← Trust Center

Data Processing Agreement (DPA)

Version 1.0 · Last updated: August 10, 2026

This Data Processing Agreement (the “DPA”) forms an integral part of the CookieHug Terms of Service and binds the Parties from the moment the Client starts using the Service — no separate document or signature is required. A printable or PDF version can be obtained using your browser’s print function.

1. Parties and roles

  1. Controller — the Client: a user of the CookieHug Service who determines the purposes and means of processing the personal data of visitors to their websites.
  2. Processor — Alfabet Marki Sp. z o.o., ul. Strzałowa 13K/1, 87-100 Toruń, Poland, NIP (tax ID) 9562399118, KRS 0001147842 (“CookieHug”).
  3. This DPA governs the processing of personal data on behalf of the Controller within the meaning of Article 28 GDPR, carried out in connection with providing the Service to the Client.

2. Definitions

  • GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).
  • Terms — the CookieHug Terms of Service available at /en/terms.
  • Service — the CookieHug service described in the Terms, covering the handling of cookie consents on the Client’s websites.
  • Consent Record — a record of a single consent event created by the Service on the Client’s website.
  • Client Data — personal data processed by CookieHug on behalf of the Client within the Service.
  • Subprocessor — a further processor whose services CookieHug uses to process Client Data.

3. Subject matter and duration of processing

  1. The subject matter of processing is the handling of cookie consents on the Client’s websites, in particular: the CMP banner, the consent register, cookie scanning, Google Consent Mode v2 and anomaly monitoring.
  2. Processing lasts for the period during which the Client uses the Service.

4. Nature and purpose of processing

  1. The nature and purpose of processing consist of collecting and storing Consent Records and making them available to the Client — in the Service dashboard, via export (CSV/NDJSON) and through the API.
  2. Raw Consent Records are stored for 90 days and automatically deleted after that period. Statistical aggregates containing no personal data may be stored indefinitely.
  3. The Client may export Consent Records before the retention period expires.

5. Categories of data subjects and categories of data

  1. Categories of data subjects: visitors to the Client’s websites and users designated by the Client.
  2. A Consent Record covers the following categories of data:
    • event type,
    • consent categories (analytics / marketing / preferences),
    • region (derived from Cloudflare geolocation headers, e.g. “EEA”, “PL”),
    • device type,
    • consent method,
    • language,
    • banner variant,
    • GPC/DNT signals,
    • decision time,
    • timestamp.
  3. A Consent Record does not contain an IP address, user agent, visitor identifier or URL. The data is pseudonymised and, on CookieHug’s side, cannot be attributed to a specific person (details: /trust/data-processing).

6. Controller’s instructions

  1. CookieHug processes Client Data solely on the Client’s documented instructions. The Client’s configuration of the Service constitutes a documented processing instruction.
  2. If, in CookieHug’s opinion, an instruction of the Client infringes the GDPR or other data protection provisions, CookieHug shall immediately inform the Client.

7. Confidentiality

Access to Client Data is limited to authorised CookieHug personnel bound by confidentiality obligations.

8. Security of processing

  1. CookieHug implements and maintains the technical and organisational measures referred to in Article 32 GDPR, described in Annex 1 to this DPA.
  2. CookieHug may update these measures, provided this does not lower the level of protection of Client Data.

9. Subprocessing (Subprocessors)

  1. The Client grants a general authorisation for CookieHug to use Subprocessors.
  2. The current list of Subprocessors is available at /trust/subprocessors and constitutes Annex 2 to this DPA.
  3. Changes to the Subprocessor list are announced on that page 14 days in advance. If the Client objects to a change, the Client has the right to terminate the Service.
  4. CookieHug imposes on Subprocessors data protection obligations equivalent to those arising from this DPA.

10. International transfers

Transfers of Client Data outside the European Economic Area take place solely through Subprocessors, on the basis of the EU-U.S. Data Privacy Framework or Standard Contractual Clauses (SCC).

11. Assistance to the Controller (data subject rights)

  1. Taking into account the nature of the processing, CookieHug assists the Client in fulfilling the rights of data subjects (Articles 12–23 GDPR), including by providing data export.
  2. Requests from data subjects addressed directly to CookieHug are forwarded to the Client without undue delay.

12. Personal data breach notification

After becoming aware of a personal data breach concerning Client Data, CookieHug notifies the Client without undue delay, and no later than within 48 hours of becoming aware of the breach, providing the information specified in Article 33(3) GDPR.

13. Deletion and return of data

  1. After the Client stops using the Service, Consent Records are deleted together with the deletion of the Client’s domain or account, and upon the Client’s request — within 30 days.
  2. Before deletion, the Client may export Consent Records themselves (dashboard, CSV/NDJSON export, API).

14. Audit

  1. CookieHug makes available to the Client the information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR (Article 28(3)(h) GDPR).
  2. Audits are carried out upon the Client’s justified request, during business hours, in a manner that does not give access to the data of other CookieHug clients.

15. Liability

The Parties’ liability for breaches of this DPA is governed by the GDPR (including Article 82) and by the provisions of the Terms, including the limitations of liability set out therein.

16. Governing law

This DPA is governed by Polish law.

17. Final provisions

  1. This DPA forms an integral part of the Terms. With respect to the processing of personal data on behalf of the Controller, the provisions of this DPA prevail over the Terms.
  2. Matters not regulated in this DPA are governed by the Terms and the GDPR.
  3. The Polish and English language versions of this DPA are equivalent.

Annex 1 — Technical and organisational measures (TOMs)

Area Measures
Encryption in transit end-to-end TLS (Cloudflare + Let’s Encrypt)
System architecture the application runs behind a reverse proxy and listens only on the loopback interface
Data location OVH hosting in Warsaw (EU); PostgreSQL database maintained locally
Authentication passwords hashed with bcrypt (cost 12); mandatory e-mail 2FA at login; account lockouts after failed login attempts with time-based escalation
Secret protection integration secrets encrypted with AES-256-GCM
Application protection rate limiting; CSRF protection; security headers (including CSP)
API tokens stored in hashed form, with a limited scope of permissions
Sessions 24-hour validity; cookies with secure and httpOnly attributes
Data separation separation of client data at the application logic level
Data minimisation Consent Records contain no IP address, user agent or visitor identifier
Retention automatic deletion of data after retention periods expire
Monitoring security event logging; login attempt records kept for 90 days

Annex 2 — List of Subprocessors

  1. The current list of Subprocessors is maintained at /trust/subprocessors (a living list, with changes announced 14 days in advance).
  2. As of the publication of this version of the DPA, the list includes: OVH (hosting, Warsaw, Poland), Cloudflare (CDN/proxy), Stripe, dpoczta.pl, Google, Apple, Facebook and wordpress.org. The roles and details of individual Subprocessors are described on the page referred to in point 1.

Language: English