Legal and trust
Data Processing Addendum
Private-beta processor terms between a customer controlling a website and AKSAMIT PROJECTS sp. z o.o. as the operator of Consentory.
1. Parties, scope and precedence
The customer identified in the applicable order or beta agreement is the controller and AKSAMIT PROJECTS sp. z o.o. is the processor for customer personal data processed through Consentory. This Addendum is incorporated into the Subscription Terms by reference and takes effect automatically when the customer accepts those terms, without any further signature; it is intended to satisfy the requirement for a binding contract in writing, including in electronic form, under Article 28(3) GDPR. If its data-protection terms conflict with the service terms, this Addendum controls for that conflict.
2. Processing details
- Subject matter: hosting consent configuration, scanning websites, operating the widget and maintaining consent evidence on the controller's instructions.
- Duration: the service term plus the documented deletion and backup-expiry period.
- Data subjects: customer users and visitors to customer-controlled websites.
- Data: account/contact data, registered domains, configuration, scan findings, pseudonymous visitor IDs, consent choices, timestamps and technical evidence metadata.
- Purpose: provide, secure, support and document the requested consent-management service.
3. Documented instructions and controller duties
Consentory processes customer personal data only on documented instructions in the agreement, product configuration and authorised support requests, unless EU or Member State law requires otherwise. The controller determines lawful purposes, categories, notices, vendors and retention and confirms that its instructions comply with applicable law.
4. Confidentiality and security
Personnel authorised to process customer personal data are subject to confidentiality obligations. Consentory maintains proportionate technical and organisational measures covering access control, credential protection, encryption in transit, tenant checks, auditability, vulnerability handling, backup and incident response. Current controls are described on the Security page.
5. Subprocessors and transfers
The controller gives general authorisation for the subprocessors in the published register. Consentory provides notice of additions and a process for reasoned objections. Where processing leaves the EEA, the parties use an applicable adequacy decision, Standard Contractual Clauses or another valid mechanism and assess supplementary safeguards where required.
6. Data-subject requests and compliance assistance
Taking account of the nature of processing, Consentory provides reasonable assistance for access, correction, deletion, restriction, portability and objection requests, DPIAs, prior consultation and the controller's security obligations. The controller remains responsible for identifying the requester and responding within the legal deadline.
7. Personal-data breaches
Consentory notifies the controller without undue delay after confirming a personal-data breach affecting customer personal data and provides available information on nature, categories, likely consequences and containment. Notification is not an admission of fault and may be supplied in phases as facts are verified.
8. Return, deletion and retention
During the service term, the controller can export configured consent records. On verified deletion or termination, Consentory deletes or returns customer personal data according to the controller's choice unless law requires retention. Residual encrypted backups expire through the documented backup cycle and remain protected from ordinary use.
9. Audit information
Consentory supplies information reasonably necessary to demonstrate Article 28 compliance. If that information is insufficient, the controller may request one reasonable audit per year, subject to confidentiality, security, scope and cost arrangements. Incident-related or regulator-required audits are handled according to the circumstances.
10. Acceptance and countersigned copy
This published text is the version in force. It binds both parties from the moment the customer accepts the Subscription Terms, and the version number and date above identify the applicable text; earlier versions are kept and supplied on request.
A countersigned copy naming both parties, the service agreement, the effective date, contacts, approved retention and any transfer annexes is available at no charge from legal@consentory.io, for customers whose procurement process requires a signed document. Requesting one does not affect the Addendum already being in force.