PXL Consent

Draft. This document has not been reviewed by a lawyer and is not in force. It will be replaced by the reviewed version before PXL Consent is offered to the public.

Data processing agreement

Last updated: [date]

This data processing agreement ("DPA") forms part of the terms of service between the customer (the controller) and [PXL legal entity name] (PXL, the processor). It is intended to meet the requirements of Article 28 of the GDPR.

1. Subject and duration

PXL processes personal data on the customer's behalf to provide PXL Consent: serving the consent banner to visitors of the customer's websites, recording and storing their consent choices, and letting the customer look them up, export and verify them. Processing lasts for as long as the customer uses the service and until the data is deleted under section 9.

2. Data subjects and personal data

Data subjectsVisitors to the customer's websites that load the PXL Consent script
Personal dataConsent ID (a random identifier), consent choices and method, time, banner and policy version, page address, browser user agent and language, the kind of device derived from the user agent, country derived from the IP address, and the IP address truncated to /16 (IPv4) or /32 (IPv6). The full IP address is used transiently to deliver the service and derive the country, and is not stored.
Special categoriesNone intended. The customer must not configure the service to collect special categories of data.
PurposeRecording and proving consent, and delivering the banner

Cookie scans load the customer's public web pages. Scans do not sign in or submit forms and are not intended to collect personal data.

3. Instructions

PXL processes the personal data only on the customer's documented instructions, which are the terms of service, this DPA and the customer's configuration of the service. Where the law requires PXL to process the data otherwise, PXL informs the customer first, unless the law forbids it. PXL tells the customer if it believes an instruction breaches the GDPR.

4. Confidentiality

People authorised to process the personal data are bound by confidentiality. Access by PXL staff is limited to what is needed to operate and support the service.

5. Security

PXL implements appropriate technical and organisational measures, including:

  • encryption in transit (TLS) for all traffic from browsers, and encrypted backups [confirm];
  • consent records that cannot be updated or deleted by the service's database role, signed per site with Ed25519, hash-chained, and sealed daily with RFC 3161 time-stamps;
  • separation of customers' data by organisation in every query, and domain verification before consent is recorded on self-serve plans;
  • minimisation of stored data, including truncated IP addresses;
  • two-factor sign-in and passkeys for dashboard users, re-authentication for security-sensitive changes, and audit logs of administrative actions;
  • backups with point-in-time recovery, and tested restores [confirm frequency].

6. Sub-processors

The customer authorises the sub-processors below. PXL gives at least [30] days' notice of new or replaced sub-processors by email; the customer may object on reasonable grounds and, if the objection cannot be resolved, terminate the affected service. PXL imposes the same data protection obligations on sub-processors and remains responsible for them.

Sub-processorPurposeLocation
Hetzner Online GmbHHosting of the application and databaseGermany
Cloudflare, Inc.CDN, network protection, country lookupGlobal network; EU Standard Contractual Clauses and the EU-US Data Privacy Framework

The time-stamping authority ([DigiCert, Inc.]) receives only cryptographic digests of the day's log heads, which contain no personal data, and is therefore not a sub-processor.

7. Assistance

Taking into account the nature of the processing, PXL helps the customer respond to data subject requests (the dashboard and API provide lookup by consent ID and export), and with security, breach notification, data protection impact assessments and prior consultation, as far as these concern the service.

8. Personal data breaches

PXL notifies the customer without undue delay, and aims to do so within [48] hours, after becoming aware of a personal data breach affecting the customer's data, with the information available and further information as it becomes available.

9. Deletion and return

Consent records are deleted when the site's retention period (12, 24 or 36 months, chosen by the customer) has passed. On termination, the customer can export the data for [30] days; PXL then deletes it, including from backups within [35] days, unless law requires storage.

10. Audits

PXL makes available the information needed to demonstrate compliance with this DPA. The consent log's evidence bundles let the customer or its auditor verify the integrity of consent records independently. The customer may carry out, or mandate an auditor to carry out, an audit once a year, or after a breach, on [30] days' notice, at its own cost and subject to confidentiality.

11. Transfers

Personal data is stored in Germany. Any transfer outside the EEA by PXL or its sub-processors takes place only with a valid transfer mechanism under Chapter V of the GDPR.

12. Precedence

If this DPA conflicts with the terms of service on the processing of personal data, this DPA takes precedence.