Legal
Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer") and Getia AS ("Processor") for the use of GetCookies ("the Service"). It applies where we process personal data on your behalf as a data processor under the GDPR and other applicable data protection laws. Last updated: January 1, 2026.
1. Definitions
Personal Data
Any information relating to an identified or identifiable natural person.
Processing
Any operation performed on personal data.
Controller
The entity that determines the purposes and means of processing.
Processor
The entity that processes personal data on behalf of the controller.
Subprocessor
Any third party engaged by the processor to process personal data.
2. Scope of processing
The Processor shall process personal data only on documented instructions from the Customer; ensure that persons processing data are subject to confidentiality obligations; implement appropriate technical and organizational security measures; assist the Customer in responding to data subject requests; and delete or return all personal data upon termination of the services.
3. Subprocessors
The Customer authorizes the Processor to engage the subprocessors listed on the subprocessors page. The Processor shall ensure that subprocessors are bound by data protection obligations no less protective than those in this DPA.
4. Security measures
The Processor implements encryption of data in transit (TLS) and at rest (provided at the infrastructure level by our hosting provider), role-based access controls and multi-factor authentication, ongoing dependency vulnerability scanning and code review, and incident response and breach notification procedures. Details are on the security page.
5. Data breach notification
In the event of a personal data breach, the Processor shall notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of the breach.
6. International transfers
When personal data is transferred outside the EEA, the Processor ensures appropriate safeguards are in place, including Standard Contractual Clauses where required.
7. Audit rights
The Processor shall make available to the Customer all information necessary to demonstrate compliance with this DPA and allow for audits conducted by the Customer or an appointed auditor.
8. Contact
Questions about this DPA: Getia AS, data protection contact, [email protected].
Try GetCookies on your own site
Start on the Free plan: one domain, a cookie scan and a consent banner, no credit card required. Upgrade only when you need more.
무료로 시작