This Data Processing Agreement (“DPA”) is entered into between iSense Ltd., doing business as Consentmo, VAT BG112660079, with registered address at 4 Prof. Georgi Bradistilov St., entrance A, 4th floor, Sofia, Bulgaria (“Consentmo”, “Processor”), and the merchant that installs or uses the Consentmo application (“Merchant”, “Controller”).

This DPA is incorporated into and forms an integral part of the Consentmo Terms of Service. It becomes binding upon the earlier of: (a) the Merchant's installation of the App; (b) the Merchant's acceptance of the Terms of Service; or (c) countersignature of this DPA by both parties.

‍

In case of conflict, this DPA prevails over the Terms of Service with respect to the processing of personal data, and the Standard Contractual Clauses referred to in Annex IV prevail over this DPA.

‍

1. Background and definitions

‍

1.1 Consentmo provides a privacy compliance application for Shopify merchants, including cookie consent management, tracker management, data subject request handling, web accessibility tools, EU withdrawal management, and related analytics and reporting (the "Services").

‍

1.2 In providing the Services, Consentmo processes personal data of the Merchant's store visitors and customers on the Merchant's behalf. For that processing, the Merchant is the controller and Consentmo is the processor within the meaning of Art. 4(7) and 4(8) of Regulation (EU) 2016/679 ("GDPR").

‍

1.3 "UK GDPR" means the GDPR as incorporated into the law of the United Kingdom; "FADP" means the Swiss Federal Act on Data Protection. Both apply as set out in Annex IV. Other capitalised terms have the meaning given in the Terms of Service.

‍

1.4 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are described in Annex I.

‍

2. Roles, instructions and Merchant obligations

‍

2.1 Roles. The Merchant acts as controller and Consentmo acts as processor with respect to the personal data described in Annex I. With respect to the Merchant's own account, billing and contact data, Consentmo acts as an independent controller as described in the Consentmo Privacy Policy.

‍

2.2 Merchant obligations (Controller). The Merchant warrants and undertakes that: (a) it has established a valid legal basis under Art. 6 GDPR for the processing of personal data through the Services; (b) its privacy notices accurately describe the processing performed through the Services; (c) its instructions to Consentmo comply with applicable data protection law; (d) it shall not submit, or use the Services to collect, special categories of personal data (Art. 9 GDPR) or personal data relating to criminal convictions and offences (Art. 10 GDPR), unless expressly agreed with Consentmo in writing; and (e) it will configure the Services (including banner behaviour, retention settings and regional rules) in accordance with the laws applicable to its stores. The Merchant remains responsible for its obligations as controller under Chapters III and IV GDPR.

‍

2.3 Processing on documented instructions. (a) Consentmo shall process personal data only on the Merchant's documented instructions, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which Consentmo is subject; in such a case, Consentmo shall inform the Merchant of that legal requirement before processing, unless that law prohibits this on important grounds of public interest. (b) The Merchant's instructions consist of: this DPA, the Terms of Service, and the configuration settings selected by the Merchant within the App. Additional instructions require written agreement between the parties. (c) Consentmo shall immediately inform the Merchant if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions. (d) Consentmo may create and use aggregated and anonymised data that does not identify any natural person and does not constitute personal data, including for the purpose of improving and developing the Services. Such data is not subject to this DPA.

‍

2.4 Duration. This DPA applies for as long as Consentmo processes personal data on the Merchant's behalf, and survives termination of the Terms of Service until all such personal data has been deleted or returned in accordance with Section 3.

‍

3. Retention, return and deletion

‍

3.1 Consent records, data subject request records, and EU withdrawal request records are retained for twelve (12) months, unless a different retention period is agreed with the Merchant in writing or made available to the Merchant as a setting in the App. The Merchant may export consent records from the App at any time.

‍

3.2 Upon termination of the Services, including uninstallation of the App, Consentmo shall, at the Merchant’s choice, delete or return personal data processed on the Merchant’s behalf in accordance with its standard deletion procedures, and in any event within one hundred and twenty (120) days, unless Union or Member State law requires storage of the personal data. The Merchant may export available personal data from the App before termination. Upon written request received before deletion, Consentmo will provide a copy of available personal data in a commonly used, machine-readable format. If the Merchant does not request return before deletion, Consentmo may delete the personal data in accordance with this Section. This deletion period does not apply to personal data archived in routine backup systems, provided that Consentmo continues to protect such data in accordance with this DPA and deletes it in the ordinary course of backup rotation.

‍

3.3 Consentmo may retain documentation demonstrating orderly and compliant processing beyond termination for accountability purposes.

‍

4. Confidentiality

‍

Consentmo shall ensure that all persons authorised to process personal data under this DPA have committed themselves to confidentiality by written agreement or are under an appropriate statutory obligation of confidentiality, and that they process the personal data only as necessary for the provision of the Services. Access to personal data is limited to personnel who require it for their role.

‍

5. Security of processing

‍

5.1 Consentmo shall implement and maintain the technical and organisational measures described in Annex II, ensuring a level of security appropriate to the risk pursuant to Art. 32 GDPR, including protection against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

5.2 Consentmo maintains an ISO/IEC 27001-certified information security management system within the scope described in its current certificate. Current certification details and other assurance materials may be made available through Consentmo’s Trust Center or upon request, subject to confidentiality and security restrictions. Consentmo may update Annex II from time to time, provided that the level of security is not materially reduced.

‍

5.3 Taking into account the nature of the processing and the information available to it, Consentmo shall assist the Merchant in ensuring compliance with the Merchant's obligations under Art. 32 to 36 GDPR.

‍

6. Sub-processors

‍

6.1 The Merchant grants Consentmo general written authorisation to engage the sub-processors listed at consentmo.com/legal/sub-processors (Annex III).

‍

6.2 Changes to sub-processors. Consentmo may add or replace sub-processors from time to time. Consentmo shall update the sub-processor list and, where the change involves a new or replacement sub-processor that will process personal data described in Annex I, provide at least thirty (30) days’ prior notice through the notification mechanism available on that page, unless shorter notice is required for security, continuity, legal, or urgent operational reasons.

‍

The Merchant may object to the change within that notice period only on reasonable data-protection grounds. The objection must describe the specific data protection concern. Consentmo will use reasonable efforts to address the objection. If Consentmo cannot reasonably address the objection, the Merchant may terminate only the affected Services as its sole remedy.

‍

6.3 Consentmo shall impose on each sub-processor, by way of a written contract, data protection obligations that are substantially the same as those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. Consentmo remains fully liable to the Merchant for the performance of each sub-processor's obligations.

‍

7. Assistance to the Merchant

‍

7.1 Data subject rights. Taking into account the nature of the processing, Consentmo shall assist the Merchant by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Merchant's obligation to respond to requests for exercising data subject rights under Chapter III GDPR (Art. 12–22). Where the Services provide self-service functionality for this purpose, including consent withdrawal, consent record export, and data subject request handling via the Privacy Center - that functionality constitutes such assistance. For requests not covered by that functionality, Consentmo shall provide reasonable assistance upon written request to privacy@consentmo.com.

‍

7.2 If Consentmo receives a request from a data subject directly, it shall forward the request to the Merchant without undue delay and shall not respond on its own behalf, except to direct the data subject to the Merchant.

‍

7.3 Impact assessments and consultations. Consentmo shall provide reasonable assistance to the Merchant with data protection impact assessments and prior consultations with supervisory authorities (Art. 35–36 GDPR), insofar as they relate to the Services.

‍

8. Personal data breach

‍

8.1 Consentmo shall notify the Merchant without undue delay after becoming aware of a personal data breach affecting personal data processed on the Merchant's behalf.

‍

8.2 The notification shall, to the extent such information is available, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Where it is not possible to provide all information at the same time, information may be provided in phases without undue further delay.

‍

8.3 Consentmo shall cooperate with the Merchant and take reasonable steps to mitigate the effects of the breach. Notification under this Section does not constitute an acknowledgement of fault or liability by Consentmo.

‍

9. Audit

‍

9.1 Consentmo shall make available to the Merchant all information reasonably necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR, including, upon written request to privacy@consentmo.com: this DPA and its annexes, current security certifications, and summaries of independent security assessments or penetration tests, where available and subject to confidentiality, redaction, and security restrictions.

‍

9.2 Where the information provided under Section 9.1 is not sufficient to demonstrate compliance, Consentmo shall allow for and contribute to audits, including inspections, conducted by the Merchant or an auditor mandated by the Merchant, subject to the following conditions: (a) at least thirty (30) days' prior written notice; (b) no more than once in any twelve (12) month period, unless required by a competent supervisory authority or following a personal data breach; (c) reasonable confidentiality undertakings by the Merchant and its auditor; and (d) no access to data of other Consentmo customers.

‍

9.3 The costs of audits under Section 9.2 exceeding one (1) business day are borne by the Merchant at Consentmo’s reasonable professional-services rates notified to the Merchant in advance, unless the audit reveals a material breach of this DPA by Consentmo.

‍

10. International data transfers

‍

10.1 Data residency. Personal data processed on the Merchant's behalf is stored in the European Economic Area (data centre location: Amsterdam, the Netherlands).

‍

10.2 Transfers to sub-processors. Where a sub-processor processes personal data outside the European Economic Area, the transfer is protected by an adequacy decision of the European Commission, including, for U.S. sub-processors, certification under the EU-U.S. Data Privacy Framework where applicable, or by the standard contractual clauses adopted under Commission Implementing Decision (EU) 2021/914 (Module 3, processor-to-processor), in each case as indicated for the relevant sub-processor at

consentmo.com/legal/sub-processors.

‍

10.3 Transfers to the Merchant. Where the Merchant is established in a third country that is not covered by an adequacy decision of the European Commission, the Merchant’s access to and receipt of personal data through the Services is treated by the parties as a transfer of personal data for the purposes of Chapter V GDPR. For such transfers, the parties hereby conclude the standard contractual clauses adopted under Commission Implementing Decision (EU) 2021/914, Module 4 (processor-to-controller), as set out in Annex IV, which forms part of this DPA where this Section 10.3 applies.

‍

10.4 For personal data subject to the UK GDPR, the UK Addendum applies; for personal data subject to the Swiss FADP, the Swiss amendments apply, each as set out in Annex IV.

‍

11. Liability

‍

11.1 Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service or other written agreement between the parties, except where liability cannot be limited or excluded under applicable law.

‍

11.2 Consentmo remains liable to the Merchant for the acts and omissions of its sub-processors to the same extent Consentmo would be liable if performing the relevant processing itself, subject to the limitations and exclusions of liability set out in the Terms of Service or other written agreement between the parties.

‍

11.3 Nothing in this DPA limits either party’s liability towards data subjects under Art. 82 GDPR or any liability that cannot be limited or excluded under applicable law.

‍

12. Final provisions

‍

12.1 In case of conflict: the Standard Contractual Clauses referred to in Annex IV prevail over this DPA; this DPA prevails over the Terms of Service, in each case with respect to the processing of personal data.

‍

12.2 Consentmo may update this DPA to reflect changes in applicable law, in the Services, or in its sub-processors, by publishing the updated version with a new version number and notifying merchants via the App and/or by email. Changes that materially reduce the level of protection for personal data take effect no earlier than thirty (30) days after such notice.

‍

12.3 This DPA is governed by the laws of Bulgaria, without prejudice to Clause 17 of the Standard Contractual Clauses in Annex IV. If any provision of this DPA is held invalid, the remaining provisions remain in full force.

‍

12.4 This DPA remains in force until all personal data processed on the Merchant's behalf has been deleted or returned in accordance with Section 3.

‍

Annex I - Description of processing

‍

A. Categories of data subjects

‍
Visitors and customers of the Merchant’s Shopify storefront(s), individuals submitting data subject requests or EU withdrawal requests, and other individuals whose personal data is submitted through the Services by or on behalf of the Merchant.

‍

B. Categories of personal data

‍

Consent management: consent identifiers, consent choices and preferences, timestamps, banner or policy version, store domain, technical browser/device information, approximate region or country, language, and IP address or derived IP-based information where processed.

‍

Privacy Center / data subject requests: name, email address, request type, request content, request status, order identifiers where provided, and related correspondence.

EU withdrawal requests: name, email address, order number, order-related information needed to process the request, withdrawal status, and related correspondence.

Analytics and reporting: event-level compliance reporting data related to consent interactions, request handling, regions, devices, pages, and store configuration, where such data relates to an identifiable individual. Aggregated and anonymised reporting data is not personal data and is not subject to this DPA, as described in Section 2.3(d).

Other data: any additional personal data submitted by or on behalf of the Merchant through the Services.

‍

C. Special categories of data

‍
Consentmo does not intentionally process special categories of personal data or personal data relating to criminal convictions and offences as part of the Services. The Merchant shall not use the Services to collect such data unless expressly agreed with Consentmo in writing.

‍

D. Nature and purpose of processing

‍
Collection, recording, organisation, storage, retrieval, disclosure to the Merchant, export, and erasure of personal data for the purpose of providing consent management, privacy request handling, EU withdrawal handling, compliance reporting, and related Shopify privacy compliance functionality.

‍

E. Frequency and duration

‍
Processing is continuous for the duration of the Merchant’s use of the Services. Retention is as set out in Section 3 of the DPA.

‍

Annex II - Technical and organisational measures

‍

The following technical and organisational measures are implemented pursuant to Article 32 GDPR and Section 5 of the DPA. Consentmo may update these measures from time to time, provided that the overall level of protection for personal data is not materially reduced.

‍

1. Access control and confidentiality

‍

Consentmo maintains role-based access controls, least-privilege access provisioning, and multi-factor authentication for personnel systems used to access production systems or personal data. Access to personal data is limited to personnel who require it for their role. Personnel with access to personal data are bound by confidentiality obligations and receive security and data protection training.

‍

2. Encryption and data protection

‍

Consentmo uses encryption in transit, including TLS 1.2 or higher, for personal data transmitted through the Services, and encryption at rest for personal data stored in production systems. Where applicable, Consentmo applies data minimisation, pseudonymisation, or similar measures to reduce processing risk.

‍

3. System integrity and change management

‍

Consentmo maintains procedures designed to protect the integrity of its systems, including logging and monitoring of relevant production access, controlled deployment processes, code review, and change management practices.

‍

4. Availability, backup and recovery

‍

Consentmo uses hosting and infrastructure providers designed to support availability and resilience of the Services. Consentmo maintains backup, restore, and recovery procedures designed to protect against accidental loss, destruction, or unavailability of personal data.

‍

5. Vulnerability and security testing

‍

Consentmo maintains vulnerability management practices, including dependency monitoring, security review of relevant changes, and independent security testing where available. Security issues may be reported through Consentmo’s responsible disclosure process or security contact published at consentmo.com/security.

‍

6. Vendor and subprocessor management

‍

Consentmo performs reasonable due diligence on subprocessors and enters into written agreements requiring subprocessors to protect personal data in accordance with Article 28(4) GDPR and this DPA.

‍

7. Incident management

‍

Consentmo maintains an incident-response process designed to identify, investigate, mitigate, and notify relevant parties of personal data breaches in accordance with Section 8 of the DPA.

‍

8. Assurance materials

‍

Consentmo maintains an ISO/IEC 27001-certified information security management system within the scope described in its current certificate. Current certification details and other assurance materials may be made available through Consentmo’s Trust Center or upon request, subject to confidentiality, redaction, and security restrictions.

‍

Annex III - Sub-processors

‍

The current list of Consentmo's sub-processors, including for each sub-processor the legal entity, country, function, categories of personal data processed, location of processing and applicable transfer mechanism, is published at consentmo.com/legal/sub-processors and forms an integral part of this DPA. Changes to the list are governed by Section 6 of the DPA.

‍

Annex IV - International transfer mechanisms

‍

A. EU Standard Contractual Clauses - Module 4 (processor-to-controller)

‍
Where Section 10.3 of the DPA applies, the parties conclude the standard contractual clauses adopted under Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (the "Clauses"), Module 4, which are incorporated into this DPA with the following selections and completions:

  • Clause 7 (docking clause): included. Affiliated entities of the Merchant operating storefronts using the Services may accede to the Clauses in accordance with Clause 7.
  • Clause 17 (governing law): the Clauses are governed by the law of Bulgaria.
  • Clause 18 (choice of forum and jurisdiction): the courts of Sofia, Bulgaria.
  • Annex I.A (list of parties): data exporter, Consentmo, acting as processor, as identified in the preamble of this DPA; data importer, the Merchant, acting as controller, as identified in the Merchant's Consentmo account and Shopify store details.
  • Annex I.B (description of transfer): as set out in Annex I of this DPA.
  • Annex II (technical and organisational measures): as set out in Annex II of this DPA.

A completed, signature-ready version of the Clauses reflecting the above selections is available at [SCC PDF link] and constitutes the operative instrument for the transfer; it forms part of this DPA where Section 10.3 applies.

‍

B. UK transfers

‍
Where the UK GDPR applies to transferred personal data, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office, in the version in force at the time of transfer (the "UK Addendum"), is incorporated into this DPA. The UK Addendum's Tables are completed by reference to Part A of this Annex and to Annexes I and II of this DPA. For the purposes of Table 4, neither party may end the UK Addendum as set out in its Section 19; to the extent the ICO issues a revised Approved Addendum under its Section 18, the parties shall work in good faith to revise this DPA accordingly.

‍

C. Swiss transfers

‍
Where the Swiss FADP applies to transferred personal data, the Clauses apply with the following amendments: references to the GDPR are understood as references to the FADP insofar as the transfer is subject to the FADP; the Swiss Federal Data Protection and Information Commissioner (FDPIC) is competent as supervisory authority insofar as the transfer is subject to the FADP; and references to "Member State" are interpreted so as not to exclude data subjects in Switzerland from enforcing their rights in their place of habitual residence in Switzerland.

‍

D. Order of precedence

‍
In case of conflict, the Clauses (as amended for UK and Swiss transfers where applicable) prevail over this DPA and over the Terms of Service.