Legal

Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer") and Getia AS ("Processor") for the use of GetCookies ("the Service"). It applies where we process personal data on your behalf as a data processor under the GDPR and other applicable data protection laws. Last updated: January 1, 2026.

1. Definitions

  • Personal Data

    Any information relating to an identified or identifiable natural person.

  • Processing

    Any operation performed on personal data.

  • Controller

    The entity that determines the purposes and means of processing.

  • Processor

    The entity that processes personal data on behalf of the controller.

  • Subprocessor

    Any third party engaged by the processor to process personal data.

2. Scope of processing

The Processor shall process personal data only on documented instructions from the Customer; ensure that persons processing data are subject to confidentiality obligations; implement appropriate technical and organizational security measures; assist the Customer in responding to data subject requests; and delete or return all personal data upon termination of the services.

3. Subprocessors

The Customer authorizes the Processor to engage the subprocessors listed on the subprocessors page. The Processor shall ensure that subprocessors are bound by data protection obligations no less protective than those in this DPA.

4. Security measures

The Processor implements encryption of data in transit (TLS) and at rest (provided at the infrastructure level by our hosting provider), role-based access controls and multi-factor authentication, ongoing dependency vulnerability scanning and code review, and incident response and breach notification procedures. Details are on the security page.

5. Data breach notification

In the event of a personal data breach, the Processor shall notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of the breach.

6. International transfers

When personal data is transferred outside the EEA, the Processor ensures appropriate safeguards are in place, including Standard Contractual Clauses where required.

7. Audit rights

The Processor shall make available to the Customer all information necessary to demonstrate compliance with this DPA and allow for audits conducted by the Customer or an appointed auditor.

8. Contact

Questions about this DPA: Getia AS, data protection contact, [email protected].

Try GetCookies on your own site

Start on the Free plan: one domain, a cookie scan and a consent banner, no credit card required. Upgrade only when you need more.

Começar grátis