Data Processing Agreement
Last updated: 11 October 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the customer who uses FrostBanner on its websites (“Controller”) and Artem Galyeyev, sole proprietor (empresário em nome individual), NIF 247017841, Maia, Portugal (“Processor”). It applies automatically when the Controller adds a website to FrostBanner and meets the requirements of Article 28 of the GDPR.
1. Subject, duration, nature and purpose
The Processor provides a cookie consent banner and stores a record of visitors' consent decisions so that the Controller can show and prove consent. Processing lasts as long as the Controller uses the Service, plus the deletion period in section 9.
2. Data subjects and data
| Data subjects | Visitors of the Controller's websites |
|---|---|
| Personal data | Random consent ID; consent choices and action; banner version; country (derived from the request); page address without query parameters; date and time; keyed hashes of the IP address and of the browser string (the IP address is not stored) |
| Special categories | None |
| Retention | 12 months from the decision, then automatic deletion |
3. Instructions
The Processor processes personal data only on the Controller's documented instructions, which are these Terms, this DPA and the settings the Controller chooses in the dashboard. If the Processor believes an instruction breaks data protection law, it will inform the Controller.
4. Confidentiality
Anyone authorised to process the data is bound by confidentiality.
5. Security measures (Art. 32)
- Encryption in transit (HTTPS/TLS) for all requests.
- IP addresses are never stored; only a keyed hash with a secret key and a monthly salt that is deleted after the month ends.
- Access to consent logs is restricted to the Controller's account; dashboard sessions use HttpOnly, Secure cookies and same-origin checks.
- Consent records are accepted only from the Controller's registered domain, and requests are rate-limited.
- Automatic deletion of records after 12 months; daily clean-up of expired data.
- Infrastructure provided by sub-processors with recognised security certifications.
6. Sub-processors
The Controller gives general authorisation to use the following sub-processors:
| Sub-processor | Purpose |
|---|---|
| Cloudflare, Inc. | Hosting, database, content delivery |
The Processor will announce new or replaced sub-processors on this page and by email at least 30 days in advance. The Controller may object on reasonable grounds; if no solution is found, the Controller may terminate the affected service. The Processor imposes the same data protection obligations on its sub-processors and remains responsible for them.
7. International transfers
Where data is transferred outside the EEA, it is protected by an adequacy decision of the European Commission (including the EU–US Data Privacy Framework where applicable) or by the Standard Contractual Clauses.
8. Assistance
Taking into account the nature of the processing, the Processor helps the Controller to answer data subject requests (for example by searching and exporting records by consent ID), and to carry out data protection impact assessments where needed.
9. Personal data breaches
The Processor will notify the Controller without undue delay, and in any case within 48 hours after becoming aware of a personal data breach affecting the Controller's data, with the information available at that time.
10. Deletion and return
The Controller can export its consent log (CSV on the Pro plan) at any time. When the Controller deletes a website or closes its account, the related data is deleted immediately from the active database and from backups within 30 days, unless law requires longer storage.
11. Audits
The Processor makes available the information necessary to demonstrate compliance with this DPA and answers reasonable written questions. On-site audits may be agreed in writing, at the Controller's cost and with reasonable notice.
12. Liability and precedence
Liability follows the Terms of Service. In case of conflict between this DPA and the Terms regarding personal data, this DPA prevails.
13. Contact
Artem Galyeyev, sole proprietor (empresário em nome individual), NIF 247017841, Maia, Portugal. Email: support@frostbanner.com.