Draft DPA / Art. 28 GDPR for adconsent customers. Lawyer review required. Acceptance is recorded in the admin UI.
Preamble
This Data Processing Agreement (DPA / AVV) governs processing by Advertiso GmbH (“Processor”) on behalf of the Customer (“Controller”) under Art. 28 GDPR for adconsent.
1. Subject matter and duration
- Subject: storing consent proofs, delivering the banner script, scanning customer websites.
- Duration: term of the main contract; deletion/return per section 8 after end of processing.
2. Nature and purpose
- Store and retrieve consent logs,
- deliver/configure the consent banner,
- scan cookies/tags on customer-designated domains,
- provide the admin UI.
3. Categories of data
- Pseudonymous consent ID,
- IP-derived country,
- user-agent hash,
- TC string / other consent strings,
- timestamps, language, regime, selected purposes/vendors,
- scan metadata (cookies/requests) from scanned pages.
4. Data subjects
Visitors of Customer websites; Customer admin users (account data under the main contract).
5. Instructions
The Processor processes data only on documented instructions of the Controller (Art. 28(3)(a) GDPR), via admin UI, email to kontakt@advertiso.de, or in writing.
6. Confidentiality
Persons authorized to process the data are bound to confidentiality (Art. 28(3)(b) GDPR).
7. TOMs — Annex A
- Encryption in transit (TLS),
- per-tenant access control,
- hashed user agents in consent logs,
- EU hosting in Germany (Hetzner Online GmbH),
- daily backups with 14-day retention,
- security-relevant logging,
- bcrypt password hashing for admin accounts.
8. Deletion and return
After end of processing, the Processor deletes or anonymizes data processed on behalf of the Controller, or returns them on request, subject to statutory retention. Admin export may be used for return.
9. Assistance
Reasonable assistance with data-subject requests, DPIAs and breach notifications (Art. 28(3)(e)–(f) GDPR) to the extent information is available to the Processor.
10. Subprocessors — Annex B
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen — hosting.
- [CDN-Anbieter] — CDN, if used.
- [ZAHLUNGSANBIETER] — payments, if personal data are involved.
Further subprocessors per Art. 28(2)/(4) GDPR. [PRÜFEN: objection mechanism.]
11. Audit rights
The Controller may verify compliance to a reasonable extent, preferably via certifications/reports; on-site audits by prior arrangement, respecting trade secrets.
12. Breach notification
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach (Art. 33(2) GDPR).
13. Final provisions
German law. Venue: Lübeck [prüfen]. This DPA is an annex to the main contract.