Data Processing Agreement
Contents
1. Definitions
Terms not defined in this Data Processing Agreement ("DPA") have the meaning given to them in the General Data Protection Regulation (EU) 2016/679 ("GDPR") or, where applicable, the UK GDPR and the Data Protection Act 2018.
- "Controller" means the Merchant who installs and configures ConsentCraft on their Shopify store and determines the purposes and means of processing Store Visitor data.
- "Processor" means Lucent Labs LLC, a California Single-Member Limited Liability Company (EIN 42-2711201), publishing entity of ConsentCraft.
- "Subprocessor" means any third party engaged by the Processor to assist in providing the Service that processes Personal Data.
- "Service" means the ConsentCraft application and all related features, as described in the Terms of Service.
- "Personal Data" has the meaning given in the GDPR.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
- "Store Visitor" means any person who visits a Merchant's Shopify storefront where a ConsentCraft consent banner is active.
- "EEA" means the European Economic Area.
- "EU SCCs" means the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (Controller to Processor).
- "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office under S119A(1) Data Protection Act 2018 (version B1.0, in force 21 March 2022).
2. Processing Details
The following details describe the processing carried out under this DPA and constitute Annex I.B to the EU SCCs (see Section 10).
| Subject matter | Operation of the ConsentCraft consent management platform on the Controller's Shopify store |
|---|---|
| Duration | For the term of the Terms of Service between Controller and Processor, plus any applicable retention periods thereafter |
| Nature of processing | Recording, storing, retrieving, and transmitting consent decisions and related audit data |
| Purpose of processing | Enabling the Controller to meet its consent record-keeping obligations under applicable data protection law, and to provide documented evidence of Store Visitor consent decisions |
| Types of personal data | Consent decision (category-level), consent timestamp, consent version identifier, partial IP address (last octet masked), browser type, screen width |
| Categories of data subjects | Store Visitors who interact with the Controller's ConsentCraft consent banner on the Controller's Shopify storefront |
| Frequency of transfer | Continuous during the term of this DPA |
| Retention period | 13 months rolling — consent records are automatically purged after 13 months. See Section 3.7. |
3. Article 28 Obligations
3.1 — Documented Instructions (Art. 28(3)(a))
Processor shall process Personal Data only on documented instructions from the Controller. The Controller's instructions are embodied in the ConsentCraft app configuration set by the Merchant. If Processor is required by Union or Member State law to process Personal Data in a manner not covered by Controller's instructions, Processor will inform Controller before processing, unless prohibited from doing so by law.
If Processor reasonably believes a Controller instruction infringes the GDPR or other applicable data protection law, Processor will promptly inform Controller. Processor is not required to follow instructions that violate applicable law.
3.2 — Confidentiality (Art. 28(3)(b))
Processor ensures that all persons authorized to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.3 — Security (Art. 28(3)(c) / Art. 32)
Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- TLS 1.2+ encryption for all Personal Data in transit
- AES-256 encryption for Personal Data at rest
- Multi-tenant data isolation — all Personal Data is stored under shop-scoped partition keys; no cross-tenant access is possible by design
- Role-based access controls limiting access to authorized personnel
- Regular security reviews and vulnerability assessments
- Incident detection and response procedures
The full technical and organizational measures are set out in Annex II (Section 10).
3.4 — Subprocessors (Art. 28(3)(d))
Processor shall not engage new Subprocessors without the Controller's general or specific prior authorization. This DPA constitutes the Controller's general authorization for the Subprocessors listed in Section 5. Processor shall give at least 30 days' advance notice before engaging any new Subprocessor by updating this DPA and notifying active Merchants. If the Controller objects to a new Subprocessor on reasonable data protection grounds within the notice period, either party may terminate the Terms of Service.
Where Processor engages Subprocessors, it imposes data protection obligations on those Subprocessors equivalent to those in this DPA. Processor remains liable to Controller for the performance of Subprocessors.
3.5 — Assistance with Data Subject Rights (Art. 28(3)(e))
Processor shall assist Controller in fulfilling its obligations to respond to requests from data subjects exercising their rights under Articles 15 to 22 of the GDPR. Where Processor receives a data subject request that it reasonably believes relates to Personal Data processed on behalf of a Controller, it will forward the request to the relevant Controller within 72 hours without responding to the data subject directly.
3.6 — Assistance with Art. 32–36 Obligations (Art. 28(3)(f))
Processor shall assist Controller in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR (security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities), taking into account the nature of processing and the information available to Processor.
3.7 — Deletion or Return (Art. 28(3)(g))
Upon expiry or termination of the Terms of Service, Processor shall, at the choice of the Controller, delete or return all Personal Data processed on the Controller's behalf, and shall delete existing copies, unless Union or Member State law requires storage for a longer period. Deletion will be completed within 30 days of termination unless Controller requests return of data in writing first.
During the term of this DPA, consent records are retained on a 13-month rolling basis and automatically purged thereafter (see Section 2, Annex I.B). This period reflects the minimum necessary to support the Controller's consent audit obligations under applicable data protection law.
3.8 — Audit Rights (Art. 28(3)(h))
Processor shall make available to Controller all information necessary to demonstrate compliance with this Article, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
Audit conditions:
- Audit requests must be submitted in writing to privacy@consentcraft.ai
- At least 30 days' advance notice is required
- Audits may be conducted no more than once per calendar year
- Audit costs (including Processor's reasonable time) are borne by Controller
- Audits must not unreasonably disrupt Processor's business operations or compromise other Merchants' data
As an alternative to on-site audit, Processor shall satisfy audit obligations by providing relevant security certifications, third-party audit reports, or written attestations from qualified security personnel.
4. Breach Notification
Processor shall notify Controller without undue delay and, where feasible, no later than 48 hours after becoming aware of a Personal Data Breach affecting Personal Data of data subjects located in the EEA or United Kingdom. For Personal Data Breaches affecting data subjects in other jurisdictions, notification shall be made within 72 hours where feasible.
The notification shall, to the extent then known, include:
- A description of the nature of the breach
- The categories and approximate number of data subjects and Personal Data records affected
- The likely consequences of the breach
- The measures taken or proposed to address the breach, including mitigation steps
Where information is not available at the time of initial notification, Processor shall provide it as soon as reasonably practicable in supplementary notifications. Notification to Controller does not constitute an admission of fault or liability.
Breach notifications will be sent to the Merchant email address on file. The Controller is responsible for its own notifications to supervisory authorities and affected data subjects as required by applicable law, including under GDPR Article 33 (72-hour supervisory authority notification) and Article 34 (data subject communication where required).
5. Authorized Subprocessors
The Controller provides general authorization for the following Subprocessors as of the effective date of this DPA. Processor shall provide at least 30 days' advance notice before engaging any new Subprocessor (see Section 3.4). Subprocessors are also listed in Annex III (Section 10).
| Subprocessor | Role | Location | Transfer Safeguard |
|---|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure (Lambda, DynamoDB, S3, CloudFront) | United States | EU SCCs + AWS Customer Agreement DPA |
| Amazon Simple Email Service | Transactional email delivery | United States | EU SCCs + AWS Customer Agreement DPA |
| Shopify Inc. | App platform (billing, OAuth, app distribution) | Canada / United States | EU SCCs + Shopify DPA |
| Bunny Way d.o.o. (Bunny CDN) | Static asset delivery (JavaScript, CSS bundles) | EU (Slovenia + global edge) | EEA-to-EEA transfer — no SCC required. Governed by Bunny CDN DPA. |
Copies of applicable SCCs and DPA links are available upon request at privacy@consentcraft.ai.
6. International Data Transfers
6.1 — EU Standard Contractual Clauses (Module 2)
Where Personal Data of EEA data subjects is transferred from the Controller (data exporter) to the Processor (data importer) in the United States or Canada, the parties hereby incorporate by reference the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (Controller to Processor) ("EU SCCs"). The EU SCCs form an integral part of this DPA. The Annexes required by the EU SCCs are set out in Section 10.
The following optional provisions and docking clauses apply to the EU SCCs as incorporated herein:
- Clause 7 (Docking clause): not used.
- Clause 9 (Use of subprocessors): general authorization for the Subprocessors listed in Section 5 (Annex III). Prior notice period for new Subprocessors: 30 calendar days.
- Clause 11 (Redress): optional independent dispute-resolution language not included.
- Clause 13(a) (Competent supervisory authority): Because Processor has no establishment in the EU and has not designated a representative under GDPR Article 27 as of the effective date, the competent supervisory authority is the Irish Data Protection Commission (DPC) — 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland — dataprotection.ie, in accordance with Clause 13(a) third bullet. See Annex I.C (Section 10) and Section 6.6 for the update trigger upon Art. 27 appointment.
- Clause 17 (Governing law): the EU SCCs are governed by the law of Ireland. See Section 8.2.
- Clause 18 (Choice of forum and jurisdiction): disputes arising from the EU SCCs shall be resolved by the courts of Ireland. See Section 8.2.
6.2 — Transfers within the EEA
Transfers of Personal Data within the EEA — including transfers to Bunny Way d.o.o. (Slovenia), which is established within the EEA — do not require Standard Contractual Clauses and are governed solely by the GDPR without the need for Article 46 safeguards.
6.3 — UK International Data Transfer Addendum
For transfers of Personal Data from the United Kingdom, the parties further incorporate by reference the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office under S119A(1) Data Protection Act 2018 (version B1.0, in force 21 March 2022) ("UK Addendum"). The UK Addendum amends and supplements the EU SCCs for UK transfers. The Tables required by the UK Addendum are set out in Section 11.
The EU SCCs as amended by the UK Addendum are governed by the law of England and Wales and subject to the exclusive jurisdiction of the courts of England and Wales (see Section 8.3).
6.4 — Transfer Impact Assessment (EU SCC Clause 14)
Processor represents that, to its knowledge, the laws and practices of the United States applicable to Processor's processing under this DPA do not prevent compliance with the EU SCCs. This assessment is based on: (a) the limited sensitivity of the Personal Data (consent records, masked IP); (b) the absence of special-category data; and (c) no specific US law or practice known to Processor that would require disclosure of the Personal Data to US authorities in a manner inconsistent with the EU SCCs.
Processor will inform Controller without undue delay if Processor becomes aware of any change in the applicable legal framework that could affect this representation.
6.5 — Government Access (EU SCC Clause 15)
Processor will use commercially reasonable efforts to notify Controller before disclosing Personal Data in response to a legally binding government request, to the extent permitted by applicable law. Where notification is legally prohibited, Processor will use commercially reasonable efforts to challenge the request before disclosing. In all cases, Processor will disclose only the minimum Personal Data required and will inform Controller as soon as any notification prohibition is lifted.
6.6 — Article 27 GDPR Representative
As of the effective date of this DPA, Processor has not designated a formal representative in the EU or UK pursuant to GDPR Article 27. Accordingly, the Irish Data Protection Commission is designated as the competent supervisory authority in Annex I.C (Section 10), per Clause 13(a) third bullet.
Upon appointment of an Article 27 representative, Processor will: (a) update Annex I.C to reflect the representative's member state supervisory authority per Clause 13(a) second bullet; and (b) update Sections 6.1 and 6.6 with the representative's identity and contact details. Active Merchants will be notified.
7. Liability
7.1
Each party's liability under this DPA is subject to the limitations set out in the Terms of Service, except as otherwise required by mandatory applicable law.
7.2
Nothing in this DPA or the Terms of Service limits or excludes either party's liability under GDPR Article 82 to data subjects who have suffered damage as a result of an infringement of the GDPR. Where Processor has caused damage to a data subject as a direct result of Processor's breach of its obligations as a data processor under Chapter IV of the GDPR, the aggregate cap in the Terms of Service does not apply to that liability.
7.3
If either party pays compensation to a data subject for damage caused by an infringement for which both parties are jointly responsible, that party may seek contribution from the other party to the extent of the other party's responsibility for the same damage, in accordance with GDPR Article 82(5).
7.4 — No Legal Advice; No Reliance; Integration
ConsentCraft is a technology tool. Nothing in this DPA, the Terms of Service, or any other ConsentCraft documentation constitutes legal advice, a legal opinion, or a compliance certification of any kind. Each party acknowledges that it has not relied on any representation, warranty, or promise not expressly set out in this DPA or the Terms of Service in entering into this agreement. This DPA, together with the Terms of Service and (where applicable) the EU SCCs and UK Addendum incorporated herein, constitutes the entire agreement between the parties with respect to the processing of Personal Data and supersedes all prior agreements and representations on that subject.
8. Governing Law
8.1 — DPA Body
Except as provided in Sections 8.2 and 8.3, this DPA is governed by and construed in accordance with the laws of the State of California, United States, without regard to its conflict-of-law provisions.
8.2 — EU Standard Contractual Clauses
The EU SCCs incorporated in Section 6.1 and their Annexes (Section 10) are governed by the law of Ireland, in accordance with Clause 17 of the EU SCCs. Disputes arising from the EU SCCs shall be resolved exclusively by the courts of Ireland, in accordance with Clause 18.
8.3 — UK Addendum
The UK Addendum incorporated in Section 6.3 and the Tables in Section 11 are governed by the law of England and Wales, in accordance with Section 17 of the UK Addendum. Disputes arising from the UK Addendum shall be resolved by the courts of England and Wales.
8.4 — Conflict / Precedence
In the event of conflict between different parts of this DPA:
- The EU SCCs (Section 6.1 and Annexes in Section 10) prevail over any conflicting provision in the DPA body (Sections 1–7 and 9) with respect to transfers of EEA Personal Data.
- The UK Addendum (Section 6.3 and Tables in Section 11) prevails over any conflicting provision in the EU SCCs or DPA body with respect to transfers of UK Personal Data, to the extent of the conflict.
- Mandatory applicable data protection law prevails over any conflicting provision in this DPA.
8.5 — Contact
For questions regarding this DPA or to request a countersigned copy:
Lucent Labs LLC
Email: privacy@consentcraft.ai
9. CCPA Service Provider Terms
9.1 — Service Provider Designation
For purposes of the California Consumer Privacy Act (Cal. Civ. Code §1798.100 et seq., as amended by the California Privacy Rights Act) ("CCPA"), Processor is a Service Provider as defined in Cal. Civ. Code §1798.140(ag). Processor processes personal information on behalf of the Controller exclusively for the Business Purpose of providing the ConsentCraft Service as described in this DPA and the Terms of Service.
9.2 — Service Provider Obligations
Processor certifies that it understands and shall comply with the applicable restrictions of a Service Provider under the CCPA. Specifically, Processor:
- shall not Sell or Share (as those terms are defined in the CCPA) personal information received from Controller;
- shall not retain, use, or disclose personal information received from Controller for any purpose other than the Business Purpose of providing the Service specified in this DPA and the Terms of Service, including retaining, using, or disclosing personal information for a commercial purpose other than providing the Service;
- shall not retain, use, or disclose personal information received from Controller outside the direct business relationship between Processor and Controller;
- shall not combine personal information received from Controller with personal information received from or collected in connection with other Controllers' data, other services, or Processor's own interaction with consumers, except as permitted by applicable CCPA regulations;
- shall assist Controller in meeting its obligations to respond to consumer requests pursuant to Cal. Civ. Code §§1798.100–1798.125. Where Processor receives a consumer request that it reasonably believes relates to personal information processed on Controller's behalf, Processor shall forward the request to the relevant Controller within 72 hours without responding to the consumer directly.
9.3 — Certification
Processor certifies that it has read and understands the restrictions in Section 9.2 and will comply with them for the duration of this DPA. Controller acknowledges that Processor's compliance with these restrictions is the basis on which the disclosure of personal information from Controller to Processor does not constitute a "sale" or "sharing" under the CCPA.
10. SCC Annexes
The following Annexes supplement the EU SCCs incorporated in Section 6.1, as required by Commission Implementing Decision (EU) 2021/914.
Annex I.A — List of Parties
| Data Exporter (Controller) | Data Importer (Processor) | |
|---|---|---|
| Name | The Merchant (Shopify store owner) who installs ConsentCraft, as identified by their Shopify account and store domain | Lucent Labs LLC |
| Address | As registered in the Merchant's Shopify account | California, United States |
| Contact | As registered in the Merchant's Shopify account | privacy@consentcraft.ai |
| Role | Data controller | Data processor |
| Signature / Date | Installation of ConsentCraft constitutes the Merchant's signature and agreement to this DPA and the incorporated EU SCCs. The date of installation is the effective date. | |
Annex I.B — Description of Transfer
| Categories of data subjects | Store Visitors located in the EEA who interact with the ConsentCraft consent banner on the Controller's Shopify storefront |
|---|---|
| Categories of personal data | Consent decision (category-level: analytics, marketing, social, functional), consent timestamp, consent version identifier, partial IP address (last octet masked — e.g., 192.168.1.xxx), browser type, screen width. No special categories of personal data (GDPR Article 9) are processed. |
| Sensitive data | None |
| Frequency of transfer | Continuous — each consent interaction generates a transfer |
| Nature of processing | Recording, storing, retrieving, and transmitting consent decisions and related audit metadata |
| Purpose of transfer | To enable the Controller to maintain tamper-evident consent audit records in fulfilment of its obligations under GDPR Article 7(1) and Recital 42 |
| Retention period | 13 months rolling — records are automatically purged after 13 months. This period supports the Controller's compliance obligations and does not exceed the minimum necessary retention period. |
| Transfers to subprocessors | Yes — to the subprocessors listed in Section 5 and Annex III, under equivalent data protection obligations |
Annex I.C — Competent Supervisory Authority
Pursuant to Clause 13(a) third bullet of the EU SCCs, because the Data Importer (Lucent Labs LLC) has no establishment in the EU and has not designated an Article 27 GDPR representative as of the effective date of this DPA, the competent supervisory authority is:
Irish Data Protection Commission (DPC)
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
www.dataprotection.ie
Upon appointment of a formal Article 27 GDPR representative, this Annex I.C will be updated to designate the supervisory authority of the member state in which the representative is established, per Clause 13(a) second bullet.
Annex II — Technical and Organizational Measures (TOMs)
The following technical and organizational measures are implemented by Processor pursuant to GDPR Article 32 and EU SCC Clause 8.6:
| Category | Measure |
|---|---|
| Encryption in transit | TLS 1.2+ for all Personal Data in transit |
| Encryption at rest | AES-256 for Personal Data at rest (AWS DynamoDB, S3) |
| Access control | Role-based access control; least-privilege principle; MFA required for infrastructure access; no unauthorized personnel access to Personal Data |
| Multi-tenant isolation | All Personal Data stored under shop-scoped partition keys; no cross-tenant data access is architecturally possible |
| Data minimization | IP address last octet masked before storage; no full IP stored; consent records identified by session token, not name or email |
| Pseudonymization | Consent records use a session token as identifier; no direct linkage to name, email, or other identifying data |
| Availability | AWS multi-AZ architecture (us-west-2); automated failover; regular backups |
| Incident response | Documented incident detection, containment, and breach notification procedures; 48-hour notification for EEA/UK data (see Section 4) |
| Subprocessor oversight | Written contracts with all subprocessors imposing equivalent data protection obligations; due diligence on engagement |
| Security reviews | Regular security reviews; annual third-party vulnerability assessment; automated security gate in CI/CD pipeline |
| Personnel | Authorized personnel receive data protection orientation on appointment; confidentiality obligations in employment or contractor agreements |
| Deletion | Automated 13-month rolling purge of consent records; deletion within 30 days of termination request (see Section 3.7) |
Annex III — List of Authorized Subprocessors
Pursuant to EU SCC Clause 9(a), the following subprocessors are authorized as of the effective date of this DPA:
| Subprocessor | Role | Location | Transfer Safeguard |
|---|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure (Lambda, DynamoDB, S3, CloudFront) | United States | EU SCCs + AWS Customer Agreement DPA |
| Amazon Simple Email Service | Transactional email delivery | United States | EU SCCs + AWS Customer Agreement DPA |
| Shopify Inc. | App platform (billing, OAuth, app distribution) | Canada / United States | EU SCCs + Shopify DPA |
| Bunny Way d.o.o. (Bunny CDN) | Static asset delivery (JavaScript, CSS bundles) | EU (Slovenia + global edge) | EEA-to-EEA transfer — Bunny CDN DPA |
Controller will be notified at least 30 days in advance of any changes to this list per Section 3.4.
11. UK International Data Transfer Addendum
This Section constitutes the Tables required by the UK International Data Transfer Addendum (version B1.0) issued by the UK Information Commissioner's Office (ICO) under S119A(1) Data Protection Act 2018 (in force 21 March 2022). The UK Addendum amends and supplements the EU SCCs incorporated in Section 6.1 for transfers of Personal Data from the United Kingdom to the United States.
Table 1: Parties
| Exporter (Controller) | Importer (Processor) | |
|---|---|---|
| Full legal name | The Merchant, as identified by their Shopify account and store domain | Lucent Labs LLC |
| Trading name | As registered in Shopify account | ConsentCraft |
| Registered address | As registered in Shopify account | California, United States |
| Official registration number | As registered in Shopify account | EIN 42-2711201 |
| Key contact | As registered in Shopify account | privacy@consentcraft.ai |
| Signature and date | Installation of ConsentCraft constitutes signature. The date of installation is the effective date of this Addendum. | |
Table 2: Selected SCCs, Modules and Selected Clauses
| Addendum EU SCCs | The Standard Contractual Clauses incorporated in Section 6.1 of this DPA — Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor) |
|---|---|
| Selected module | Module 2: Transfer Controller to Processor |
| Clause 7 (Docking clause) | Not used |
| Clause 11 (Redress) | Optional language not included |
| Clause 9(a) (Subprocessors) | General authorization. Prior notice period for new Subprocessors: 30 calendar days. |
| Clause 17 (Governing law) | England and Wales (as amended by the UK Addendum — see Section 8.3) |
| Clause 18(b) (Jurisdiction) | England and Wales |
Table 3: Appendix Information
The "Appendix Information" required by the UK Addendum is set out in Section 10 of this DPA:
- Annex I.A (List of parties) — Section 10, Annex I.A
- Annex I.B (Description of transfer) — Section 10, Annex I.B, and Section 2
- Annex II (Technical and organizational measures) — Section 10, Annex II
- Annex III (Authorized subprocessors) — Section 10, Annex III, and Section 5
Table 4: Ending the Addendum When the Approved Addendum Changes
| Which Party may end this Addendum (Section 19)? | Neither party |
|---|
If the Information Commissioner issues a revised Approved Addendum under Section 18 of the UK Addendum, neither party may end this Addendum solely because of that change. The parties will negotiate in good faith to incorporate any changes required to maintain compliance with the revised Approved Addendum.