Data Processing Addendum
This Data Processing Addendum ("DPA") supplements the CookieGuard Terms of Service and governs the processing of personal data by CookieGuard on behalf of Customer.
Effective: May 19th, 2026
This DPA is entered into between the customer identified in the CookieGuard subscription account ("Customer") and AllCaps Technologies Inc., the operator of CookieGuard ("CookieGuard," "we," "us"). This DPA forms part of the CookieGuard Terms of Service available at https://cookieguard.co/terms (the "Agreement") and applies to the extent CookieGuard processes Personal Data on behalf of Customer in connection with the CookieGuard service (the "Service"). In the event of a conflict between this DPA and the Agreement, this DPA governs solely with respect to the processing of Personal Data.
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person that is processed by CookieGuard on behalf of Customer in connection with the Service, including consumer health data as defined under MHMDA and Nevada SB 370 where applicable.
"Controller," "Processor," "Data Subject," "Processing," and related terms have the meanings given to them under the GDPR or, where applicable, the equivalent meanings under U.S. state privacy laws (e.g., "Business" and "Service Provider" under the CCPA/CPRA; "Controller" and "Processor" under VCDPA, CPA, CTDPA, UCPA; "Regulated Entity" and "Processor" under MHMDA).
"Sub-processor" means any third party engaged by CookieGuard that processes Personal Data in the course of providing the Service.
2. Roles of the Parties
For the purposes of this DPA, Customer is the Controller (or Business, or Regulated Entity, as applicable) of Personal Data and CookieGuard is the Processor (or Service Provider). CookieGuard processes Personal Data only on documented instructions from Customer, including with regard to transfers, unless required to do otherwise by applicable law. The Agreement, this DPA, and Customer's configuration of the Service collectively constitute Customer's instructions.
3. Scope, Nature, and Purpose of Processing
Subject matter: CookieGuard processes Personal Data to display cookie consent banners, capture and store end-user consent decisions, enforce consent state on Customer's website, and provide Customer with audit logs of those consent decisions.
Duration: The term of the Agreement plus any retention period required by applicable law or specified in the Agreement.
Nature and purpose of processing: Collection, recording, organization, structuring, storage, retrieval, and transmission of consent-related data for the purpose of enabling Customer's compliance with privacy and consumer-health-data regulations applicable to Customer's website.
Categories of Data Subjects: Visitors to Customer's websites where the CookieGuard banner script is installed.
Categories of Personal Data: IP address (used for geo-detection at the country and U.S. state level and then discarded or stored in coarse form), region or country code, anonymous first-party cookie identifier, user-agent string, consent timestamp, the categories of cookies/tracking the data subject accepted or rejected, and (for Healthcare-tier Customers) whether the data subject's consent applies to MHMDA, Nevada SB 370, or the sensitive consent category. CookieGuard does not process the content of forms, quizzes, intake submissions, health data inferred from user inputs, or any other data that flows outside of the consent banner itself.
4. CookieGuard Obligations
CookieGuard will: (a) process Personal Data only on documented instructions from Customer; (b) ensure that personnel authorized to process Personal Data are bound by appropriate obligations of confidentiality; (c) implement and maintain appropriate technical and organizational security measures as described in Section 7; (d) make available to Customer such information as is reasonably necessary to demonstrate compliance with this DPA; (e) assist Customer, taking into account the nature of the processing, in responding to requests from Data Subjects exercising their rights under applicable law; and (f) at Customer's election, delete or return all Personal Data after the end of the provision of services, except where retention is required by applicable law.
CookieGuard will not (i) sell or share Personal Data (as those terms are defined under CCPA/CPRA or other applicable law); (ii) retain, use, or disclose Personal Data outside of the direct business relationship between CookieGuard and Customer; or (iii) combine Personal Data received from or on behalf of Customer with personal data received from any other source, except as expressly permitted by applicable law.
5. Customer Obligations
Customer represents, warrants, and undertakes that: (a) Customer has a lawful basis under applicable law to instruct CookieGuard to process Personal Data; (b) Customer has provided all required notices and obtained all required consents from Data Subjects; (c) Customer has independently determined the applicability of GDPR, CCPA/CPRA, MHMDA, Nevada SB 370, and any other privacy or consumer-health-data law to Customer's operations; (d) Customer is solely responsible for configuring the Service correctly (including, for Healthcare-tier Customers, enabling the applicable MHMDA and Nevada SB 370 toggles and the sensitive consent category for sites that require them); and (e) Customer's use of the Service does not violate the rights of any Data Subject or any applicable law.
6. Sub-processors
Customer authorizes CookieGuard to engage Sub-processors to assist in providing the Service. CookieGuard will (a) enter into a written agreement with each Sub-processor that imposes data protection obligations substantially equivalent to those in this DPA, and (b) remain liable for the acts and omissions of its Sub-processors with respect to the processing of Personal Data. The current list of Sub-processors includes:
- Supabase, Inc. — hosted PostgreSQL database for consent log storage and account data (United States)
- Vercel, Inc. — application hosting, edge geo-detection, and CDN (United States)
- Stripe, Inc. — subscription billing and payment processing (United States)
- Anthropic, PBC — limited internal tooling that does not access end-user Personal Data (United States)
CookieGuard will notify Customer of any intended addition or replacement of Sub-processors by updating this DPA at least thirty (30) days in advance, giving Customer the opportunity to object on reasonable grounds.
7. Security Measures
CookieGuard maintains the following technical and organizational measures to protect Personal Data: encryption in transit (TLS 1.2+) and at rest; access controls limiting Personal Data to authorized personnel on a need-to-know basis; logging and monitoring of administrative access; least-privilege service accounts; segregation of production from non-production environments; secure software development practices including dependency scanning; and incident response procedures. Specific measures may be updated from time to time provided that the overall level of protection is not reduced.
8. Personal Data Breach Notification
CookieGuard will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer's Personal Data. The notification will include, to the extent then known, a description of the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach.
9. International Data Transfers
CookieGuard is established in the United States, and Personal Data may be transferred to and processed in the United States by CookieGuard and its Sub-processors. Where required by applicable law for transfers from the EEA, United Kingdom, or Switzerland, the parties agree that the Standard Contractual Clauses adopted by the European Commission (Module Two: Controller to Processor) and the UK International Data Transfer Addendum, as applicable, are incorporated into this DPA by reference, with the following elections: (i) Clause 7 (docking clause) applies; (ii) Clause 9, Option 2 (general written authorization) applies with a notice period of thirty (30) days; (iii) Clause 11 (independent dispute resolution body) does not apply; (iv) Clause 17 governing law is the law of Ireland; and (v) Clause 18 forum is Ireland.
10. Audit Rights
On reasonable prior written request (no more than once per twelve-month period, except where required by a supervisory authority or following a Personal Data Breach), CookieGuard will make available to Customer such information and certifications as are reasonably necessary to demonstrate compliance with this DPA. Audits will be conducted during normal business hours, will not unreasonably interfere with CookieGuard's operations, and the auditor will be bound by appropriate confidentiality obligations. The audited party bears its own costs unless the audit reveals material non-compliance, in which case CookieGuard will bear the reasonable costs of the audit.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement, including any aggregate liability cap. This DPA does not create any independent cause of action that would not otherwise exist under the Agreement.
12. Term and Termination
This DPA takes effect on the date Customer first uses the Service after the Effective Date above (or on the date Customer executes a signed copy, if Customer has signed this DPA) and continues for the duration of the Agreement. Sections that by their nature should survive termination (including Sections 1, 4(f), 7, 8, 10, 11, and 13) will survive.
13. Governing Law and Order of Precedence
This DPA is governed by the laws specified in the Agreement, except to the extent that any applicable data protection law mandates otherwise (in which case such law applies only to the extent so mandated). The order of precedence is: (1) any provision of an applicable Standard Contractual Clause to the extent required by EU law; (2) this DPA; (3) the Agreement.
14. Executing this DPA
Customer may execute this DPA by countersignature and email to connect@allcaps.ai, or by accepting it electronically through any mechanism CookieGuard makes available for that purpose. For Customers on the Healthcare tier, execution is recommended. For all other Customers, this DPA is incorporated by reference into the Agreement and applies whether or not separately signed.
15. Contacting Us
For questions about this DPA, contact us at connect@allcaps.ai or by mail to AllCaps Technologies Inc, PO Box 1143 Frisco, TX, 75035.