Data processing agreement for privaci.io
The data processing agreement between Privaci (processor) and the customer (controller) under Article 28 GDPR, including subprocessors and transfer grounds.
Last updated
This data processing agreement (DPA) governs the processing of personal data that Privaci carries out on behalf of the customer under Regulation (EU) 2016/679 (GDPR), Article 28.
The agreement is entered into automatically as part of the terms of service when the customer accepts our terms of service, and is binding on both parties from the moment of acceptance. If you would like a physically signed copy, or have questions about the agreement, please contact us at hello@privaci.io.
1. The parties
1.1 Processor
Privaci by bon.do ApS
CVR: 43473425
Email: hello@privaci.io
Website: privaci.io
Privaci acts as processor and processes personal data solely on the controller's behalf and on the controller's documented instructions, cf. section 2.3.
1.2 Controller
The customer, as stated in the service agreement or on account creation with Privaci. The customer is the controller of the personal data processed through the Privaci service and is responsible for ensuring a valid legal basis under the GDPR.
2. Subject matter and purpose of the processing
2.1 Subject matter
Privaci provides a cookie consent management platform (CMP) that allows the controller to collect, record and manage end users' consent to the use of cookies and similar tracking technologies on the controller's website(s).
2.2 Purposes of the processing
- Collecting and storing consent from the websites' visitors
- Documenting the content, time, policy version and language of the consent
- Displaying the cookie banner and managing preferences for the controller's visitors
- Scanning and classifying cookies on the controller's website
- Technically enforcing consent choices through the Privaci script
- Providing the consent log for documentation and any supervisory review
2.3 Instructions
Privaci processes personal data solely in accordance with the controller's documented instructions, unless processing is required by EU law or the national law of a member state. In the latter case Privaci will inform the controller, unless the relevant law prohibits such notification.
3. Types of personal data
In delivering the service, Privaci processes the following categories of personal data on behalf of the controller:
- Consent choices — which categories of cookies the visitor accepted or rejected.
- Pseudonymous visit ID — a random, pseudonymous identifier
(
privaci_vid) that ties the consent choice to the visitor's consent session. It is created only once the visitor makes a choice. - Timestamps — the time the consent was given and any subsequent update.
- Consent state — the visitor's choice and timestamp, stored locally in the
visitor's browser (
privaci_consent) for up to 12 months.
Privaci does not process IP addresses or user-agent strings as part of the consent service, and consent is tied solely to the pseudonymous visit ID. No signed cookie is used to store consent.
Privaci does not process special categories of personal data under Article 9 GDPR, and encourages the controller not to disclose such information through the platform.
4. Categories of data subjects
The data subjects are visitors to the controller's website(s), including:
- Prospective and existing customers of the controller
- Anonymous visitors without an existing customer relationship
- Employees of the controller visiting the company's own websites
5. Security measures
Privaci has implemented technical and organisational measures that provide a level of security appropriate to the risk of the processing, cf. Article 32 GDPR. The measures include, but are not limited to:
5.1 Technical measures
- Encryption in transit: all communication uses TLS 1.2 or newer (HTTPS).
- Encryption at rest: personal data is encrypted in the database with AES-256.
- Access control: the principle of least privilege applies to all internal systems. Access requires multi-factor authentication (MFA).
- Pseudonymisation: consent data is tied to a pseudonymous consent ID and contains neither IP address nor user agent.
- Audit log: all administrative actions on personal data are logged and retained for at least 12 months.
- Vulnerability scanning: infrastructure and applications are monitored continuously and undergo regular penetration tests.
- Backup: automatic daily backups with encrypted storage and regular restore testing.
5.2 Organisational measures
- Confidentiality obligations for all staff and subcontractors with access to personal data.
- Ongoing training of staff in data protection and information security.
- A documented procedure for handling security breaches, including notifying the controller within 24 hours of discovery.
- Internal review of security measures at least once a year.
6. Subprocessors
By entering into this agreement the controller grants general prior authorisation for Privaci to use subprocessors. Privaci will inform the controller of planned changes involving the addition or replacement of subprocessors with at least 30 days' notice, so that the controller has an opportunity to object.
Privaci uses the following subprocessors:
| Subprocessor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Cloudflare, Inc. | CDN, DDoS protection, DNS | USA/EU | EU-US Data Privacy Framework |
| Hetzner Online GmbH | Server infrastructure and data storage | EU (DE/FI) | Within the EU/EEA |
| Amazon Web Services EMEA SARL | Backup storage and file handling | EU (IE/DE) | Within the EU/EEA |
| Postmark (ActiveCampaign) | Transactional email (receipts) | USA | Standard contractual clauses (SCCs) |
| Stripe, Inc. | Payment processing (invoicing) | USA/EU | EU-US Data Privacy Framework + SCCs |
Privaci ensures that all subprocessors are subject to the same data protection obligations as set out in this agreement, and that written agreements have been entered into with them in accordance with Article 28(4) GDPR.
7. Transfers outside the EU/EEA
Personal data is primarily processed within the EU/EEA. To the extent processing involves a transfer to third countries (including the USA), this takes place solely on the basis of one of the following transfer grounds, cf. Chapter V GDPR:
- Adequacy decision: transfer to countries for which the European Commission has adopted an adequacy decision.
- EU-US Data Privacy Framework: for providers certified under the EU-US DPF.
- Standard contractual clauses (SCCs): the European Commission's standard contractual clauses of 4 June 2021, supplemented by a transfer impact assessment (TIA) where relevant.
Privaci will make documentation of the transfer grounds used available to the controller on request.
8. Deletion and return
8.1 Deletion on termination
On termination or expiry of the service agreement, Privaci will delete all personal data processed on behalf of the controller no later than 90 days after the agreement ends, unless a retention obligation follows from EU law or Danish law.
8.2 Return
Within 30 days of the agreement ending, the controller may request an export of consent data in a machine-readable format (CSV or JSON). After that, data is deleted in accordance with section 8.1.
8.3 Ongoing retention periods
Consent logs are retained for up to 24 months (730 days) from the time of recording for the purpose of documenting compliance to supervisory authorities. The retention period is set by the rule that applied at the time of the decision, and covers both the current consent state and the immutable consent log. Through the administration panel the controller may request deletion of specific data subjects on the basis of a right-to-erasure request (Article 17 GDPR).
9. Audit and inspection
Privaci makes available all information necessary to demonstrate compliance with the obligations in Article 28 GDPR, and allows for and contributes to audits, including inspections, carried out by the controller or another auditor authorised by the controller.
Audits are carried out:
- With at least 30 days' written notice to Privaci.
- At most once per calendar year, unless there is a specific, substantiated suspicion of a breach.
- At the controller's expense, unless the audit reveals material breaches committed by Privaci.
As an alternative to a physical audit, Privaci may present the documentation of its security measures that is available at the time of the request — for example a description of the technical and organisational measures in section 5.
10. Rights of data subjects
The controller is responsible for handling requests from data subjects exercising their rights under the GDPR (Articles 15–22), including the rights of access, rectification, erasure, restriction and data portability.
Privaci assists the controller in meeting such requests by, taking into account the nature of the processing and the information available:
- Providing technical means to export and delete specific data subjects through the administration panel.
- Answering written requests about which information is processed for a given data subject within 10 working days.
11. Personal data breaches
Privaci will notify the controller of a confirmed personal data breach without undue delay and no later than 24 hours after becoming aware of it. The notification contains, to the extent the information is available:
- A description of the breach, including the categories and approximate number of data subjects and records concerned.
- Contact details for Privaci's data protection officer or other contact point.
- A description of the likely consequences of the breach.
- A description of the measures taken or proposed to address the breach.
The controller alone is responsible for assessing whether the breach must be reported to the Danish Data Protection Agency and/or to the affected data subjects under Articles 33–34 GDPR.
12. Liability and indemnity
The parties' liability under this data processing agreement is governed by the limitations of liability set out in the terms of service in force between the parties.
To the extent Privaci is held liable to a data subject or a supervisory authority for breaches caused by the controller's instructions or actions, the controller is obliged to indemnify Privaci to the extent the liability arises from circumstances attributable to the controller.
Privaci's total liability under this agreement is in any case limited to the amount the controller has paid to Privaci in the 12 months immediately preceding the event that gave rise to the claim.
13. Duration and termination
This data processing agreement takes effect when the customer accepts Privaci's terms of service and remains valid for as long as Privaci processes personal data on behalf of the controller.
The agreement ends automatically on expiry or termination of the service agreement. Privaci's obligation to delete data, cf. section 8, continues after the agreement ends.
If applicable data protection law changes, Privaci reserves the right to update this agreement with reasonable notice. The controller will be notified by email at least 30 days before material changes take effect. Continued use of the service after the effective date constitutes acceptance of the updated terms.
14. Governing law and venue
This data processing agreement is governed by Danish law, with the GDPR and other directly applicable EU law taking precedence.
Any dispute arising from this agreement that cannot be resolved amicably is decided by the Danish courts with the Aarhus City Court as the court of first instance.
15. Signature
This data processing agreement is deemed signed and binding on both parties when the controller accepts Privaci's terms of service on account creation or through continued use of the service.
If you would like an individual, physically signed agreement — for example for your company's DPO or for internal compliance documentation — please contact us. We will send a signed copy within 5 working days.