Subject matter and duration
This DPA governs Consentcook's processing of personal data on behalf of the Customer for the duration of the subscription.
Controller and processor roles
Following ICO guidance, the parties agree: the Customer is the controller for consent data collected from its site visitors; Consentcook is the processor for that data; Consentcook is an independent controller for its own account, authentication, and billing records. Both parties must put appropriate controller-processor arrangements in place.
Processor obligations
Consentcook processes personal data only on documented Customer instructions, ensures confidentiality of personnel, implements the security measures in our Security page, assists with data-subject requests, and deletes or returns personal data at the end of the engagement.
Subprocessors
Consentcook engages the subprocessors listed on the Subprocessors page. The Customer authorises these subprocessors and will be notified of changes before new ones take effect.
International transfers
Where personal data is transferred outside the UK/EEA, the parties rely on the UK IDTA / EU Standard Contractual Clauses as applicable.
Deletion and DSAR support
Consentcook supports automated retention-based deletion and an audited per-subject erasure workflow keyed by the anonymous subject key. Every erasure is recorded in an immutable audit log.