Data processing agreement
Schedule to the terms of use and sale, version of 25 September 2026. It applies as soon as the terms are accepted and constitutes the contract required by article 28(3) of Regulation (EU) 2016/679 (GDPR).
1. Parties and roles
The customer, as publisher of the website on which it installs the banner, is the controller for the collection of its visitors’ consent and the retention of the proof of that consent: it is for the customer to demonstrate that consent was given (article 7(1) GDPR). KIPDEV SAS (a French simplified joint-stock company, SIREN 884 120 890, 4 rue des Frênes, 33700 Mérignac, France) is its processor: it processes this data on the customer’s behalf, in order to operate Orbe.
Where the customer uses Orbe for its own clients’ websites (agency), the customer itself is their processor and KIPDEV SAS is its sub-processor. The customer warrants that it has obtained its clients’ authorisation to use KIPDEV SAS and passes this agreement on to them.
2. Description of the processing
- Subject matter and purpose: displaying the banner, applying the visitor’s choice (blocking trackers), recording that choice so that the customer can prove it, and presenting it to the customer.
- Nature: automated online processing, on KIPDEV SAS’s servers.
- Data subjects: visitors to the customer’s websites.
- Data: random identifier of the choice (also stored in a first-party cookie on the website, 6 months), choice per category, date, version and fingerprint of the text displayed, language, page address (without parameters), truncated HMAC fingerprint of the IP address, abbreviated browser and operating system (“Chrome 140 · macOS”). The IP address itself is used only in memory, for rate limiting, and is never stored. The fingerprint of the IP address remains pseudonymised, and therefore personal, data. No special categories of data within the meaning of article 9 GDPR are processed.
- Operations: collection, recording, hash chaining, sealing, storage, consultation by the customer, export, deletion.
- Duration: the term of the contract, then the time needed for return and deletion as provided in article 10. The log is not purged automatically: the customer sets the retention period for its records and can delete a website and its log at any time. For reference, the European Data Protection Board states that proof of consent should be kept for as long as the processing lasts, and then no longer than necessary to comply with a legal obligation or for the establishment, exercise or defence of legal claims (Guidelines 05/2020, § 107).
Scanning a website’s public pages does not collect any visitor data.
3. Customer instructions
KIPDEV SAS processes the data only on the customer’s documented instructions, including with regard to transfers outside the European Union: these instructions are the terms of use and sale, this agreement and the settings chosen in the customer area. If KIPDEV SAS is required by Union or Member State law to carry out other processing, it informs the customer beforehand, unless that law prohibits it. If an instruction appears to it to infringe the GDPR or other data protection rules, it informs the customer immediately.
4. Confidentiality
Persons authorised to process the data at KIPDEV SAS are bound by confidentiality. They access a customer’s log only to provide the service, resolve an incident or respond to a request from that customer.
5. Security (article 32 GDPR)
- Encrypted communications (HTTPS). Database not exposed to the internet.
- IP address replaced on receipt by a truncated HMAC fingerprint using a secret key.
- Log chained with SHA-256 hashes: any modification, deletion or insertion is detectable; in the plans that include it, daily sealing timestamped by a third-party service.
- Consent records accepted only from the website’s declared domain (origin check), rate-limited.
- Passwordless sign-in to the account, via a time-limited link; sessions in a signed cookie that scripts cannot access.
6. Sub-processors
The customer gives general authorisation to use the following sub-processors for visitor data:
| Provider | Registered office | Use | Place of processing |
|---|---|---|---|
| Hostinger International Ltd | Cyprus (61 Lordou Vironos Street, 6023 Larnaca) | Hosting of the service, the script, the database and the visitors’ consent log. | France (server in Paris) |
Visitor data is therefore not transferred outside the European Union. KIPDEV SAS contractually imposes on its sub-processors data protection obligations equivalent to those of this agreement, and remains fully liable to the customer for their performance (article 28(4) GDPR).
The following providers work for KIPDEV SAS but receive no visitor data:
| Provider | Registered office | Use |
|---|---|---|
| Resend (Plus Five Five, Inc.) | United States | Emails sent to the customer (sign-in, Sentinel alerts). No visitor data. |
| Stripe | Ireland and United States | Payment of the customer’s subscription. No visitor data. |
| Cloudflare, Inc. | United States | Domain name and DNS of the service. Does not receive the consent log. |
The following also receive data, but only a cryptographic hash (the root of the day’s log), which cannot be used to identify a visitor: the timestamping services (DigiCert, with FreeTSA as a fallback) and the public OpenTimestamps servers.
Any addition or replacement of a sub-processor is announced to the customer by email at least 30 days in advance; the customer may object by terminating free of charge before the announced date.
7. Data subject rights
If a visitor exercises their rights with KIPDEV SAS, the request is forwarded without delay to the customer, who responds to it. Visitors can change their choice at any time using the website’s “Manage cookies” button. KIPDEV SAS assists the customer, through appropriate technical measures and insofar as possible, in responding to requests: the identifier of the choice is stored in the visitor’s cookie and makes it possible to find their records in the export.
8. Assistance to the customer
KIPDEV SAS assists the customer, taking into account the nature of the processing and the information available to it, in complying with its obligations regarding security, notification of breaches, impact assessments and prior consultation (articles 32 to 36 GDPR).
9. Personal data breaches
KIPDEV SAS notifies the customer of any personal data breach of which it becomes aware, without undue delay and no later than 48 hours, so as to leave the customer time to notify the CNIL (the French supervisory authority) itself within 72 hours. The notification describes the nature of the breach, the data and persons concerned, the likely consequences and the measures taken or proposed.
10. End of the contract
Before the contract ends, the customer exports its log from its customer area (return of data). At the customer’s choice, and at its written request to contact@orbeconsent.com, KIPDEV SAS then deletes the data and its copies within 30 days, unless retention is required by law. As long as the account exists, the data remains stored and available for export.
11. Audits
KIPDEV SAS makes available to the customer the information needed to demonstrate compliance with this agreement and answers its written questions. An audit, including an inspection, may be carried out by the customer or by an auditor bound by confidentiality whom it appoints, with 30 days’ notice, at the customer’s expense, no more than once a year except in the event of a proven breach or a request from a supervisory authority.
Contact for any data-related question: contact@orbeconsent.com.