Introduction
This Data Processing Agreement ("DPA") forms part of the agreement between you ("Controller", "Customer") and OptinStack ("Processor") when you use the OptinStack consent management platform (the "Service").
The Processor is OptinStack LLC, 30 N Gould St, STE R, Sheridan, WY 82801, USA.
It applies when we process personal data on your behalf, for example consent records, visitor identifiers, and configuration data tied to your projects and domains.
By using Free or paid plans, you agree to this DPA in addition to our Terms and Conditions and Privacy Policy. Enterprise customers may request a countersigned copy via hello@optinstack.com.
Roles and scope
You determine the purposes and means of processing personal data collected from visitors to your websites through OptinStack. You are the Controller for that data.
OptinStack processes personal data only to provide the Service, hosting configuration, syncing consent records, generating exports, running scans you initiate, optional Consent Forwarding you configure, and related operational tasks documented in your workspace settings.
We process personal data only on your documented instructions, including the Terms, this DPA, and actions you take in the dashboard.
Categories of personal data
Subject to your configuration, the personal data we process as Processor typically includes consent records and related technical metadata such as: a salted hash of the visitor IP address (never the raw IP), browser user agent, server-derived region, page URL and domain, consent action and mode, selected consent categories, Global Privacy Control signal if present, banner text snapshot, runtime version metadata, optional legislation or framework fields (including TCF or GPP strings when enabled), and delivery status for Consent Forwarding when configured.
We do not process visitor names, email addresses, or payment card data as part of standard consent-record processing. Account and billing data for your OptinStack users is described in our Privacy Policy and is processed as controller data for our relationship with you, not as processor data for your end users.
Processor obligations
OptinStack will:
- Process personal data only to deliver and support the Service.
- Ensure personnel with access to personal data are bound by confidentiality obligations.
- Implement appropriate technical and organizational security measures.
- Assist you with data subject requests where feasible, considering the nature of processing and information available to us.
- Notify you without undue delay after becoming aware of a personal data breach affecting your workspace data.
- Delete or return personal data upon termination of the Service, as described in the Retention and deletion section below.
- Not sell personal data or use it for unrelated commercial purposes.
Controller obligations
You will:
- Ensure you have a lawful basis to collect and process visitor data through the Service.
- Publish accurate privacy notices and link them from your consent banner and consent preferences surfaces.
- Configure retention, categories, regional modes, and optional Consent Forwarding endpoints appropriate for your properties.
- Respond to data subject requests for data you control as Controller, including data held at any Consent Forwarding destination you operate.
Consent Forwarding
If you enable Consent Forwarding, you instruct OptinStack to transmit copies of consent records to an HTTPS endpoint you specify. You are responsible for the security, retention, and lawful use of data at that destination. The endpoint provider is your processor or service provider, not an OptinStack sub-processor under this DPA.
OptinStack standard retention and automatic deletion apply only to personal data stored in OptinStack systems. Records already delivered to your endpoint are outside OptinStack storage once accepted by your destination.
Preferred consent storage region instruction
An eligible project selection of a Preferred consent storage region is a documented storage instruction for future authoritative consent records, regional cold consent-analytics archives, and temporary CSV export artifacts. Cloudflare location hints are best-effort and do not restrict all processing or access to the selected geography.
If a project has more than one historical assignment, OptinStack may process records across those regions to perform authorized reads, exports, retention, and deletion. A later selection does not migrate earlier records. Cloudflare edge processing, queues, Pipelines, Analytics Engine, logs, support, security, and administration may operate globally, and the SCCs, UK Addendum, and other applicable transfer safeguards continue to apply.
Retention and deletion
Consent records collected through your configuration are retained for twelve (12) months on standard plans, unless you request earlier deletion. Archiving a project stops runtime activity but does not pause or extend the standard retention window. You may delete individual consent records from your workspace at any time; verified project-wide erasure requires a support request. Enterprise customers may negotiate a different retention period under a separate written agreement.
Account, workspace, and billing data is retained while your account is active and for a reasonable period afterward to comply with legal obligations and resolve disputes. Operational logs are retained according to documented internal schedules.
Upon termination, you may export your consent records and configuration while your account remains active. After termination, we will delete or return your personal data subject to legal retention requirements. To request deletion of specific data, contact hello@optinstack.com.
Sub-processors
You authorize OptinStack to engage sub-processors to support the Service. A current, categorized list, including the purpose and location of processing for each sub-processor, is published at /legal/subprocessors.
We require sub-processors to meet data protection obligations substantially similar to those in this DPA. We provide at least 30 days notice of material sub-processor changes by email to account owners and by updating the published list.
Objections or sub-processor questions: hello@optinstack.com.
International transfers
Personal data may be processed in the United States and other countries where we or our sub-processors operate. Our infrastructure runs on a global edge network with no region pinning by default.
For restricted transfers from the EEA, the parties incorporate the European Commission Standard Contractual Clauses adopted by Decision 2021/914, Module 2 (Controller to Processor). For UK restricted transfers, the UK International Data Transfer Addendum modifies those clauses. For Swiss transfers, references are adapted to the Swiss Federal Act on Data Protection and the competent Swiss authority where applicable.
These transfer terms apply to every affected customer, including Free and paid self-serve plans. If this DPA conflicts with the SCCs or mandatory transfer terms, those transfer terms prevail; otherwise this DPA prevails over conflicting commercial terms for processing personal data.
Security
We maintain administrative, technical, and organizational safeguards designed to protect personal data, including encryption in transit (TLS), encryption at rest as provided by our infrastructure providers, application-level encryption for selected secrets we store on your behalf, role-based access controls, multi-factor authentication available through our identity provider, audit logging of sensitive actions, and monitoring of production systems.
No system is completely secure. You are responsible for securing access to your account credentials, workspace permissions, and any Consent Forwarding endpoint you configure.
Transfer Annex I: parties and processing
Exporter: the Customer identified by the OptinStack account or order, acting as controller. Importer: OptinStack LLC, 30 N Gould St, STE R, Sheridan, WY 82801, USA, acting as processor. Contact for both DPA and transfer matters: hello@optinstack.com.
Processing covers hosting consent configuration, collecting and retaining consent records, customer-initiated public-site scans, exports, and related support for the subscription term plus documented deletion and legal-retention periods. Data subjects are Customer website visitors and authorized Customer users. Data categories are described in Categories of personal data. Transfers may occur continuously while the Service is used. The competent supervisory authority is determined under Clause 13 of the SCCs.
Transfer Annex II: technical and organizational measures
Measures include TLS in transit; provider-supported encryption at rest; application-level encryption for selected secrets; role-based and least-privilege access; identity-provider authentication and available multi-factor authentication; audit logging of sensitive actions; tenant and project authorization controls; backup and recovery measures; vulnerability and dependency management; incident response; personnel confidentiality; and sub-processor due diligence.
Transfer Annex III: approved sub-processors
The approved sub-processors, services, data categories, locations, transfer mechanisms, optionality, privacy links, and effective dates are maintained on /legal/subprocessors and incorporated into this DPA by reference.
Audits and documentation
Upon reasonable written request, we will provide information necessary to demonstrate compliance with this DPA, subject to confidentiality and security constraints.
On-site audits may be available for Enterprise customers under separate agreement.
Term
This DPA remains in effect for as long as OptinStack processes personal data on your behalf. Provisions intended to survive termination (including confidentiality and deletion obligations) will survive.