Service Provider applies a general limit on the number of measurements for a given Domain, covering all Accounts to which the Domain has been added. Once this limit is reached, manual scans and scans requested via the API are suspended until the end of the Limit Period, even if the Customer has not used up its individual Subpage Limit.
  8. The Service Provider reserves the right to develop the Service, add new features and modify the interface. A material restriction of features or limits within the Customer's plan requires prior notice of at least 30 days and entitles the Customer to terminate the Agreement.
  9. The free demonstration scan publicly available on the Website is illustrative and covers a limited number of subpages. It is not a full analysis of the website, and a positive result does not mean that the website fully complies with the law.
  10. Technical requirements. To use the Service, the following are required: a device with internet access; an active email address; for the CMP Engine, a web browser supporting the ECMAScript 2019 standard or later, including Google Chrome from version 73, Microsoft Edge from version 79, Mozilla Firefox from version 63 and Safari from version 12.1, with JavaScript and cookies enabled, as well as the ability to place the script code on the Customer's website; for the customer panel, a web browser in a version supported by its manufacturer, released no earlier than 2023. The Service Provider does not guarantee that the Service works correctly in browsers for which the manufacturer has ended support, or with JavaScript disabled.

§6. Rules for using the scanner

  1. The Customer represents that it is entitled to scan each Domain added to the Account, as the owner, as the administrator or on the basis of the consent of the person entitled to give it. This representation is made both when a Domain is added and each time a scan is requested.
  2. The Service Provider does not verify the Customer's legal title to the Domain. The sole basis for performing a scan is the representation made by the Customer, and responsibility for its truthfulness rests with the Customer.
  3. The following are prohibited in particular: scanning Domains for which the Customer has no authorisation; using the scanner for reconnaissance of infrastructure in order to carry out an attack; attempting to circumvent request limits, for example by creating multiple Accounts; requesting scans in such a large volume that they may disrupt the operation of the scanned website.
  4. The scanner works in two modes, which differ in how they handle the robots.txt file:
    • in subpage counting mode, before the scan, the scanner respects the rules set out in the robots.txt file of the scanned Domain, including the crawl-delay parameter. If the server returns an error, this is treated as a prohibition of access. No response, or the absence of the file itself, means that there are no rules;
    • the actual scan concerning cookies is performed on the subpages indicated by the Customer or determined in the previous step and does not read the robots.txt file again.
  5. The scanner identifies itself as CookieOfficerBot/1.0 and gives the address of an information page that describes the rules of its operation and how to block it.
  6. The scanner covers only publicly available resources. Areas that require logging in are not scanned.
  7. The Service Provider may introduce request rate limits and cache results. The scope and values of these limits may change and do not constitute an obligation towards the Customer or the owner of the scanned website.
  8. In the event of a reasonable suspicion of a breach of clause 1 or 3, the Service Provider may suspend the scanning of the Domain concerned or suspend the Account, informing the Customer of this.
  9. The Customer indemnifies the Service Provider against liability towards third parties for claims arising from the scanning of a Domain for which the Customer was not authorised.

§7. Customer's obligations

  1. The Customer is the controller of the personal data of Visitors to its websites and is responsible for: choosing the legal bases for processing, the content of the information displayed in the consent banner, the retention period of the Consent Log (in accordance with the selected plan) and fulfilling the rights of data subjects.
  2. The Customer is responsible for correctly embedding the CMP Engine on its websites and for correctly configuring the blocking of tracking scripts until consent is obtained.
  3. The Service is a supporting tool and does not replace legal advice. The categorisation of tracking technologies and the generated declarations are auxiliary and require verification by the Customer. The Service Provider does not guarantee that using the Service in itself ensures full compliance with the law; ultimate compliance depends on the Customer's decisions and configuration. The Service Provider recommends consulting a lawyer or a data protection officer about the banner configuration and the categorisation.
  4. The Customer may not resell access to the Service or make its Account available to third parties, unless it participates in the Partner Programme on separate terms.
  5. Prohibition of unauthorised use of the Service. It is prohibited to decompile, copy or create derivative works based on the Service, and to download its content automatically beyond the scope of the API made available. It is also prohibited to use the Service to design, build or develop competing products.
  6. Prohibition of providing unlawful content. The Customer undertakes not to provide unlawful content, including content that infringes the rights of third parties, personal rights, intellectual property rights or data protection laws. This applies in particular to data entered into the Account, the content of the consent banner, cookie declarations and materials sent in support requests. On receiving an official notice or credible information about the unlawful nature of such content, the Service Provider will disable access to it, notifying the Customer at the same time.
  7. API access keys. API access keys are confidential, assigned to a specific Account and may not be passed on to third parties. The Customer is responsible for all actions performed using its keys. The Service Provider may revoke a key if it has a reasonable suspicion that the key has been disclosed, and may modify the scope and version of the API, giving notice of material changes at least 30 days in advance.
  8. Up-to-date Account details. The Customer must keep the email address assigned to the Account and its payment details up to date. The Customer is responsible for the consequences of these details being out of date, including not receiving the notifications referred to in §5(6) and in §9.

§8. Classification of tracking technologies

  1. Detected tracking technologies are classified automatically and reproducibly by the Service on the basis of: rules developed by the Service Provider, the Open Cookie Database, a public signature database, rules concerning domains, heuristic rules and the categories assigned to other technologies identified by the same script.
  2. Classification is based on the metadata of the tracking technology, such as its name, domain, vendor and signature, and not on Visitors' personal data.
  3. The Service Provider does not guarantee that the classification is complete or always correct, regardless of the method used. A technology that is not recognised is given the category “Unclassified”, and a recognised technology may be misclassified, particularly if its name or domain has changed on the vendor's side.
  4. The Customer can manually change the category of each tracking technology in the customer panel. Such a change takes precedence over the automatic classification and applies to script blocking, the banner content, the public cookie declaration and the API. The change remains in effect even after a subsequent scan.
  5. Information about the source on the basis of which the category was assigned is recorded in the scan results and is available in the data export, provided that the plan includes this feature.
  6. The final verification of the correctness of the classification before the consent banner is published rests with the Customer, in accordance with §7(3).

§9. Fees and payments

  1. The amount of the fees is set out in the Price List. The prices given are net prices, to which value added tax is added at the applicable rate.
  2. The fee for a Billing Period is charged in advance, automatically, through the payment operator. Full payment card details are processed only by the payment operator; the Service Provider does not receive them.
  3. Invoices are issued electronically and made available in the customer panel. The Customer consents to receiving invoices in electronic form.
  4. Polish National e-Invoicing System (KSeF). Where the Service Provider is required to issue structured invoices, invoices for Customers whose business is established, or that have a fixed establishment, in Poland are issued in that system and are deemed delivered when they are assigned an identification number. For Customers outside Poland, invoices are made available in the customer panel and sent by email.
  5. Automatic subscription renewal. The subscription renews automatically for the next Billing Period unless the Customer turns this option off in the customer panel before the end of the current Billing Period.
  6. Changing the plan during a Billing Period:
    • an upgrade takes effect immediately, and the price difference will be settled pro rata for the remaining period and included in the next invoice;
    • a downgrade takes effect from the start of the next Billing Period, without pro rata settlement or refund;
    • during the Trial Period, both plan changes take effect immediately and involve no financial settlement.
  7. Refunds. Fees paid in advance are not refundable if the Customer terminates the Agreement or downgrades the plan during a paid Billing Period. Termination takes effect at the end of the paid period, and the Customer retains access to the Service in its existing scope until then. The above does not exclude a refund under §16(4) and §15(3).
  8. Failed payment. If a payment fails, the payment operator makes further attempts to collect it in accordance with the schedule set by the Service Provider. Once the payment retry attempts have been exhausted, the CMP Engine ceases to be available for the Customer's Domains, and the Project returns to the Free Plan. This means that the consent banner stops being displayed, Visitors' consents are no longer recorded, scripts that the Customer has placed under automatic blocking stop being blocked and run without consent, and scripts held back manually by the Customer in the page code stop running. Where the CMP Engine is deployed through a tag manager, whether blocking continues is decided by that tag manager's consent mechanism. A Customer that does not want the CMP Engine to remain active on its websites during this period should remove the script code from its website. Failure to pay for the Service does not release the Customer from the obligation to settle the outstanding payment, and the Service Provider may terminate the Agreement. If the Customer initiates a chargeback without first contacting the Service Provider, and the chargeback turns out to be unjustified, the Service Provider may claim from the Customer reimbursement of the fees and costs charged by the payment operators.
  9. Price changes apply only from the next Billing Period and require notice to the Customer at least 30 days in advance. A Customer that does not accept the new price may terminate the Agreement with effect from the end of the current, paid period.
  10. Discount codes and promotions. Discounts and promotional codes apply on the terms and for the period indicated when they are made available, cannot be combined with each other or with other reductions unless stated otherwise, and cannot be exchanged for cash. The Service Provider may cancel a code if it has been used contrary to its purpose, for example resold or used to obtain the Trial Period more than once.

§10. Availability of the Service

  1. The Service Provider endeavours to ensure the continuity of the Service but does not guarantee any particular level of availability and is not liable in this respect, unless a separate agreement provides otherwise.
  2. The Service consists of two layers:
    • the CMP Engine together with its distribution infrastructure, that is, the host from which the script and the banner configuration are downloaded; its unavailability affects the operation of banners on Customers' websites;
    • the customer panel and the Service Provider's information pages; their temporary unavailability does not interrupt the operation of banners that have already been loaded in Visitors' browsers.
  3. Maintenance breaks may occur without prior notice. The Service Provider tries to carry them out outside peak hours and to keep them to the minimum necessary.
  4. The Service Provider may temporarily suspend access to the Service if this is necessary to ensure security or the integrity of the Service, or to protect the data of other Customers. Where possible, it gives 24 hours' notice of such a suspension, unless the situation requires immediate action.
  5. The Service Provider is not liable for unavailability of the Service resulting from: failures on the Customer's side, incorrect embedding of the CMP Engine on the website, problems with or failures of infrastructure providers, attacks on the infrastructure or force majeure. The exclusion of liability for infrastructure providers does not affect the Service Provider's obligations under data protection law or under the data processing agreement (DPA).

§11. Support

  1. Technical support is available by email at kontakt@cookieofficer.pl and through the contact form available on the Website.
  2. The Service Provider does not guarantee a response within any particular time. It tries to respond within a reasonable time, in the order resulting from the nature of the request.
  3. The Service Provider accesses the Customer's Account only when this is necessary to resolve a reported problem.

§12. Intellectual property rights

  1. All rights to the Service, including the source code, the interface, the documentation, the catalogue of descriptions of tracking technologies and the CookieOfficer trademarks, belong to the Service Provider.
  2. The Customer receives a non-exclusive, non-transferable licence to use the Service for the term of the Agreement, solely to the extent necessary to use it for its intended purpose.
  3. The licence includes the right to embed the CMP Engine on the Domains added to the Account and to publish the generated cookie declarations on those Domains.
  4. Data entered by the Customer remains its property. The Service Provider does not acquire any rights to it beyond the scope necessary to provide the Service, as set out in the data processing agreement (DPA).
  5. Opinions, suggestions and proposals provided by the Customer may be used by the Service Provider to develop the Service without any obligation to remunerate the Customer, and the Service Provider may freely dispose of them.
  6. The Service uses the Open Cookie Database under the Apache 2.0 licence. The terms of that licence apply to the relevant components.

§13. Confidentiality

  1. The Parties undertake to keep confidential any information obtained in connection with the performance of the Agreement that is marked as confidential or whose confidential nature follows from the circumstances.
  2. This obligation does not apply to information that is publicly available, has been lawfully obtained from a third party, or whose disclosure is required by law or by a decision of a competent authority.
  3. The confidentiality obligation lasts for the entire term of the Agreement and for 3 years after its end.
  4. Customer references. The Customer consents to the Service Provider using the Customer's name and logo for reference and marketing purposes, including placing them on the list of customers on the Website and in sales materials. The Customer may withdraw this consent at any time, and the Service Provider will stop using the name and logo within a reasonable time.

§14. Liability

  1. The Service Provider is liable only for actual loss caused to the Customer in connection with the performance of the Agreement, within the limits set out in this §14.
  2. The Service Provider's total liability under the Agreement, including the data processing agreement (DPA), for all events combined, is limited to the sum of the fees paid by the Customer under the Agreement in the twelve months preceding the event giving rise to the claim. If, at the time of that event, the Agreement had lasted less than twelve months, liability is limited to the sum of the fees paid since the date on which the Agreement was concluded.
  3. The Service Provider is not liable for: lost profits, indirect and consequential damage, loss of data, interruption of the Customer's business, loss of reputation, or administrative fines, other fines and other public-law sanctions imposed on the Customer.
  4. The Service Provider is not liable for the Service malfunctioning as a result of: the configuration made by the Customer, the content of the banner and cookie declarations published by the Customer, changes made on the Customer's website, the operation of third-party software, the suspension of the provision of the CMP Engine because the Pageview limit was exceeded or because of payment arrears, or failures of or interruptions in the operation of the infrastructure providers listed in Annex 3 to the data processing agreement (DPA). The exclusion of liability for infrastructure providers is without prejudice to data protection law, in particular Article 28(4) GDPR, and to the provisions of the data processing agreement (DPA).
  5. The monetary limit of liability in clause 2 does not apply to damage caused by the Service Provider intentionally or to liability that cannot be limited or excluded under mandatory provisions of law. The exclusions and limitations in clauses 3 and 4 apply in all other cases.
  6. Liability under the statutory warranty for defects (rękojmia), physical and legal, is excluded (Article 558 § 1 of the Polish Civil Code). This exclusion does not apply where the defect was fraudulently concealed by the Service Provider.
  7. The Service is provided “as is”, subject to the limitations permitted by law. The Service Provider does not guarantee that the scanner will detect all tracking technologies on the Customer's website, that the classification will always be correct, or that using the Service will ensure the Customer's full compliance with data protection law. The obligation to verify rests with the Customer (§7(3), §8(6)).
  8. The Service Provider gives no additional assurances or warranties beyond those expressly contained in these Terms, in particular as to the fitness of the Service for the Customer's particular purposes.
  9. The limitations and exclusions of liability in this §14 apply regardless of the legal basis of the claim, whether contractual, tortious or statutory, even if the Service Provider was informed of the possibility of damage.
  10. The limitations and exclusions of liability in this §14 also apply to the persons whom the Service Provider uses in performing the Agreement, including employees, associates and subcontractors.
  11. The Customer is liable to the Service Provider for damage resulting from a breach of §6 (Rules for using the scanner) and §7 (Customer's obligations).

§15. Indemnification

  1. The Service Provider undertakes to indemnify the Customer against liability towards third parties for claims of infringement of intellectual property rights by the Service, covering the damages awarded and reasonable costs of legal defence, provided that the Customer: notifies the Service Provider of the claim without delay, allows the Service Provider to conduct the defence and cooperates with the Service Provider in the course of the proceedings.
  2. The indemnity in clause 1 does not cover claims resulting from: modification of the Service by the Customer, combining the Service with third-party software in a way that does not comply with the documentation, use of the Service in a way that does not comply with these Terms, and use of a version of the Service that has not been updated, if the Service Provider has made an update available.
  3. If a claim under clause 1 prevents the further provision of the Service, the Service Provider may, at its own choice: obtain for the Customer the right to continue using the Service, modify the Service so that it does not infringe the rights of third parties, or terminate the Agreement and at the same time refund the fees for the unused period.
  4. The Customer undertakes to indemnify the Service Provider against liability towards third parties for claims resulting from: the Customer's breach of §6 (Rules for using the scanner), the Customer's breach of §7 (Customer's obligations), the content of the consent banner and cookie declarations published by the Customer, and the lack of a legal basis for processing Visitors' data. The Customer also covers administrative fines and other fines imposed on the Service Provider, as well as reasonable defence costs incurred by the Service Provider, if they result from the breaches listed above.
  5. The indemnity in clause 1 is subject to a separate monetary limit of twice the limit set out in §14(2). The indemnity in clause 4 is not subject to any monetary limit.

§16. Complaints

  1. Complaints must be submitted to kontakt@cookieofficer.pl, stating the Customer's name, a description of the problem and the expected resolution, within 30 days of the day on which the irregularity came to light.
  2. The Service Provider considers a complaint within 14 working days and, in matters requiring additional clarification, without delay once that clarification is completed, informing the Customer of the reason for the delay.
  3. A complaint may not concern irregularities resulting from: the Customer's failure to meet the technical requirements, incorrect embedding of the CMP Engine on the website, the configuration made by the Customer, or the operation of third-party software.
  4. If a complaint is accepted, the refund is made using the same payment method within 14 days of the complaint being accepted.

§17. Term and termination of the Agreement

  1. The Agreement is concluded for an indefinite period, with settlement in Billing Periods.
  2. The Customer may terminate the Agreement at any time by turning off the automatic renewal of the subscription in the customer panel. The Agreement expires at the end of the current, paid Billing Period.
  3. The Service Provider may terminate the Agreement with 30 days' notice.
  4. The Service Provider may terminate the Agreement with immediate effect if the Customer materially breaches §6 (Rules for using the scanner) or §7 (Customer's obligations), is in arrears with payment as described in §9(8), or uses the Service for unlawful activities.
  5. Data export. Before deleting a Project or the Account, the Customer should export its data, including the Consent Log, using the feature available in the customer panel, if the plan includes export. Once a Project has been deleted, self-service export is not possible. For 30 days after the end of the Agreement, the Service Provider makes a copy of the data available at the Customer's request, at no additional charge, in accordance with §11 of the data processing agreement (DPA).
  6. Switching providers. At the Customer's request, the Service Provider provides assistance in transferring the data collected within the Service to another data processing service provider or to the Customer's own infrastructure, in accordance with Regulation (EU) 2023/2854. Such a request may be made at any time. The transfer covers at least: the Consent Log, scan results and the banner configuration, in commonly used, machine-readable formats (CSV or JSON). The Service Provider makes this data available regardless of whether the Customer's plan includes the export feature in the customer panel. The transitional period for completing the transfer does not exceed 30 calendar days and may be extended once at the Customer's request, for a period that the Customer considers more appropriate. If completing the transfer within this period is technically impossible, the Service Provider notifies the Customer within 14 working days of receiving the request, justifies the impossibility and indicates an alternative transitional period not exceeding 7 months. The Service Provider does not charge any fees for assistance with switching providers.
  7. After the end of the transitional period, the Customer may retrieve the data listed in clause 6 for at least 30 calendar days; clause 5 also applies in this respect. After that period, the data is deleted in accordance with §11 of the data processing agreement (DPA).
  8. Deleting the Account in the customer panel deletes the Customer's authentication data and profile, but does not delete the data collected within the Service. Projects, banner configurations, the Consent Log, scan results, billing data and the proof of acceptance of these Terms are kept for the periods indicated in the Privacy Policy and in the data processing agreement (DPA). Requests to delete this data must be sent to kontakt@cookieofficer.pl. Deleting the Account does not end the Agreement or stop the automatic renewal of the subscription; notice of termination of the Agreement must be given separately: before the Account is deleted, in the customer panel, or, after it has been deleted, by email to the address indicated in §1(3).
  9. Effects of the end of the Agreement on the Customer's websites. After the Agreement is terminated or expires, the CMP Engine stops working on the Domains added to the Customer's Account. The Customer is responsible for removing the script code from its websites and for ensuring compliance with the law by other means.
  10. Information about the jurisdiction to which the ICT infrastructure used to provide the Service is subject, and a general description of the technical, organisational and contractual measures aimed at limiting third-country authorities' access to non-personal data, are available at cookieofficer.pl/infrastruktura and are kept up to date by the Service Provider.

§18. Amendments to the Terms

  1. The Service Provider may amend these Terms for important reasons, such as: a change in the law or its interpretation, a change in the scope or manner of providing the Service, security considerations, or organisational changes on the Service Provider's side.
  2. The Service Provider notifies the Customer of a planned amendment at least 30 days in advance by sending information to the email address assigned to the Account.
  3. A Customer that does not accept the amendment may terminate the Agreement before the amendment takes effect. Failure to terminate means acceptance of the new terms.
  4. Amendments resulting solely from the need to adapt these Terms to mandatory provisions of law may take effect within a shorter period if the law so provides.

§19. Governing law and dispute resolution

  1. The Agreement is governed by Polish law.
  2. Disputes arising from the Agreement are resolved by the court having local jurisdiction over the Service Provider's principal place of business.
  3. The provision on the jurisdiction of the court is without prejudice to provisions that confer exclusive or special jurisdiction on a court of another state, in particular Regulation (EU) No 1215/2012.
  4. The Parties undertake to attempt in good faith to resolve a dispute amicably before referring it to court.

§20. Specific risks and operation of the software

  1. Risks associated with using electronic services. Using services provided by electronic means involves risks typical of the internet, such as: malware (viruses, worms, Trojan horses), attempts at unauthorised access to the Account, including phishing, unsolicited correspondence (spam) and attacks on service availability. The Service Provider recommends: using up-to-date antivirus software and a firewall, regularly updating the browser and operating system, using a unique password for the Account, and not sharing login details and API keys with third parties.
  2. Operation of the software provided by the Service Provider. As part of the Service, the Service Provider makes available, for embedding on the Customer's website, the CMP Engine, whose task is to: display the consent banner, record the Visitor's decision in the Consent Log and hold back non-essential scripts until consent is given, to the extent resulting from the configuration chosen by the Customer and from the result of the most recent scan. Where the CMP Engine is deployed through a tag manager, script blocking is performed by that tag manager's consent mechanism, not by the CMP Engine itself.
  3. Operation of the CMP Engine with regard to consents and user data. In connection with displaying the consent banner, the CMP Engine stores the following data in the Visitor's browser:
    • the co_consent cookie, containing the scope and time of the consent given, the pseudonymous consent identifier and the Project identifier; its lifetime is set by the Customer, 365 days by default;
    • in browser storage: a queue of unsent consent proofs (__coQ, lifetime up to 30 days), the Visitor's country code (co-geo, 24 hours) and a copy of the banner configuration (co-cfg together with two auxiliary keys);
    • with consent sharing within a domain group enabled: an additional co-bulk entry in browser storage on the Service Provider's domain.
  4. The CMP Engine does not store the Visitor's first name, last name or email address in the Visitor's browser. A detailed list of the information processed and its retention periods is set out in the Privacy Policy and, as regards data entrusted by the Customer, also in the data processing agreement (DPA).
  5. The rules for the use of cookies on the Service Provider's own Website (cookieofficer.pl) are described in the Privacy Policy.

§21. Final provisions

  1. Force majeure. Neither Party is liable for non-performance or improper performance of the Agreement to the extent that it is caused by force majeure, that is, an external event that could not be foreseen or prevented, such as: natural disasters, acts of public authority, wars, strikes, or failures of power or telecommunications infrastructure affecting more than a local area. The Party affected by force majeure notifies the other Party without delay. If this state lasts longer than 30 days, either Party may terminate the Agreement with immediate effect.
  2. Notices. The Service Provider sends notices and statements relating to the Agreement to the email address assigned to the Customer's Account, and the Customer sends them to the address indicated in §1(3). A notice is deemed delivered when it is sent to the correct address. The Customer must keep the email address assigned to the Account up to date and working; the consequences of any failure in this respect are borne by the Customer.
  3. Entire agreement. The terms of the Agreement are set out exclusively in these Terms together with the annexes listed in §1(4). Promotional materials, presentations and other information provided before the Agreement was concluded do not form part of it unless they have been expressly incorporated. This provision does not exclude liability that cannot be excluded under mandatory provisions of law.
  4. Exclusion of the Customer's standard terms. The application of the Customer's standard contract terms, such as general terms and conditions, model contracts or terms of service, is excluded, even if the Customer refers to them in an order or in correspondence.
  5. No assignment. The Customer may not transfer its rights and obligations under the Agreement without the Service Provider's consent. The Service Provider may transfer its rights and obligations in the event of the disposal of its business, informing the Customer of this 30 days in advance.
  6. Effects of invalidity of provisions. The invalidity of one of the provisions does not affect the validity of the others. In place of the invalid provision, the provision of law closest to its economic purpose applies.
  7. No waiver. The Service Provider's failure to exercise a right to which it is entitled does not constitute a waiver of that right.
  8. Language of the Agreement. These Terms, together with their annexes, are drawn up in Polish, and the Agreement is concluded in that language. These Terms are available at cookieofficer.pl/regulamin, and the annexes at the addresses indicated in §1(4). Any translations are for information only and do not form part of the Agreement.