Scope
This Data processing agreement applies when CookieFence processes personal data on behalf of customers who use our consent management services.
Roles
With respect to personal data processed through the service, the customer acts as the controller and CookieFence acts as the processor. CookieFence processes personal data only on documented instructions from the customer, unless otherwise required by applicable law.
Customer instructions
The customer instructs CookieFence to process personal data as necessary to provide, secure, maintain, and support the service, in accordance with this Agreement, the Terms of service, and any documented instructions provided by the customer through the service or in writing.
Processing
CookieFence processes personal data solely to provide, secure, maintain, and support the service. Depending on the customer's configuration and use of the service, processing may include consent choices, cookie preferences, IP address information, browser and device details, timestamps, domain information, account details, and support communications. Personal data is processed for the duration of the customer's use of the service unless otherwise required by applicable law.
Security
CookieFence uses technical and organizational measures designed to protect personal data, including access controls, secure hosting, encryption where appropriate, monitoring, and internal handling practices that limit access to authorized personnel.
Confidentiality
CookieFence ensures that persons authorized to process personal data are subject to appropriate confidentiality obligations.
Subprocessors
CookieFence may use subprocessors for hosting, infrastructure, edge security, communications, billing, and support. We remain responsible for subprocessors we engage to process customer personal data and use contractual safeguards where required. CookieFence will maintain an up-to-date list of subprocessors and will notify customers of material changes where required by applicable law.
| Subprocessor | Purpose | Primary processing location |
|---|
| DigitalOcean | Cloud hosting and infrastructure | Frankfurt, Germany (EU) |
| Cloudflare | CDN, DNS, TLS, DDoS protection and edge security | Global network (appropriate transfer safeguards where required) |
| Mollie | Payment processing and subscription billing | Netherlands (EU) |
| Brevo | Transactional email communications | France (EU) |
Some subprocessors are headquartered outside the European Union. Where personal data is transferred internationally, CookieFence relies on appropriate transfer safeguards in accordance with applicable data protection law.
International transfers
If personal data is transferred outside the European Economic Area, CookieFence implements appropriate safeguards, including the European Commission's Standard Contractual Clauses or other lawful transfer mechanisms where required.
Assistance
CookieFence will provide reasonable assistance to help customers meet obligations relating to data subject rights, security, breach notifications, data protection impact assessments, and consultations with supervisory authorities, taking into account the nature of the processing and information available to CookieFence.
Security incidents
If CookieFence becomes aware of a personal data breach affecting customer personal data, we will notify affected customers without undue delay and provide information reasonably available to help meet legal obligations.
Return and deletion
At the customer's choice, CookieFence will delete or return customer personal data after termination of the services and within a reasonable period unless retention is required by applicable law.
Audit and compliance
Upon reasonable written request, CookieFence will make available information reasonably necessary to demonstrate compliance with this Agreement and applicable data protection law and, where required by law, allow reasonable audits or inspections subject to appropriate confidentiality and security measures. Customers are responsible for reasonable costs associated with audits that exceed one request per year or are not required by applicable law.
Signed DPA
Customers requiring a signed copy of this Data processing agreement for procurement or compliance purposes may contact CookieFence.