Last updated: June 25, 2026

Data processing agreement

These data processing terms describe how CookieFence handles personal data when we provide services to customers.

This Data processing agreement forms part of the Terms of service and applies from June 25, 2026.

Scope

This Data processing agreement applies when CookieFence processes personal data on behalf of customers who use our consent management services.

Roles

With respect to personal data processed through the service, the customer acts as the controller and CookieFence acts as the processor. CookieFence processes personal data only on documented instructions from the customer, unless otherwise required by applicable law.

Customer instructions

The customer instructs CookieFence to process personal data as necessary to provide, secure, maintain, and support the service, in accordance with this Agreement, the Terms of service, and any documented instructions provided by the customer through the service or in writing.

Processing

CookieFence processes personal data solely to provide, secure, maintain, and support the service. Depending on the customer's configuration and use of the service, processing may include consent choices, cookie preferences, IP address information, browser and device details, timestamps, domain information, account details, and support communications. Personal data is processed for the duration of the customer's use of the service unless otherwise required by applicable law.

Security

CookieFence uses technical and organizational measures designed to protect personal data, including access controls, secure hosting, encryption where appropriate, monitoring, and internal handling practices that limit access to authorized personnel.

Confidentiality

CookieFence ensures that persons authorized to process personal data are subject to appropriate confidentiality obligations.

Subprocessors

CookieFence may use subprocessors for hosting, infrastructure, edge security, communications, billing, and support. We remain responsible for subprocessors we engage to process customer personal data and use contractual safeguards where required. CookieFence will maintain an up-to-date list of subprocessors and will notify customers of material changes where required by applicable law.

SubprocessorPurposePrimary processing location
DigitalOceanCloud hosting and infrastructureFrankfurt, Germany (EU)
CloudflareCDN, DNS, TLS, DDoS protection and edge securityGlobal network (appropriate transfer safeguards where required)
MolliePayment processing and subscription billingNetherlands (EU)
BrevoTransactional email communicationsFrance (EU)

Some subprocessors are headquartered outside the European Union. Where personal data is transferred internationally, CookieFence relies on appropriate transfer safeguards in accordance with applicable data protection law.

International transfers

If personal data is transferred outside the European Economic Area, CookieFence implements appropriate safeguards, including the European Commission's Standard Contractual Clauses or other lawful transfer mechanisms where required.

Assistance

CookieFence will provide reasonable assistance to help customers meet obligations relating to data subject rights, security, breach notifications, data protection impact assessments, and consultations with supervisory authorities, taking into account the nature of the processing and information available to CookieFence.

Security incidents

If CookieFence becomes aware of a personal data breach affecting customer personal data, we will notify affected customers without undue delay and provide information reasonably available to help meet legal obligations.

Return and deletion

At the customer's choice, CookieFence will delete or return customer personal data after termination of the services and within a reasonable period unless retention is required by applicable law.

Audit and compliance

Upon reasonable written request, CookieFence will make available information reasonably necessary to demonstrate compliance with this Agreement and applicable data protection law and, where required by law, allow reasonable audits or inspections subject to appropriate confidentiality and security measures. Customers are responsible for reasonable costs associated with audits that exceed one request per year or are not required by applicable law.

Signed DPA

Customers requiring a signed copy of this Data processing agreement for procurement or compliance purposes may contact CookieFence.

Contact us

To request a signed DPA or ask data processing questions, email privacy@cookiefence.com.