This Data Processing Agreement (“DPA”) is entered into by and between:
This DPA forms an integral part of the Service agreement between Consentik and the Client (the “Agreement”) and governs the processing of personal data by Consentik on behalf of the Client in accordance with Article 28 of the General Data Protection Regulation (GDPR) and other Applicable Data Protection Law.
By installing an Consentik application from the Shopify App Store, You accept this DPA which forms part of Your agreement with Consentik for the provision of the Services (“Services”).
1.1 GDPR Definitions. Terms defined in Regulation (EU) 2016/679 (“GDPR”) have the same meaning in this DPA, including but not limited to: “Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, “Personal Data Breach”, “Supervisory Authority”.
1.2 Additional Definitions.
2.1 Appointment as Processor. The Controller appoints Consentik as a Processor to process Personal Data on the Controller’s behalf in connection with the Services. This appointment is made in accordance with Article 28(1) GDPR.
2.2 Authorization to Process. Consentik is authorized to process Personal Data only:
This fulfills the requirements of Article 28(3)(a) GDPR.
3.1 Documented Instructions. Consentik shall process Personal Data only on documented instructions from the Controller, which include:
Note: The Controller is responsible for configuring privacy and consent settings appropriately before collecting End User data. Consentik processes data according to these configured settings. This fulfills the requirements of Article 28(3)(a) GDPR.
3.2 Notification. Consentik will notify Controllers of significant Service issues that may impact data collection. However, brief interruptions or minor technical issues may be resolved without notification if they do not materially impact the Service. If Consentik:
Consentik shall:
Service Limitations: The Controller acknowledges that: technical issues may occasionally affect data collection and processing; some data loss may occur during Service interruptions or technical issues; Consentik will use commercially reasonable efforts to minimize any data loss; and real-time data collection depends on multiple factors including third-party platforms and browser technologies.
3.3 Controller Obligations. The Controller shall:
4.1 Subject Matter. The subject matter of the processing is the provision of the Services through the Consentik applications, which operate on the Shopify platform.
4.2 Purpose of Processing. Personal Data shall be processed exclusively for the following purposes:
This fulfills the requirements of Article 28(3) GDPR.
4.3 Nature of Processing. Processing operations may include, depending on the applicable Consentik application:
4.4 Duration of Processing. Processing shall continue for the duration of the Controller’s active Consentik subscription. Data is deleted or returned upon termination as per Section 10 of this DPA. This information is required by Article 28(3) GDPR.
5.1 Categories of Data Subjects.
This information is required by Article 28(3) GDPR.
5.2 Categories of Personal Data. The specific categories depend on the Consentik application used and the Controller’s configuration, and may include:
From Store Visitors (End Users):
From Clients (Merchants):
This fulfills the requirements of Article 28(3) GDPR.
5.3 Special Categories of Data. No special categories of data under Article 9 GDPR are intentionally collected or processed.
6.1 Technical and Organizational Measures. Consentik shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
Technical Measures Currently Implemented:
Note: The Cloud Provider provides built-in redundancy and data durability, and Consentik maintains backup and recovery procedures for personal data, including encrypted backups and documented restoration processes.
Organizational Measures:
This fulfills the requirements of Article 28(3)(c) and Article 32 GDPR.
6.2 Security Updates. Consentik shall regularly review and update security measures to maintain appropriate protection levels.
6.3 Data Storage. Consentik may store certain data in the user’s browser, including existing or custom cookie values, URL parameters, and other information provided by the user, using browser-based technologies such as Cookies, Local Storage, or Session Storage. These processes are essential for maintaining data integrity, supporting necessary backend operations, and delivering core, additional, and enhanced functionalities.
7.1 Personnel Confidentiality. Consentik ensures that:
This fulfills the requirements of Article 28(3)(b) GDPR.
7.2 Ongoing Obligations. Confidentiality obligations survive termination of employment or engagement.
8.1 General Authorization. The Controller provides general written authorization for Consentik to engage Subprocessors, subject to the requirements in this section.
8.2 Current Subprocessors. The Controller acknowledges that Consentik engages multiple Sub-processors to provide the Services, including but not limited to our Cloud Provider as our primary infrastructure provider for cloud hosting and data storage. The complete and current list of all Sub-processors, including their specific processing activities and locations, is maintained by Omegatheme and made available to the Controller upon request and in accordance with Section 8.3.
8.3 Adding or Replacing Subprocessors.
This fulfills the requirements of Article 28(2) GDPR.
8.4 Right to Object.
This fulfills the requirements of Article 28(2) GDPR.
8.5 Subprocessor Obligations. Consentik shall:
This fulfills the requirements of Article 28(4) GDPR.
9.1 Data Location. Personal Data is processed and stored on infrastructure operated by Consentik’s Sub-processors, primarily on servers hosted with our Cloud Provider (Leaseweb Canada Inc in Montreal, Canada). Additional Sub-processors may process data in other locations as required to provide the Services.
9.2 Safeguards. Where Personal Data is processed in a country other than the Controller’s country of origin, Consentik protects the data through:
9.3 Frequency and Volume. Processing and any cross-border data flows occur continuously during Service provision as end-user interactions are tracked and processed.
9.4 Standard Contractual Clauses (SCCs). Where the provision of the Services involves a transfer of Personal Data from the European Economic Area (EEA) to a country that has not been recognised as ensuring an adequate level of protection — including transfers to Consentik in Vietnam and to Consentik’s Sub-processors — then:
10.1 Deletion or Return Upon Termination. Upon termination or expiry of the Services, Consentik shall, at the choice of the Controller:
Omegatheme shall inform the Controller if it is legally obligated to retain any personal data after the termination of processing activities. This fulfills the requirements of Article 28(3)(g) GDPR.
10.2 Deletion on Request During Active Service. During the term of Service, the Controller may request the deletion of personal data at any time through the Services or by written instruction. Omegatheme shall delete such data without undue delay, unless retention is required by applicable law. If immediate deletion is not technically feasible, Consentik shall inform the Controller of the reason and the expected timeline. This fulfills the requirements of Article 28(3)(f) GDPR.
10.3 Deletion Timing and Method. Unless otherwise agreed in writing, Consentik shall delete personal data:
10.4 Data Export During Service. To exercise data access rights, Controllers can use the account or data settings available within the Services or contact [email protected].
10.5 Retention Periods. In accordance with the Terms of Service Section 11.4.2, Consentik retains Personal Data only for as long as necessary to fulfill the purposes for which it was collected and processed. Specifically:
Clients may request deletion of their data at any time via the Services. All data retention is subject to legal obligations, dispute resolution needs, enforcement of agreements, security requirements, or legitimate business interests (including backups, audit logs, and fraud prevention).
10.6 Shopify Compliance Webhooks. As a Shopify application, Consentik implements and honors Shopify’s mandatory privacy webhooks. Upon receiving the relevant webhook from Shopify, Consentik will:
These mechanisms operate in addition to, and are consistent with, the deletion and data subject rights provisions set out in Sections 10 and 11 of this DPA.
11.1 Assistance Obligation. Consentik shall provide reasonable assistance to the Controller in fulfilling its obligations to respond to data subject requests regarding:
This fulfills the requirements of Article 28(3)(e) GDPR.
11.2 Procedure for Requests.
11.3 Technical Assistance. Consentik provides tools and technical measures to enable the Controller to respond to data subject requests in a timely and legally compliant manner.
12.1 Notification Timeline. Consentik shall notify the Controller without undue delay, and in any case within 72 hours, after becoming aware of a Personal Data Breach. The notification will be delivered via email. This fulfills the requirements of Article 28(3)(f) and Article 33 of the GDPR.
12.2 Initial Notification Content. The initial breach notification shall include, to the extent known:
This fulfills the requirements of Article 33(3) GDPR.
12.3 Ongoing Cooperation. Consentik shall:
This fulfills the requirements of Article 28(3)(f) GDPR.
12.4 Exclusions. Consentik is not required to notify the Controller of:
13.1 Audit Rights. The Controller has the right to conduct audits or inspections of Consentik’s data processing activities and relevant systems, as required under Article 28(3)(h) GDPR.
13.2 Audit Procedures. Consentik shall satisfy the Controller’s audit rights primarily by making available documentation describing its security measures, summary information, and relevant third-party audit reports or certifications (such as SOC 2, ISO 27001, or equivalent), where available. A direct audit or on-site inspection may be conducted only where: (a) required by a competent supervisory authority; (b) following a confirmed Personal Data Breach affecting the Controller’s Personal Data; or (c) the documentation and reports made available above are insufficient to demonstrate compliance. Any such audit shall be:
This fulfills the requirements of Article 28(3)(h) GDPR.
13.3 Documentation. Consentik shall maintain appropriate records of processing activities and make them available to the Controller or competent supervisory authority upon request. This fulfills the requirements of Article 28(3)(h) GDPR.
14.1 General Assistance. Taking into account the nature of the processing, Consentik shall assist the Controller, upon request, in ensuring compliance with:
This assistance shall be provided in accordance with Article 28(3)(f) GDPR.
14.2 Information Provision. Consentik shall provide all information necessary to demonstrate compliance with Article 28 GDPR obligations. This fulfills the requirements of Article 28(3)(h) GDPR.
15.1 Restrictions on Processing. Consentik shall not:
Where the Controller and its End Users are subject to US Privacy Laws, the additional terms set out in Section 16 (CCPA / US State Privacy Terms) shall apply.
15.2 Aggregated and Anonymized Data. Notwithstanding Section 15.1, Consentik may create and derive anonymized and/or aggregated data that does not identify the Controller or any natural person from its processing in connection with the Services, and may use such anonymized and/or aggregated data to operate, secure, develop, and improve the Services and for Consentik’s other legitimate business purposes. Consentik shall implement reasonable measures to ensure such data cannot be re-identified and shall not attempt to re-identify it.
16.1 Application. This Section applies where the Controller is a “Business” and the End Users are “Consumers” subject to the California Consumer Privacy Act (CCPA) or other US Privacy Laws. In the event of a conflict between this Section and the rest of this DPA with respect to processing governed by US Privacy Laws, this Section controls for those matters.
16.2 Roles of the Parties. For the purposes of US Privacy Laws, the Controller is the “Business” and Consentik is the “Service Provider” (and, where applicable under other state laws, a “Processor”) that processes Personal Information on behalf of, and at the direction of, the Business.
16.3 Limitations on Processing. Consentik shall process Personal Information only for the limited and specified business purposes of providing the Services as described in this DPA and the Agreement, and shall not:
16.4 Certification. Consentik certifies that it understands the restrictions set out in Section 16.3 and will comply with them.
16.5 Consumer Rights. Consentik shall provide reasonable assistance to the Controller in responding to verifiable Consumer requests to exercise their rights under US Privacy Laws, including the rights to know/access, delete, correct, opt out of sale/sharing, and limit the use of sensitive personal information. The assistance mechanisms described in Section 11 of this DPA apply equally to such requests.
16.6 Notice of Inability to Comply. Consentik shall notify the Controller without undue delay if it determines that it can no longer meet its obligations under US Privacy Laws. Upon such notice, the Controller may take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Information.
16.7 Right to Monitor. The Controller has the right to take reasonable and appropriate steps to ensure that Consentik uses Personal Information in a manner consistent with the Controller’s obligations under US Privacy Laws, consistent with the audit rights set out in Section 13 of this DPA.
16.8 Deidentified Data. Where Consentik processes deidentified data, it shall maintain and use such data in accordance with the CCPA’s requirements for deidentified information and shall not attempt to reidentify the data, except as permitted by law.
17.1 Statutory Liability. Each Party shall be liable for the damages it causes through an infringement of this DPA or Applicable Data Protection Laws. Nothing in this DPA limits either party’s liability under Articles 82 and 83 GDPR.
17.2 Responsibility Allocation.
This allocation reflects Article 82 GDPR.
17.3 Limitation of Liability. Subject to Section 17.1, each party’s and its affiliates’ total aggregate liability arising out of or in connection with this DPA, whether in contract, tort (including negligence), or any other theory of liability, shall be subject to the exclusions and limitations of liability set out in the Agreement (Terms of Service). Any claim brought against Consentik or its affiliates under or in connection with this DPA shall be brought solely by the Controller entity that is a party to the Agreement.
18.1 Term. This DPA:
18.2 Survival. The following sections survive termination:
18.3 Termination. Termination of this DPA shall be governed by the termination provisions in the Terms of Service (Section 11). Specifically:
Upon termination, data deletion obligations in Section 10 of this DPA shall apply.
19.1 Governing Law. This DPA shall be governed by the laws of Vietnam, without regard to its conflict of law principles.
19.2 Jurisdiction. Any dispute arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the competent courts of Vietnam.
19.3 Modification. Consentik will provide 30 days advance notice for any material changes to this DPA via email or dashboard notification. Non-material changes (such as clarifications, typo corrections, or formatting updates) may be made without advance notice. Material changes require Your acceptance through continued use of the Services after the notice period. If You do not agree to the modified DPA, You must discontinue use of the Services before the effective date of the changes.
19.4 Links to Other Websites. Our Service may contain links to third-party websites or Services that are not owned or controlled by Consentik. Consentik has no control over, and assumes no responsibility for, the content, privacy policies, or practices of any third party websites or Services.
19.5 Order of Precedence. For matters related to data protection and privacy, the following order of precedence shall apply:
This order of precedence applies only to data protection matters. For all other matters, the order of precedence in Section 14.13 of the Terms of Service shall apply.
Công ty Cổ phần Phần mềm Cyber (Cyber Software Joint Stock Company)
No. 3, Alley 175/55 Lac Long Quan, Tay Ho Ward, Hanoi City, Vietnam
Business Registration No. / Tax Code (MST): 0109598571
Email: [email protected]
By installing an Consentik application, You acknowledge that You have read, understood, and agree to be bound by this Data Processing Agreement.