Consentinel Data Processing Addendum (DPA)
Last updated: August 12, 2026
This Data Processing Addendum ("DPA") forms part of the Consentinel Terms of Service or other agreement (the "Agreement") between SLI Studios Web Development, LLC, a Florida limited liability company ("Consentinel" or "Processor"), and the Customer organization ("Customer" or "Controller"). It governs Consentinel's processing of Customer Personal Data on Customer's behalf through the Hosted Service.
1. Public WordPress Plugin; when this DPA applies
The Consentinel WordPress Plugin can operate locally without an account or connection to Consentinel. Data created and stored solely in local Plugin mode remains in the Customer-controlled WordPress environment. Consentinel does not receive that data and is not its processor or service provider; this DPA does not apply to it.
This DPA applies when Customer creates or uses a Hosted Service account or affirmatively connects a WordPress site to Consentinel Cloud and Consentinel processes Customer Personal Data. Routine account, billing, support, security, and business-administration data that Consentinel processes for its own purposes is governed by the Privacy Policy and is outside this DPA.
2. Definitions
- Applicable Data Protection Law means privacy and data-protection law applicable to the processing, including, where applicable, the GDPR, UK GDPR, CCPA/CPRA, Florida Digital Bill of Rights, and other United States state privacy laws.
- Customer Personal Data means personal data or personal information described in Annex A that Consentinel processes on Customer's behalf. It includes connected-site Visitor Consent Data but excludes data processed solely in local Plugin mode.
- Data Subject Request means a request to exercise a privacy right under Applicable Data Protection Law.
- GDPR means Regulation (EU) 2016/679.
- Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. It excludes unsuccessful attempts that do not compromise Customer Personal Data.
- Subprocessor means a third party engaged by Consentinel to process Customer Personal Data.
- Visitor Consent Data means consent-event records from visitors of Customer's connected and published sites, including the pseudonymous data described in Annex A.
Terms such as controller, processor, business, service provider, contractor, consumer, personal data, personal information, processing, sale, share, and supervisory authority have the meanings given by Applicable Data Protection Law.
3. Roles and documented instructions
Customer is the controller/business and Consentinel is the processor/service provider for Customer Personal Data. Each party will comply with the obligations applicable to its role.
Customer instructs Consentinel to process Customer Personal Data only to:
- provide, secure, troubleshoot, and support the Hosted Service described in the Agreement and documentation;
- connect and authenticate Customer's WordPress sites; serve Customer's published configuration and SDK bundle; receive, store, display, export, and delete Visitor Consent Data; and perform Customer-requested scans and reports;
- apply Customer's configuration choices, plan, retention period, exports, and deletion instructions; and
- comply with law, in which case Consentinel will inform Customer before processing unless law prohibits notice.
The Agreement, this DPA, Customer's configuration, and authorized use of the Hosted Service constitute Customer's complete documented instructions. Additional instructions must be consistent with the Agreement and may require agreed fees for material implementation work. Consentinel will promptly inform Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law and may suspend the affected processing while the parties resolve it.
4. Customer obligations
Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data and for:
- providing legally sufficient, accessible, and age-appropriate privacy and cookie notices;
- establishing and documenting a lawful basis for each purpose and category, including consent where required;
- configuring categories, defaults, banner behavior, Global Privacy Control, opt-out methods, withdrawal, and retention to match Customer's actual practices and audience;
- responding to Data Subject Requests and maintaining any direct relationship with site visitors;
- ensuring that Customer's trackers, vendors, tag managers, server-side processing, and disclosures comply with law; and
- obtaining verifiable parental or guardian authorization where required for children. Customer will not instruct Consentinel to facilitate sale or sharing of personal information of a person under 16 without the affirmative authorization required by California law, and will comply with GDPR Article 8 and applicable Member State age rules when relying on a child's consent.
Customer will not submit special-category data, sensitive personal information beyond account-access data necessary for the service, or directly identifying visitor information unless the parties first agree in writing on additional safeguards.
5. Processor obligations and purpose limitation
Consentinel will:
- process Customer Personal Data only on documented instructions and only for the purposes in Annex A;
- not sell or share Customer Personal Data, use it for targeted advertising or profiling, or retain, use, or disclose it outside the direct business relationship except as permitted by law;
- not combine Customer Personal Data with personal information received from another customer or collected from Consentinel's own interaction with a visitor, except as legally permitted to provide the contracted business purposes or in de-identified aggregate form that cannot reasonably be re-associated;
- ensure that persons authorized to process Customer Personal Data are bound by confidentiality;
- implement and maintain Annex B measures and not materially reduce their overall protection during the term;
- provide reasonable assistance with Data Subject Requests, security, breach notification, data protection assessments, prior consultation, and Customer's compliance obligations, considering the nature of processing and information available to Consentinel; and
- notify Customer if Consentinel determines it can no longer meet an applicable processor or service-provider obligation and cooperate in reasonable steps to stop and remediate unauthorized processing.
Consentinel may create aggregated or de-identified information only if it takes reasonable measures to prevent re-identification, publicly commits to maintain it in de-identified form, and does not attempt to re-identify it except to test de-identification safeguards as permitted by law.
6. CCPA/CPRA and Florida processor terms
To the extent the CCPA/CPRA applies, Consentinel is a service provider and contractor. It certifies that it understands and will comply with the restrictions in this DPA. Customer grants Consentinel the right to process personal information only for the limited and specified purposes in Section 3 and Annex A. Customer may take reasonable and appropriate steps to help ensure consistent processing and, after notice, to stop and remediate unauthorized use.
To the extent the Florida Digital Bill of Rights applies, this DPA provides the clear processing instructions, nature and purpose, data types, duration, and party rights and obligations required for a controller-processor contract. Consentinel will assist with applicable consumer requests, security and breach duties, and data protection assessments; require confidentiality; delete or return data at Customer's direction subject to law; make compliance information available; and cooperate with reasonable assessments.
Nothing in the Agreement or DPA waives or limits a non-waivable consumer or data-subject right.
7. Confidentiality
Consentinel will limit access to Customer Personal Data to personnel and contractors who need it to provide or secure the Hosted Service. Those persons must be bound by contractual or statutory confidentiality obligations and receive appropriate privacy and security guidance.
8. Subprocessors
Customer gives general written authorization for the following Subprocessors:
| Subprocessor | Processing role | Primary location |
|---|---|---|
| Supabase, Inc. | Hosted Postgres, authentication-related infrastructure, and edge functions supporting the consent API | United States |
| Vercel, Inc. | Application, dashboard, API, and related hosting | United States and provider infrastructure |
| Cloudflare, Inc., if enabled | CDN delivery, network security, and related routing for SDK bundles | Global |
Stripe and Google Public DNS may process Customer account, payment, or domain-verification data as described in the Privacy Policy but do not process Visitor Consent Data as part of the consent-record service.
Consentinel will impose data-protection obligations on each Subprocessor that are no less protective in substance for the processing it performs, and Consentinel remains responsible for each Subprocessor's performance to the extent required by law.
Consentinel will provide at least 30 days' prior notice by email, dashboard, or published subprocessor notice before adding or replacing a Subprocessor that processes Customer Personal Data. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith to resolve the objection. If no reasonable alternative is available, Customer may terminate the affected Hosted Service and receive a prorated refund of prepaid unused fees.
9. Data Subject Requests
Consentinel generally cannot identify a site visitor from pseudonymous Visitor Consent Data alone. Taking into account the nature of processing, Consentinel will provide reasonable technical and organizational assistance for Customer to respond to Data Subject Requests, including available search, export, correction-through-supplement, restriction, and deletion functions.
If Consentinel receives a request relating to Customer Personal Data, it will direct the requester to Customer and promptly notify Customer unless prohibited by law. Consentinel will not independently respond except on Customer's instruction or as legally required. Customer is responsible for verifying the requester and determining the response.
10. Security and Security Incidents
Consentinel will maintain the technical and organizational measures in Annex B, taking into account the state of the art, implementation cost, nature and scope of processing, and risks to individuals.
Consentinel will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data, with a target of 72 hours where practicable. Notice will include information reasonably available concerning the nature of the incident, affected data and individuals, likely consequences, mitigation, and a contact for follow-up. Consentinel may provide information in phases and will cooperate with Customer's legally required investigation, remediation, and notifications.
Notice is not an admission of fault or liability. Customer is responsible for notifications by the controller unless law requires Consentinel to notify directly.
11. Assessments, audits, and compliance information
Consentinel will provide information reasonably necessary to demonstrate compliance with this DPA, including relevant summaries of independent assessments or Subprocessor reports where available.
No more than once annually, and additionally after a material Security Incident or regulator request, Customer may conduct a reasonable assessment itself or through an independent assessor bound by confidentiality. The assessment must use available documentation first, avoid access to other customers' data or security-sensitive systems, occur during normal business hours, and not unreasonably disrupt operations. Customer will bear its costs; Consentinel may charge reasonable fees for material assistance beyond ordinary documentation, unless the assessment identifies a material breach by Consentinel.
Consentinel will provide reasonable assistance with Customer's data protection impact assessments and prior consultation with a supervisory authority when the processing presents a high risk and the requested assistance relates to the Hosted Service.
12. Return, deletion, retention, and legal holds
Customer may export available Customer Personal Data during the term. Hosted Visitor Consent Data is retained according to the Customer plan, currently 90 days for the Free Hosted plan and up to 24 months for paid plans, unless a shorter period is configured or law requires preservation.
At Customer's written direction or upon termination, Consentinel will delete or return Customer Personal Data within 30 days from active systems, except for data that law, a court order, security needs, backup cycles, dispute preservation, or a documented legal hold requires Consentinel to retain. Retained data remains protected by this DPA and will be processed only for the preservation purpose until deletion is permitted.
Deleting a Hosted Service account does not delete records held solely in Customer's local WordPress environment. Customer controls local Plugin retention and deletion.
13. International transfers
Customer Personal Data may be processed in the United States. If Customer transfers personal data subject to GDPR Chapter V to Consentinel, no adequacy decision applies, and the European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 are legally available for the transfer, the parties enter into and are bound by those clauses ("EU SCCs"), Module 2 (Controller to Processor), completed as stated in Annex C. The EU SCCs prevail over conflicting Agreement terms for the regulated transfer.
The parties will cooperate on a transfer impact assessment and implement reasonable supplementary measures. Consentinel will provide information reasonably necessary to evaluate relevant laws and government-access risks and will notify Customer of a legally binding government request when permitted. If Consentinel's processing is directly subject to GDPR under Article 3(2), or the EU SCCs otherwise cannot lawfully support a transfer, the parties will suspend the affected transfer or use another valid Article 46 mechanism.
For UK-restricted transfers, the parties will use the then-current UK International Data Transfer Addendum to the EU SCCs or another valid UK mechanism.
14. General
This DPA terminates when Consentinel no longer processes Customer Personal Data, except provisions that must survive to protect retained data. If a provision conflicts with Applicable Data Protection Law, it will be interpreted to provide the required protection. Amendments required by a change in law may be made on reasonable notice.
15. Liability
Liability under this DPA is governed by the Terms, including the Privacy and Security Cap. Those limits apply only between the parties and do not limit a data subject's non-waivable rights, third-party-beneficiary rights under the EU SCCs, or a regulator's authority.
Annex A - Processing details
- Subject matter: operation of the Hosted Service for connected Customer sites, including site connection, configuration delivery, hosted consent interfaces, consent-event recording, display, export, retention, deletion, and Customer-requested site scans.
- Duration: the Agreement term plus the applicable retention, deletion, backup, and legal-hold periods.
- Nature and purpose: receive and apply Customer instructions; deliver the consent interface and blocking configuration; record and preserve evidence of visitor choices; support GPC and withdrawal; display and export records; secure and troubleshoot the service; and perform documented Customer-requested scans and reports.
- Categories of data subjects: visitors to Customer's connected sites; Customer administrators and authorized users to the limited extent their data is processed on Customer's behalf.
- Categories of personal data: site domain and connection identifiers; consent choices by category; method; GPC signal; timestamp; banner-configuration and SDK versions; coarse jurisdiction; salted hash of truncated IP address (IPv4 /24, IPv6 /64); salted hash of user-agent string; and related service metadata necessary to provide the processing.
- Sensitive or special-category data: none intended. Account authentication data processed by Consentinel as controller is described in the Privacy Policy. Customer must not intentionally submit special-category data through free-text fields or configurations.
- Frequency: continuous when a hosted consent interface is published; periodic or Customer-initiated for configuration synchronization, scans, exports, and support.
- Retention: 90 days for the Free Hosted plan or up to 24 months for paid plans for Visitor Consent Data; configuration history while the connected site exists; deletion and legal-hold exceptions as stated in Section 12.
- Local Plugin exclusion: local consent records, local scanner results, WordPress database content, theme and plugin source files, and local settings are not transferred to Consentinel in local mode and are outside this DPA.
Annex B - Technical and organizational measures
- Access control: per-organization row-level security for client access paths; least-privilege production access; role separation; credentialed and logged administrative access.
- API and credential separation: consent events accepted through controlled service paths; publishable and privileged service credentials separated; billing webhooks signature-verified; site-scoped connection tokens.
- Pseudonymization and minimization: IP truncation before consent-record hashing; per-site server-side salts unavailable to clients; raw IP addresses not stored in consent records; user-agent hashing; coarse rather than precise jurisdiction.
- Integrity and evidence: consent events append-only through normal service interfaces; published banner configurations frozen; configuration and consent records associated with version and time metadata.
- Encryption: TLS in transit; encryption at rest through hosting providers; secrets stored in controlled service environments.
- Availability and resilience: provider infrastructure, backups and recovery mechanisms appropriate to the service, cached or local behavior where documented, monitoring, and incident-response procedures.
- Retention and disposal: tier-based scheduled purges, constrained query windows, deletion workflows, backup cycling, and legal-hold controls.
- Development and operations: change review, dependency and vulnerability management, environment separation where appropriate, access revocation, and security-focused logging.
- Subprocessor governance: diligence, contractual data-protection obligations, change notice, and review of available security assurances.
- Review: periodic evaluation of measures in light of changes to risk, law, and the service.
Annex C - EU SCC completion particulars
For transfers requiring the EU SCCs:
- Module: Module 2, Controller to Processor.
- Clause 7: the optional docking clause applies.
- Clause 9: Option 2, general written authorization, with the 30-day notice period in Section 8.
- Clause 11: the optional independent dispute-resolution language does not apply unless the parties agree otherwise in writing.
- Clause 13: the competent supervisory authority is determined under Clause 13 of the EU SCCs based on the data exporter's establishment, representative, or affected data subjects.
- Clause 17: Option 1 applies; the EU SCCs are governed by the law of Ireland.
- Clause 18: the courts of Ireland have jurisdiction.
- Annex I.A - data exporter: Customer and its address and contact details stated in the Agreement or Customer account; role: controller. Activities: operation of Customer's connected sites and use of the Hosted Service. Signature and date: Customer's legally binding acceptance of the Agreement and DPA.
- Annex I.A - data importer: SLI Studios Web Development, LLC, 1688 Meridian Avenue, Suite 700, Miami Beach, Florida 33139, USA; legal@consentinel.co; role: processor. Activities: providing the Hosted Service described in Annex A. Signature and date: Consentinel's legally binding acceptance of the Agreement and DPA.
- Annex I.B: the transfer description is Annex A.
- Annex II: the technical and organizational measures are Annex B.
- Annex III: the authorized Subprocessors are listed in Section 8.