Skip to main content
Last updated: 1 July 2026

Data Processing Agreement

Standard GDPR Article 28 data processing terms for ConsentSignals B2B customers. A countersigned copy is available on request for Agency and Enterprise plans.

Parties

This Data Processing Agreement ("DPA") forms part of the agreement between: Controller: The customer organisation using ConsentSignals paid services ("Customer") Processor: Rivoryn Limited, Limerick, Ireland ("ConsentSignals", "we", "us") This DPA applies when ConsentSignals processes personal data on behalf of the Customer in connection with the ConsentSignals compliance scanning and monitoring platform.

Subject matter and duration

ConsentSignals processes personal data submitted by the Customer (including account data, scan URLs, and scan results linked to the Customer's account) for the duration of the subscription and 30 days thereafter, unless a longer retention is required by law or agreed in writing.

Nature and purpose of processing

Processing activities include: • Hosting and storing scan requests and results • Generating compliance audit reports • Authentication and billing • Optional real-time monitoring via the ConsentSignals agent • Transactional email notifications ConsentSignals does not process end-user personal data from scanned third-party websites beyond technical metadata required to deliver the service.

Categories of data and data subjects

Data subjects: Customer employees, contractors, and authorised users. Categories: names, email addresses, authentication identifiers, billing references, URLs submitted for scanning, and compliance scan outputs.

Processor obligations

ConsentSignals shall: • Process personal data only on documented instructions from the Customer • Ensure persons authorised to process data are bound by confidentiality • Implement appropriate technical and organisational measures (Article 32 GDPR) • Not engage sub-processors without prior notice (see Sub-processors below) • Assist the Customer with data subject requests and DPIAs where reasonable • Delete or return personal data on termination, subject to legal retention • Make available information necessary to demonstrate compliance • Notify the Customer without undue delay of a personal data breach

Sub-processors

The Customer authorises ConsentSignals to use the following sub-processors (updated June 2026): • Supabase — database hosting (EU region) • Vercel — frontend hosting (EU edge) • Railway / Render — API hosting (EU region) • Clerk — authentication (SOC 2 Type II) • Stripe — payment processing (PCI DSS Level 1) • Resend — transactional email (EU region available) • Upstash — Redis cache (EU region) • OpenAI / Anthropic — LLM explanation (EU data residency options; no training on Customer data) ConsentSignals will notify Customers of material sub-processor changes at least 14 days in advance via email or in-app notice. Customers may object on reasonable grounds relating to data protection. A standalone sub-processor list is maintained in our Privacy Policy and updated when vendors change.

International transfers

Where personal data is transferred outside the EEA, ConsentSignals relies on Standard Contractual Clauses (SCCs) and supplementary measures as required. Sub-processor DPAs incorporate SCCs where applicable.

Audit rights

Upon reasonable written request, ConsentSignals will provide SOC 2 reports, penetration test summaries, or complete a security questionnaire. On-site audits may be conducted once per year with 30 days' notice, subject to confidentiality and minimal disruption.

Governing law

This DPA is governed by the laws of Ireland. Courts of Ireland have exclusive jurisdiction, without prejudice to mandatory consumer protections in your country of residence where applicable.

Signing

For a countersigned DPA or custom enterprise terms, contact: privacy@consentsignals.com Subject: DPA request — [Your organisation name] Enterprise and Agency plans include a signed DPA on request. This page constitutes our standard DPA terms for all paid subscriptions unless a separate agreement is executed.
Questions?
Email privacy@consentsignals.com or use the contact form.