Skip to content

Legal

Data processing agreement

Last updated August 24, 2026.

Introduction

This Data Processing Agreement ("DPA") forms part of the agreement between you ("Controller", "Customer") and OptinStack ("Processor") when you use the OptinStack consent management platform (the "Service").

The Processor is OptinStack LLC, 30 N Gould St, STE R, Sheridan, WY 82801, USA.

It applies when we process personal data on your behalf, for example consent records, visitor identifiers, and configuration data tied to your projects and domains.

By using Free or paid plans, you agree to this DPA in addition to our Terms and Conditions and Privacy Policy. Enterprise customers may request a countersigned copy via OptinStack hello@optinstack.com.

Roles and scope

You determine the purposes and means of processing personal data collected from visitors to your websites through OptinStack. You are the Controller for that data.

OptinStack processes personal data only to provide the Service, hosting configuration, syncing consent records, generating exports, running scans you initiate, optional Consent Forwarding you configure, and related operational tasks documented in your workspace settings.

We process personal data only on your documented instructions, including the Terms, this DPA, and actions you take in the dashboard.

If we believe that an instruction infringes the GDPR or other applicable EU or Member State data protection law, or the UK GDPR or other applicable UK data protection law, we will inform you without undue delay.

Categories of personal data

Subject to your configuration, the personal data we process as Processor typically includes consent records and related technical metadata such as: a salted hash of the visitor IP address (never the raw IP), browser user agent, server-derived region, page URL and domain, consent action and mode, selected consent categories, Global Privacy Control signal if present, banner text snapshot, runtime version metadata, optional legislation or framework fields (including TCF or GPP strings when enabled), and delivery status for Consent Forwarding when configured.

We do not process visitor names, email addresses, or payment card data as part of standard consent-record processing. Account and billing data for your OptinStack users is described in our Privacy Policy and is processed as controller data for our relationship with you, not as processor data for your end users.

Processor obligations

OptinStack will:

  • Process personal data only to deliver and support the Service.
  • Ensure personnel with access to personal data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures.
  • Assist you with data subject requests where feasible, considering the nature of processing and information available to us.
  • Assist you, to the extent reasonably feasible given the nature of the processing and the information available to us, with data protection impact assessments and prior consultation with supervisory authorities under Articles 35 and 36 GDPR or equivalent obligations that apply to you as Controller.
  • Notify you without undue delay after becoming aware of a personal data breach affecting your workspace data.
  • Delete or return personal data upon termination of the Service, as described in the Retention and deletion section below.
  • Not sell personal data or use it for unrelated commercial purposes.

Controller obligations

You will:

  • Ensure you have a lawful basis to collect and process visitor data through the Service.
  • Publish accurate privacy notices and link them from your consent banner and consent preferences surfaces.
  • Configure retention, categories, regional modes, and optional Consent Forwarding endpoints appropriate for your properties.
  • Review scan outputs and automatic tracker classifications, which are estimates only, and determine the correct legal category for every tracker used on your properties.
  • Respond to data subject requests for data you control as Controller, including data held at any Consent Forwarding destination you operate.

If you enable Consent Forwarding, you instruct OptinStack to transmit copies of consent records to an HTTPS endpoint you specify. You are responsible for the security, retention, and lawful use of data at that destination. The endpoint provider is your processor or service provider, not an OptinStack sub-processor under this DPA.

OptinStack standard retention and automatic deletion apply only to personal data stored in OptinStack systems. Records already delivered to your endpoint are outside OptinStack storage once accepted by your destination.

An eligible project selection of a Preferred consent storage region is a documented storage instruction for future authoritative consent records, regional cold consent-analytics archives, and temporary CSV export artifacts. Cloudflare location hints are best-effort and do not restrict all processing or access to the selected geography.

If a project has more than one historical assignment, OptinStack may process records across those regions to perform authorized reads, exports, retention, and deletion. A later selection does not migrate earlier records. Cloudflare edge processing, queues, Pipelines, Analytics Engine, logs, support, security, and administration may operate globally, and the SCCs, UK Addendum, and other applicable transfer safeguards continue to apply.

Retention and deletion

Consent records collected through your configuration are retained according to the plan for each project, unless you request earlier deletion: three (3) years on Free, Pro, Business, and Workspace site-pack plans, and five (5) years or a custom period on Enterprise. Records that pass the end of the applicable window are scheduled for deletion from OptinStack’s active consent-record store, following a short technical buffer after that window. Archiving a project stops runtime activity but does not pause or extend the applicable retention window. You may delete individual consent records from your workspace at any time; verified project-wide erasure requires a support request. Enterprise customers may negotiate a different retention period under a separate written agreement. Other logs, backups, exports, and forwarded copies follow separate lifecycles.

Account, workspace, and billing data is retained while your account is active and for a reasonable period afterward to comply with legal obligations and resolve disputes. Operational logs are retained according to documented internal schedules.

Upon termination, you may export your consent records and configuration while your account remains active. After termination, we will delete or return your personal data subject to legal retention requirements. To request deletion of specific data, contact OptinStack hello@optinstack.com.

Sub-processors

You provide general written authorization for OptinStack to engage sub-processors to support the Service (Article 28 GDPR; EU SCCs Module 2, Clause 9, Option 2). A current, categorized list of Customer Data Subprocessors, including services, data categories, locations, transfer mechanisms, optionality, privacy links, and effective dates, is published at Subprocessors and Service Providers and incorporated into this DPA by reference.

We require sub-processors to meet data protection obligations substantially similar to those in this DPA.

We will inform you of intended additions or replacements of sub-processors at least thirty (30) days before the new sub-processor is engaged, by updating the Subprocessor List at Subprocessors and Service Providers and, where we have a working email address for your account, by email to that address. You may object to an intended change on reasonable data-protection grounds before engagement by contacting OptinStack hello@optinstack.com. If you object and we cannot reasonably accommodate the objection, you may terminate the affected Service as described in the Terms.

Objections or sub-processor questions: OptinStack hello@optinstack.com.

International transfers

Personal data may be processed in the United States and other countries where we or our sub-processors operate. Our infrastructure runs on a global edge network with no region pinning by default.

For restricted transfers from the EEA, the parties incorporate the European Commission Standard Contractual Clauses adopted by Decision 2021/914, Module 2 (Controller to Processor), with the following Module 2 selections completed:

  • Clause 9 (Use of sub-processors): Option 2 (General written authorization). The data importer will inform the data exporter of any intended changes to sub-processors at least thirty (30) days in advance, as described in the Sub-processors section of this DPA.
  • Clause 17 (Governing law): these Clauses shall be governed by the law of Ireland.
  • Clause 18 (Choice of forum and jurisdiction): any dispute arising from these Clauses shall be resolved by the courts of Ireland.

UK and Swiss transfer terms

For UK restricted transfers, the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0, in force 21 March 2022) (the “UK Addendum”) applies. Part 1 Tables are completed as follows:

  • Table 1 (Parties): the parties and key contacts are as identified in Transfer Annex I (Exporter: the Customer as controller; Importer: OptinStack LLC as processor; contact for both: the email stated in Transfer Annex I).
  • Table 2 (Selected SCCs, Modules and Selected Clauses): the EU SCCs Module 2 (Controller to Processor) with Clause 9 Option 2, Clause 17 (Ireland), and Clause 18 (courts of Ireland) as stated in International transfers above.
  • Table 3 (Appendix Information): the appendix information is set out in Transfer Annex I, Transfer Annex II, and Transfer Annex III of this DPA (including the Subprocessor List at Subprocessors and Service Providers).
  • Table 4 (Ending this Addendum when the Approved Addendum changes): either party may end the Addendum as set out in Section 19 of the UK Addendum Mandatory Clauses.

UK Addendum Mandatory Clauses and Swiss adaptations

Part 2 Mandatory Clauses of the Approved Addendum are incorporated by reference. For the purposes of Section 12 of those Mandatory Clauses, the information required by the format of the UK Addendum is as completed in the Part 1 Tables above and in the Annexes of this DPA.

For Swiss transfers, references in the SCCs are adapted to the Swiss Federal Act on Data Protection and the competent Swiss authority where applicable.

These transfer terms apply to every affected customer, including Free and paid self-serve plans. If this DPA conflicts with the SCCs, the UK Addendum, or other mandatory transfer terms, those transfer terms prevail; otherwise this DPA prevails over conflicting commercial terms for processing personal data.

Security

We maintain administrative, technical, and organizational safeguards designed to protect personal data, including encryption in transit (TLS), encryption at rest as provided by our infrastructure providers, application-level encryption for selected secrets we store on your behalf, role-based access controls, multi-factor authentication available through our identity provider, audit logging of sensitive actions, and monitoring of production systems.

No system is completely secure. You are responsible for securing access to your account credentials, workspace permissions, and any Consent Forwarding endpoint you configure.

Transfer Annex I: parties and processing

Exporter: the Customer identified by the OptinStack account or order, acting as controller. Importer: OptinStack LLC, 30 N Gould St, STE R, Sheridan, WY 82801, USA, acting as processor. Contact for both DPA and transfer matters: OptinStack hello@optinstack.com.

Processing covers hosting consent configuration, collecting and retaining consent records, customer-initiated public-site scans, exports, and related support for the subscription term plus documented deletion and legal-retention periods. Data subjects are Customer website visitors and authorized Customer users. Data categories are described in Categories of personal data. Transfers may occur continuously while the Service is used. The competent supervisory authority is determined under Clause 13 of the SCCs.

Transfer Annex II: technical and organizational measures

Measures include TLS in transit; provider-supported encryption at rest; application-level encryption for selected secrets; role-based and least-privilege access; identity-provider authentication and available multi-factor authentication; audit logging of sensitive actions; tenant and project authorization controls; backup and recovery measures; vulnerability and dependency management; incident response; personnel confidentiality; and sub-processor due diligence.

Transfer Annex III: approved sub-processors

The approved Customer Data Subprocessors, services, data categories, locations, transfer mechanisms, optionality, privacy links, and effective dates are maintained in the Customer Data Subprocessors section of Subprocessors and Service Providers and incorporated into this DPA by reference. Other service providers and independent controllers listed on that page for transparency are outside this Annex III list.

Audits and documentation

Upon reasonable written request, we will make available information necessary to demonstrate compliance with this DPA and Article 28 of the GDPR (or equivalent obligations under the UK GDPR or other applicable law), subject to confidentiality and security constraints.

You (or an independent auditor mandated by you that is not a competitor of OptinStack) may conduct audits, including inspections, of our processing of Customer Personal Data under this DPA. Audits are subject to: (a) at least thirty (30) days’ prior written notice, except where a supervisory authority requires a shorter period or where there is a personal data breach affecting your data; (b) reasonable frequency, ordinarily not more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach; (c) performance during normal business hours and in a manner that does not unreasonably disrupt our operations; (d) written confidentiality obligations for any external auditor; and (e) our right to require that review of sensitive security information occur first through documentation, questionnaires, and available third-party reports (for example SOC or ISO reports from our infrastructure providers) where those materials reasonably address the request.

Where an on-site audit remains reasonably necessary after those materials, we will contribute to that audit under a mutually agreed scope and security rules. You bear the reasonable costs of extraordinary audits beyond annual documentation review, unless the audit reveals a material breach of this DPA attributable to us.

Term

This DPA remains in effect for as long as OptinStack processes personal data on your behalf. Provisions intended to survive termination (including confidentiality and deletion obligations) will survive.