Data Processing Agreement
The Art. 28 GDPR agreement under which Tripticode processes personal data on your behalf. Part of the Terms of Service for every plan.
1. Parties and scope
This Data Processing Agreement ("DPA") is entered into between the organization that accepts the Tripticonsent Terms of Service (the "Customer", acting as controller) and Tripticode, S.L., tax ID B05654819, C/ Júcar 36B, 41012 Sevilla, Spain (the "Processor", reachable at dp@tripticode.com). It applies whenever Tripticode processes personal data on the Customer’s behalf through the Service ("Customer Personal Data"), forms part of the Terms for every plan, and takes effect when the Customer accepts them. On data protection matters it prevails over the Terms. Terms such as controller, processor, personal data breach and supervisory authority have the meaning given in Regulation (EU) 2016/679 ("GDPR").
2. Details of the processing (Annex I)
| Item | Detail |
|---|---|
| Subject matter | Operating the Service: recording, storing, proving and exporting consent and preference decisions, and the related tooling. |
| Duration | For the term of the Customer’s subscription, plus the deletion period in section 3(g). |
| Nature and purpose | Storing consent and preference records with their proof (timestamp, IP address, exact statement version) in an append-only vault; issuing signed receipts; answering the Customer’s API calls; delivering the Customer’s webhooks and transactional emails; data-subject-request tooling (export, rectification, erasure); scanning the Customer’s own websites for cookies. |
| Types of personal data | Identifiers the Customer chooses to send (email, phone, external ID, custom IDs), stored encrypted; device and cookie identifiers; consent and preference states, versions and timestamps; IP address and user agent recorded as proof; data-subject-request details; identity documents, only if the Customer enables document verification. |
| Data subjects | The Customer’s end users and website visitors; the Customer’s staff who use the console. |
| Special categories | Not intended. The Customer must not send special categories of data (Art. 9 GDPR), except identity documents in the optional document-verification flow for data-subject requests. |
3. Processor obligations (Art. 28(3) GDPR)
- (a) Instructions. The Processor processes Customer Personal Data only on the Customer’s documented instructions: the Terms, this DPA, and the Customer’s configuration of and calls to the Service. This includes transfers to a third country. If an instruction infringes data protection law in the Processor’s opinion, it will tell the Customer, unless the law prohibits it.
- (b) Confidentiality. Everyone authorized to process Customer Personal Data is bound by confidentiality.
- (c) Security. The Processor implements the technical and organizational measures in Annex II (Art. 32 GDPR).
- (d) Sub-processors. As set out in section 5.
- (e) Data-subject requests. The Service gives the Customer tooling to answer requests: export, rectification and erasure (by crypto-shredding), with verification flows. The Processor forwards any request it receives directly to the Customer and does not answer it itself.
- (f) Assistance. The Processor assists the Customer with its obligations under Arts. 32–36 GDPR (security, breach notification, impact assessments and prior consultation), taking into account the nature of the processing and the information available to it.
- (g) End of processing. The Customer can export its data at any time. Within 30 days after the subscription ends, the Processor deletes Customer Personal Data, unless EU or Member State law requires it to be kept. Backups are overwritten within their retention period.
- (h) Demonstrating compliance. The Processor makes available the information needed to demonstrate compliance with this DPA: documentation, answers to reasonable security questionnaires, and the audit log of the Customer’s organization. It allows audits: one per year at the Customer’s cost with 30 days’ notice, or at any time when required by a supervisory authority.
4. Personal data breaches
The Processor notifies the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. As the information becomes available, the notice includes what Art. 33(3) GDPR requires. The Processor takes reasonable steps to contain the breach and helps the Customer meet its own notification obligations.
5. Sub-processors
- The Customer gives a general authorization to engage the sub-processors listed in the privacy policy, and new ones under this section.
- The Processor gives at least 30 days’ notice of a new or replacement sub-processor by email to the organization’s owners. The Customer may object on reasonable data-protection grounds within that period. If the parties can’t resolve it, the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees.
- The Processor imposes data-protection obligations on each sub-processor that are no less protective than this DPA, and remains liable to the Customer for its sub-processors’ performance.
6. International transfers
Customer Personal Data is stored in the EU (database, cache and hosting in Frankfurt / eu-central). Where a sub-processor processes it outside the EEA, the transfer relies on the EU-US Data Privacy Framework where the recipient is certified, or on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 3, processor to processor) with supplementary measures. The details are in the privacy policy.
7. Customer obligations
The Customer is responsible for the lawfulness of the processing it instructs: a valid legal basis, adequate notices to its end users, and not sending data the Service does not need. It must keep its API keys and identity secrets confidential, and verify the domains it uses with LIVE keys.
8. Liability, term and law
Liability between the parties under this DPA is subject to the "Limitation of liability" section of the Terms, which caps the Processor’s aggregate liability at the fees paid in the preceding twelve (12) months, except for damages caused by willful misconduct or gross negligence. That cap governs claims between the parties only — for example, one party’s contribution claim against the other under Art. 82(5) GDPR after compensating a data subject. It does not, and cannot, limit either party’s own liability directly to a data subject under Art. 82 GDPR, which each party bears as that Article provides. This DPA lasts for as long as the Processor processes Customer Personal Data. It is governed by Spanish law, and the courts of Sevilla (Spain) have jurisdiction, unless the Standard Contractual Clauses require otherwise.
Annex II — Technical and organizational measures
- Encryption. Identifiers and personal data are encrypted at rest with AES-256-GCM, with key rotation. Every connection uses TLS.
- Pseudonymous lookups. Identifiers are found through an HMAC-SHA256 hash with a secret pepper that is separate from the encryption key.
- Integrity and proof. The consent vault is append-only (records are never modified; a change is a new record). Every decision gets an Ed25519-signed receipt. The organization audit log is hash-chained.
- Isolation. Data is scoped to the organization and site, and test data and live data are kept strictly apart.
- Access control. Roles per organization and site; TOTP multi-factor authentication; SAML SSO limited to DNS-verified domains; short-lived sessions with rotating refresh tokens; single-use login links with rate limits and bot protection.
- API access. Keys are stored only as hashes. Secret keys can be limited by scopes, IP allowlist and expiry. Public keys are restricted to verified domains in live mode, and can only reach identified people with a server-signed identity token.
- Network hardening. Outbound requests to customer-supplied URLs are SSRF-guarded (no internal addresses, every redirect re-checked). Requests are rate-limited, and security headers and a content security policy are enforced.
- Erasure. Erasure by crypto-shredding: destroying a subject’s key makes their records unreadable while the proof chain stays intact.
- Identity documents. A document uploaded to verify a data-subject request is hard-deleted automatically 7 days after upload, regardless of the verification outcome, whether or not the Customer has configured a different window — this default applies even if the Customer never visits the retention settings.
- Residency and resilience. Hosting, database and cache are in the EU. Deliveries go through a durable queue with retries. Backups are managed by the database provider.
- Operations. Error tracking masks personal data before sending (EU region). Dependencies are checked for known vulnerabilities on every change. There is a published vulnerability-disclosure policy (security) and a documented incident and breach procedure.