Data processing agreement

This is an English translation provided for convenience. The French version (Accord de sous-traitance des données) is the legally binding version: in the event of any discrepancy or difference in interpretation, the French version prevails.

Schedule to the terms of use and sale, version of 25 September 2026. It applies as soon as the terms are accepted and constitutes the contract required by article 28(3) of Regulation (EU) 2016/679 (GDPR).

1. Parties and roles

The customer, as publisher of the website on which it installs the banner, is the controller for the collection of its visitors’ consent and the retention of the proof of that consent: it is for the customer to demonstrate that consent was given (article 7(1) GDPR). KIPDEV SAS (a French simplified joint-stock company, SIREN 884 120 890, 4 rue des Frênes, 33700 Mérignac, France) is its processor: it processes this data on the customer’s behalf, in order to operate Orbe.

Where the customer uses Orbe for its own clients’ websites (agency), the customer itself is their processor and KIPDEV SAS is its sub-processor. The customer warrants that it has obtained its clients’ authorisation to use KIPDEV SAS and passes this agreement on to them.

2. Description of the processing

Scanning a website’s public pages does not collect any visitor data.

3. Customer instructions

KIPDEV SAS processes the data only on the customer’s documented instructions, including with regard to transfers outside the European Union: these instructions are the terms of use and sale, this agreement and the settings chosen in the customer area. If KIPDEV SAS is required by Union or Member State law to carry out other processing, it informs the customer beforehand, unless that law prohibits it. If an instruction appears to it to infringe the GDPR or other data protection rules, it informs the customer immediately.

4. Confidentiality

Persons authorised to process the data at KIPDEV SAS are bound by confidentiality. They access a customer’s log only to provide the service, resolve an incident or respond to a request from that customer.

5. Security (article 32 GDPR)

6. Sub-processors

The customer gives general authorisation to use the following sub-processors for visitor data:

ProviderRegistered officeUsePlace of processing
Hostinger International LtdCyprus (61 Lordou Vironos Street, 6023 Larnaca)Hosting of the service, the script, the database and the visitors’ consent log.France (server in Paris)

Visitor data is therefore not transferred outside the European Union. KIPDEV SAS contractually imposes on its sub-processors data protection obligations equivalent to those of this agreement, and remains fully liable to the customer for their performance (article 28(4) GDPR).

The following providers work for KIPDEV SAS but receive no visitor data:

ProviderRegistered officeUse
Resend (Plus Five Five, Inc.)United StatesEmails sent to the customer (sign-in, Sentinel alerts). No visitor data.
StripeIreland and United StatesPayment of the customer’s subscription. No visitor data.
Cloudflare, Inc.United StatesDomain name and DNS of the service. Does not receive the consent log.

The following also receive data, but only a cryptographic hash (the root of the day’s log), which cannot be used to identify a visitor: the timestamping services (DigiCert, with FreeTSA as a fallback) and the public OpenTimestamps servers.

Any addition or replacement of a sub-processor is announced to the customer by email at least 30 days in advance; the customer may object by terminating free of charge before the announced date.

7. Data subject rights

If a visitor exercises their rights with KIPDEV SAS, the request is forwarded without delay to the customer, who responds to it. Visitors can change their choice at any time using the website’s “Manage cookies” button. KIPDEV SAS assists the customer, through appropriate technical measures and insofar as possible, in responding to requests: the identifier of the choice is stored in the visitor’s cookie and makes it possible to find their records in the export.

8. Assistance to the customer

KIPDEV SAS assists the customer, taking into account the nature of the processing and the information available to it, in complying with its obligations regarding security, notification of breaches, impact assessments and prior consultation (articles 32 to 36 GDPR).

9. Personal data breaches

KIPDEV SAS notifies the customer of any personal data breach of which it becomes aware, without undue delay and no later than 48 hours, so as to leave the customer time to notify the CNIL (the French supervisory authority) itself within 72 hours. The notification describes the nature of the breach, the data and persons concerned, the likely consequences and the measures taken or proposed.

10. End of the contract

Before the contract ends, the customer exports its log from its customer area (return of data). At the customer’s choice, and at its written request to contact@orbeconsent.com, KIPDEV SAS then deletes the data and its copies within 30 days, unless retention is required by law. As long as the account exists, the data remains stored and available for export.

11. Audits

KIPDEV SAS makes available to the customer the information needed to demonstrate compliance with this agreement and answers its written questions. An audit, including an inspection, may be carried out by the customer or by an auditor bound by confidentiality whom it appoints, with 30 days’ notice, at the customer’s expense, no more than once a year except in the event of a proven breach or a request from a supervisory authority.

Contact for any data-related question: contact@orbeconsent.com.