Legal

Data Processing Agreement (DPA)

Terms for processing data on behalf of the Client (GDPR Article 28).

Compliant with GDPR Article 28

Last updated: August 2026

Legal framework

The Client acts as data controller for personal data collected via the CookieFort CMP on its websites. COOKIEFORT SAS (share capital €5,000, RCS Paris 107 807 554, registered office: 5 rue de la Terrasse, 75017 Paris) acts as data processor within the meaning of Article 28 of the GDPR.

This DPA forms an integral part of the General Terms of Sale and Use (CGV/CGU). In the event of conflict, the provisions most protective of data subjects prevail.

Description of processing

2.1 Data subjects

Visitors to the Client's websites on which the CookieFort CMP is installed and who interact with the consent banner or preference centre.

2.2 Categories of data

  • Consent identifier (visitor ID)
  • Choice data (accepted/refused categories, granular preferences)
  • Timestamp of the decision
  • Technical environment data: truncated IP address, User-Agent, domain name of the site visited

2.3 Purposes

  • Collect, store and return consent choices to the Client
  • Maintain a register of proof of consent
  • Transmit Consent Mode v2 signals to Google Analytics, GTM or GA4 according to the Client's configuration
  • Produce anonymised statistics on acceptance rates

Data sovereignty

CookieFort guarantees impermeability to the US Cloud Act and FISA Section 702. Personal data is hosted exclusively within the European Union and Switzerland by Infomaniak Network SA, with no transfer to the United States or to providers subject to extraterritorial US surveillance laws.

Processor obligations

  • Process personal data only on documented instructions from the Client, including with regard to transfers
  • Ensure that persons authorised to process personal data are bound by confidentiality
  • Assist the Client, where appropriate, in carrying out data protection impact assessments (DPIAs)
  • Assist the Client in responding to requests from data subjects exercising their rights
  • Notify the Client of any personal data breach within 48 hours of becoming aware of it, with the information required under Article 33 of the GDPR

Sub-processors

Sub-processorServiceLocation
Infomaniak Network SACloud hosting, database, CDNSwitzerland / European Union
Stripe Payments Europe LtdB2B payment processingEuropean Union (Ireland)

CookieFort shall inform the Client of any intended change concerning the addition or replacement of sub-processors at least 15 days in advance, giving the Client the right to object on legitimate grounds relating to data protection.

Technical and organisational measures (TOMs)

  • Truncation or masking of IP addresses in consent logs
  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Multi-factor authentication (MFA), least-privilege access and logging of administrative actions
  • Daily encrypted backups with tested restoration procedures

Duration and end of processing

This DPA applies from acceptance of the CGV/CGU for the duration of the subscription. Upon termination, CookieFort shall delete or return all personal data processed on behalf of the Client within 30 days, unless applicable law requires retention. A certificate of destruction may be issued upon written request.

Audit

The Client may request a documentary audit of compliance with this DPA once per calendar year, upon written request sent to cmp@cookiefort.com. CookieFort shall provide the relevant documentation within a reasonable timeframe.

Governing law and jurisdiction

This DPA is governed by French law. Any dispute relating to data processing under this agreement shall fall within the jurisdiction of the Court of Appeal of Paris.